Could your company lose €38M on a single email?

Sefri-Cime lost it in December 2021. FACC AG lost €42M in 2016. Arup lost $25M USD in 2024. Estimate in 60 seconds your exposure to Business Email Compromise (BEC) / CEO fraud — annual probability and total expected cost (amount diverted + forensics + legal + crisis communication; reputation excluded, not quantifiable), with a public, auditable methodology.

$2.77B
Global BEC losses 2024
80%
Organizations hit by payments fraud (2023)
~50%
of BEC attacks bypass MFA
66%
Funds frozen by the FBI — in the US only
Start the calculation →
Institutional sources used in the model

Calculator — 6 questions

Every coefficient comes from a public source. The full XLSX workbook can be downloaded at the bottom of the page. No data is sent to any server: the entire calculation runs in your browser.

Drives attack frequency and the cap on expected loss.
Construction and manufacturing dominate BEC losses (FBI IC3 2024, ALTA 2024).
Direct attack surface: 88% of BEC funds move via wire transfer (Verizon DBIR 2025).
In the US the FBI freezes 66% of funds reported early enough (IC3 2024, $561M). Outside the US there is no equivalent mechanism: our model assumes a markedly lower recovery rate.
Neutralizes account takeover (ATO), which is involved in ~1/3 of BEC cases.
The only process control with a quantified loss reduction (AFP 2024: ~65% retrospective).

Your estimate

Annual probability
of a BEC incident within 12 months
Total expected cost (EAL)
Amount diverted + forensics + legal + crisis communication · 80% range:
Comparative score
Log scale 1-10 (indicative)

Priority levers (conditional on your answers)

    80% confidence interval — your actual exposure may vary by ±50%. This calculation does not account for: anti-phishing training, cyber insurance, incident response plan maturity, or prior incident history. See the Methodology section for full details on limitations.
    A control built for BEC — no infrastructure
    Sealfie — face validation + cryptographic signature for the 3 to 5 people in the payment decision chain. Before any sensitive wire transfer, sender and approver confirm their identity on a dedicated out-of-band channel. Neutralizes video deepfakes, CEO spoofing, and email ATO on the exact surface where BEC operates — without deploying an EDR or reworking your infrastructure. Discover Sealfie ↗

    Methodology

    Reproducible and auditable. The model was submitted to an adversarial audit via Perplexity Sonar-Reasoning-Pro. Initial score 3/10 → defensible after 8 documented corrections. Every coefficient has a public source.

    10-step formula

    P_attempt × P_success × attempts_year × (1 - recovery) × loss_per_incident — capped at the IC3 95th percentile (revenue × 8%).

    26 documented cases

    Calibrated on 21 international cases + 7 French cases (Sefri-Cime €38M, Etna, Forges de Courcelles, Pathé NL, Saône-et-Loire, Ploudaniel, Le Cerf & Bachelet).

    Adversarial audit

    MFA factor 0.3 → 0.5 (Beazley: ~50% bypass). Base success 0.12 → 0.035 (IC3 / universe × underreporting). Revenue × 8% cap documented (IC3 p95).

    Total cost in 4 layers

    Direct EAL + uninsurable net loss (deductible, sublimit, exclusion) + BEC-specific remediation (€7k-130k) + qualitative risks (reputation, HR, legal).

    UCPD / DGCCRF compliance

    Verifiable quantitative claims (public XLSX), no overstatement (80% interval), no concealment (unmodeled factors listed). GDPR: no personal data is processed by the calculation.

    French legal framework

    Art. L.561-15 Monetary and Financial Code (Tracfin via bank), art. 314-1 (breach of trust — intent required), art. 62-2 Code of Criminal Procedure (conditional police custody), L225-251 Commercial Code, MAR Art. 17, AMF General Regulation 223-2.

    What this tool is not. Not an individual statistical prediction. Not an ISO 27001, PCI-DSS, or NIS2 audit. Not a substitute for a pentest or a PASSI audit. The results are an order of magnitude meant to inform a decision, not replace one.

    BEC vs Ransomware — by sector

    These figures are not used in your calculation — they situate BEC within your sector's broader cyber landscape. Scale: mid-market organization (200 – 2,000 employees) in France.

    BEC — Business Email Compromise
    Highly targeted, ongoing

    3 to 5 people in the company are high-value targets: CFO, treasurer, CEO, head of payments. Attackers research them (LinkedIn, press releases, company registries) and probe continuously — monthly to weekly attempts, all year round. No malware, no network access — the attack arrives by email, phone, or video call (deepfake).

    Ransomware
    Broad surface, one-off event

    Any employee can be the entry point (a click on an attachment, an exposed RDP port, a VPN flaw). The attack then compromises the entire network: lateral movement, encryption, exfiltration. When it happens — often just once in the company's lifetime — it's a catastrophic event that halts operations.

    Attack surface
    BEC — 3 to 5 people (CFO, treasurer, CEO, payment clerk)
    Ransomware — the entire fleet (users, endpoints, servers, VPN, RDP)
    Cadence
    BEC — ongoing: monthly to weekly attempts, 12 months a year
    Ransomware — one-off: 1 typical successful attempt per decade of operation
    Fitting control
    BEC — strong authentication of the sender/approver pair on a dedicated out-of-band channel
    Ransomware — EDR, network segmentation, immutable backups, identity management at scale
    Sector BEC — prob/year BEC — median loss Ransomware — prob/year Ransomware — total cost RW / BEC cost ratio
    Construction / Real Estate 5 – 8%€100k – 200k 10 – 18%€1M – 4M ≈ 20 ×
    Manufacturing 4 – 7%€80k – 150k 15 – 25%€2M – 5M ≈ 30 ×
    Professional services 4 – 6%€60k – 130k 10 – 18%€2M – 5M ≈ 30 ×
    Healthcare 3 – 5%€60k – 120k 15 – 25%€4M – 10M ≈ 60 ×
    Finance / Insurance 4 – 6%€100k – 200k 8 – 15%€3M – 6M ≈ 30 ×
    Tech / Digital 3 – 5%€50k – 110k 8 – 15%€2M – 5M ≈ 30 ×
    Commerce / Retail 4 – 6%€50k – 110k 8 – 15%€1M – 3M ≈ 20 ×
    Public sector / Local government 3 – 5%€60k – 120k 10 – 20%€1M – 3M ≈ 20 ×
    Key takeaway. BEC is not a "lightweight version" of ransomware — it is a threat different in nature.
    • BEC targets 3 to 5 specific people, attacks them continuously, all year round, and moves through human channels (email, phone, video call) — not through the network.
    • Ransomware targets the entire infrastructure, strikes once every 5-10 years, and moves through a technical entry point.
    Practical consequence. An EDR, network segmentation, immutable backups — the standard anti-ransomware toolkit — do not defend against BEC. BEC requires a targeted, permanent control over the small payment decision chain: strong out-of-band authentication of the sender and approver before any sensitive wire transfer. This is a people-centered protection, not an infrastructure-centered one.
    Caveats. Ransomware probabilities come from Sophos / CESIN / CPME surveys skewed toward larger organizations — likely underestimated for very small SMEs. IBM 2024 costs are global averages (predominantly US) — France is often 20-40% lower. Ranges of ±50% — high uncertainty on both the BEC and ransomware sides. Per-row detail and sources: sheet 14-BEC-vs-Ransomware of the XLSX workbook.

    Downloads

    Everything is public. An auditor, a journalist, or a competitor can fully reproduce this model. We commit to correcting any documented discrepancy within 7 days via methodologie@inkan.link.

    FAQ

    Why only 6 questions?

    Each question had to meet 3 criteria: measurable differential signal (±30% on the EAL), answerable in < 10s, and at least one public institutional source validating the factor. Noisier signals (anti-phishing training, cyber insurance, security budget) were excluded for lack of quantifiable evidence.

    Is my data sent to a server?

    No. The entire calculation runs in your browser (client-side JavaScript). No information is transmitted to Inkan.link or any third party. No cookies are set.

    Why are probability and loss displayed with a range?

    Because a precise estimate would be a misleading commercial claim (UCPD). Propagating uncertainty across the coefficients yields an 80% confidence interval of ±50% to ±100% on the EAL. It's an order of magnitude, not a prediction.

    Why is layer 3 (remediation) < €130k and not €700k like in other calculators?

    Because BEC is a social engineering fraud with minimal technical footprint. Arup's CIO (Hong Kong, $25M USD, 2024) publicly stated "no systems compromised." The €700k ranges sometimes cited correspond to ransomware IR engagements (network mapping, enterprise EDR, AD rebuild). For a typical BEC: DMARC + MFA + training = €2k-25k, not €500k.

    What happens if I'm a CFO held in police custody after a BEC incident?

    Police custody is not automatic for a BEC victim. The standard French procedure (art. 61-1 Code of Criminal Procedure) is a voluntary interview (audition libre). Police custody (art. 62-2 Code of Criminal Procedure) is only possible in cases of suspected internal complicity, production of falsified documents, or violation of specific obligations. Article 314-5 of the Penal Code, sometimes cited, does not exist; the actual basis for breach of trust is article 314-1, which requires intent to misappropriate (not mere negligence).

    How can I verify your figures?

    All coefficients are in the XLSX workbook, sheet 3-Coefficients and 4-Base-Rates. Every cell has a source URL in sheet 6-Sources. Any discrepancy with our calculation is a bug, not an opinion — we correct it within 7 days.

    I represent the DGCCRF / a journalist / a competitor. How do I dispute a figure?

    Contact: methodologie@inkan.link. Send us the disputed XLSX cell along with an alternative public source. We publish the correction (or the reason for keeping it as-is) in a public CHANGELOG within 7 days.