Could your company lose €38M on a single email?

Sefri-Cime lost it in December 2021. FACC AG lost €42M in 2016. Arup lost $25M USD in 2024. Estimate in 60 seconds your exposure to Business Email Compromise (BEC) / CEO fraud — annual probability and total expected cost (amount diverted + forensics + legal + crisis communication; reputation excluded, not quantifiable), with a public, auditable methodology.

$2.77B
Global BEC losses 2024
FBI IC3 Annual Report 2024
85%
Organizations targeted at least once/year
AFP Payments Fraud Survey 2024
~50%
of BEC attacks bypass MFA
Beazley Cyber Services Q4 2024
< 20%
Recovery rate in France
Europol IOCTA 2024
Start the calculation →
Institutional sources used in the model
FBI IC3 2024 Verizon DBIR 2025 ANSSI Panorama 2024 ENISA Threat Landscape 2024 AFP Payments Fraud 2024 Coalition Claims Report 2024 Europol IOCTA 2024 Tracfin 2023

Calculator — 6 questions

Every coefficient comes from a public source. The full XLSX workbook can be downloaded at the bottom of the page. No data is sent to any server: the entire calculation runs in your browser.

Drives attack frequency and the cap on expected loss.
Construction and manufacturing dominate BEC losses (FBI IC3 2024, ALTA 2024).
Direct attack surface: 88% of BEC funds move via wire transfer (Verizon DBIR 2025).
The recovery rate drops from 66% (US via FBI RAT) to < 15% abroad (Europol IOCTA 2024).
Neutralizes account takeover (ATO), which is involved in ~1/3 of BEC cases.
The only process control with a quantified loss reduction (AFP 2024: ~65% retrospective).

Your estimate

Annual probability
of a BEC incident within 12 months
Total expected cost (EAL)
Amount diverted + forensics + legal + crisis communication · 80% range:
Comparative score
Log scale 1-10 (indicative)

Priority levers (conditional on your answers)

    80% confidence interval — your actual exposure may vary by ±50%. This calculation does not account for: anti-phishing training, cyber insurance, incident response plan maturity, or prior incident history. See the Methodology section for full details on limitations.
    A control built for BEC — no infrastructure
    Sealfie — face validation + cryptographic signature for the 3 to 5 people in the payment decision chain. Before any sensitive wire transfer, sender and approver confirm their identity on a dedicated out-of-band channel. Neutralizes video deepfakes, CEO spoofing, and email ATO on the exact surface where BEC operates — without deploying an EDR or reworking your infrastructure. Discover Sealfie ↗

    Methodology

    Reproducible and auditable. The model was submitted to an adversarial audit via Perplexity Sonar-Reasoning-Pro. Initial score 3/10 → defensible after 8 documented corrections. Every coefficient has a public source.

    10-step formula

    P_attempt × P_success × attempts_year × (1 - recovery) × loss_per_incident — capped at the IC3 95th percentile (revenue × 8%).

    26 documented cases

    Calibrated on 21 international cases + 7 French cases (Sefri-Cime €38M, Etna, Forges de Courcelles, Pathé NL, Saône-et-Loire, Ploudaniel, Le Cerf & Bachelet).

    Adversarial audit

    MFA factor 0.3 → 0.5 (Beazley: ~50% bypass). Base success 0.12 → 0.035 (IC3 / universe × underreporting). Revenue × 8% cap documented (IC3 p95).

    Total cost in 4 layers

    Direct EAL + uninsurable net loss (deductible, sublimit, exclusion) + BEC-specific remediation (€7k-130k) + qualitative risks (reputation, HR, legal).

    UCPD / DGCCRF compliance

    Verifiable quantitative claims (public XLSX), no overstatement (80% interval), no concealment (unmodeled factors listed). GDPR: no personal data is processed by the calculation.

    French legal framework

    Art. L.561-15 Monetary and Financial Code (Tracfin via bank), art. 314-1 (breach of trust — intent required), art. 62-2 Code of Criminal Procedure (conditional police custody), L225-251 Commercial Code, MAR Art. 17, AMF General Regulation 223-2.

    What this tool is not. Not an individual statistical prediction. Not an ISO 27001, PCI-DSS, or NIS2 audit. Not a substitute for a pentest or a PASSI audit. The results are an order of magnitude meant to inform a decision, not replace one.

    BEC vs Ransomware — by sector

    These figures are not used in your calculation — they situate BEC within your sector's broader cyber landscape. Scale: mid-market organization (200 – 2,000 employees) in France.

    BEC — Business Email Compromise
    Highly targeted, ongoing

    3 to 5 people in the company are high-value targets: CFO, treasurer, CEO, head of payments. Attackers research them (LinkedIn, press releases, company registries) and probe continuously — monthly to weekly attempts, all year round. No malware, no network access — the attack arrives by email, phone, or video call (deepfake).

    Ransomware
    Broad surface, one-off event

    Any employee can be the entry point (a click on an attachment, an exposed RDP port, a VPN flaw). The attack then compromises the entire network: lateral movement, encryption, exfiltration. When it happens — often just once in the company's lifetime — it's a catastrophic event that halts operations.

    Attack surface
    BEC — 3 to 5 people (CFO, treasurer, CEO, payment clerk)
    Ransomware — the entire fleet (users, endpoints, servers, VPN, RDP)
    Cadence
    BEC — ongoing: monthly to weekly attempts, 12 months a year
    Ransomware — one-off: 1 typical successful attempt per decade of operation
    Fitting control
    BEC — strong authentication of the sender/approver pair on a dedicated out-of-band channel
    Ransomware — EDR, network segmentation, immutable backups, identity management at scale
    Sector BEC — prob/year BEC — median loss Ransomware — prob/year Ransomware — total cost RW / BEC cost ratio
    Construction / Real Estate 5 – 8%€100k – 200k 10 – 18%€1M – 4M ≈ 20 ×
    Manufacturing 4 – 7%€80k – 150k 15 – 25%€2M – 5M ≈ 30 ×
    Professional services 4 – 6%€60k – 130k 10 – 18%€2M – 5M ≈ 30 ×
    Healthcare 3 – 5%€60k – 120k 15 – 25%€4M – 10M ≈ 60 ×
    Finance / Insurance 4 – 6%€100k – 200k 8 – 15%€3M – 6M ≈ 30 ×
    Tech / Digital 3 – 5%€50k – 110k 8 – 15%€2M – 5M ≈ 30 ×
    Commerce / Retail 4 – 6%€50k – 110k 8 – 15%€1M – 3M ≈ 20 ×
    Public sector / Local government 3 – 5%€60k – 120k 10 – 20%€1M – 3M ≈ 20 ×
    Key takeaway. BEC is not a "lightweight version" of ransomware — it is a threat different in nature.
    • BEC targets 3 to 5 specific people, attacks them continuously, all year round, and moves through human channels (email, phone, video call) — not through the network.
    • Ransomware targets the entire infrastructure, strikes once every 5-10 years, and moves through a technical entry point.
    Practical consequence. An EDR, network segmentation, immutable backups — the standard anti-ransomware toolkit — do not defend against BEC. BEC requires a targeted, permanent control over the small payment decision chain: strong out-of-band authentication of the sender and approver before any sensitive wire transfer. This is a people-centered protection, not an infrastructure-centered one.
    Caveats. Ransomware probabilities come from Sophos / CESIN / CPME surveys skewed toward larger organizations — likely underestimated for very small SMEs. IBM 2024 costs are global averages (predominantly US) — France is often 20-40% lower. Ranges of ±50% — high uncertainty on both the BEC and ransomware sides. Per-row detail and sources: sheet 14-BEC-vs-Ransomware of the XLSX workbook.

    Downloads

    Everything is public. An auditor, a journalist, or a competitor can fully reproduce this model. We commit to correcting any documented discrepancy within 7 days via methodologie@inkan.link.

    FAQ

    Why only 6 questions?

    Each question had to meet 3 criteria: measurable differential signal (±30% on the EAL), answerable in < 10s, and at least one public institutional source validating the factor. Noisier signals (anti-phishing training, cyber insurance, security budget) were excluded for lack of quantifiable evidence.

    Is my data sent to a server?

    No. The entire calculation runs in your browser (client-side JavaScript). No information is transmitted to Inkan.link or any third party. No cookies are set.

    Why are probability and loss displayed with a range?

    Because a precise estimate would be a misleading commercial claim (UCPD). Propagating uncertainty across the coefficients yields an 80% confidence interval of ±50% to ±100% on the EAL. It's an order of magnitude, not a prediction.

    Why is layer 3 (remediation) < €130k and not €700k like in other calculators?

    Because BEC is a social engineering fraud with minimal technical footprint. Arup's CIO (Hong Kong, $25M USD, 2024) publicly stated "no systems compromised." The €700k ranges sometimes cited correspond to ransomware IR engagements (network mapping, enterprise EDR, AD rebuild). For a typical BEC: DMARC + MFA + training = €2k-25k, not €500k.

    What happens if I'm a CFO held in police custody after a BEC incident?

    Police custody is not automatic for a BEC victim. The standard French procedure (art. 61-1 Code of Criminal Procedure) is a voluntary interview (audition libre). Police custody (art. 62-2 Code of Criminal Procedure) is only possible in cases of suspected internal complicity, production of falsified documents, or violation of specific obligations. Article 314-5 of the Penal Code, sometimes cited, does not exist; the actual basis for breach of trust is article 314-1, which requires intent to misappropriate (not mere negligence).

    How can I verify your figures?

    All coefficients are in the XLSX workbook, sheet 3-Coefficients and 4-Base-Rates. Every cell has a source URL in sheet 6-Sources. Any discrepancy with our calculation is a bug, not an opinion — we correct it within 7 days.

    I represent the DGCCRF / a journalist / a competitor. How do I dispute a figure?

    Contact: methodologie@inkan.link. Send us the disputed XLSX cell along with an alternative public source. We publish the correction (or the reason for keeping it as-is) in a public CHANGELOG within 7 days.