Risk & Strategy / ROI Calculator

What this is for: Calculate migration ROI with breach avoidance, compliance savings, and payback period.

What a good answer looks like: A payback period you would defend under questioning — which means the breach-avoidance input is a number you can source, not the one that makes the case work.

Worked example: Pick the 'Average org' tier, enter your products to migrate and planning horizon, then halve the breach-probability input: if the payback period still lands inside the horizon, the case does not depend on the scary number.

Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.

Browse all Business tools · Browse PQC learning modules

For your role

Executive / Business Leader
Pick the SMB, Average org or Fortune-1000-class tier, enter the products to migrate, capex per product and the planning horizon: the three-year total cost against the cost of inaction is the payback figure for the board, exportable as .pdf or .docx.
GRC / Risk & Compliance
The Applicable Frameworks and Penalty per Incident inputs put regulatory exposure into the same figure as breach cost; keep the HNDL exposure and breach-probability inputs you used, because they are the assumptions an auditor will ask about.

Board-ready business case. Intended audience: CFO, CIO, and board. Figures are illustrative estimates; pair with your organization's finance model before seeking approval.

Total Cost (3yr)

$5.4M

Capex $3.8M + Opex $1.7M

Cost of Inaction (3yr)

$6.1M

Expected breach + compliance exposure

NPV @ 10%

-$95K

3-year ROI: +12%

Payback Period

31mo

Capex recoup from net benefit

Investment
150 of 888888
$25K$75K$200K
0%15% ≈ $563K/yr40%

Capex: 50 × $75K = $3.8M + Opex $563K/yr × 3yr = $5.4M total

Cross-check vs your assessment

Run the assessment to generate a second, independent cost estimate — then this panel cross-checks it against your per-product model so you never present a single unverified number.

Risk Reduction

Industry breach baseline (Other): $4.4M — IBM Cost of a Data Breach Report 2025. Quantum amplification is composed from three defensible factors below.

0%50%100%
0%50%100%
0%50%100%
1%9.3%50%

Default reflects the selected organization size — Cyentia IRIS 2025 anchors per organization size (Figures 6 and 7 of the report). The tiers sit close together because IRIS 2025's finding is that they have converged: small-firm risk has more than doubled since 2008 while the largest firms' has fallen. Drag the slider to override.

$4.4M × quantum amp 2.50× × 9.3% = $1.0M/year

Regulatory Exposure
05 of 191191
$500K$2.0M$10M

5 frameworks × $2.0M × 10% incident rate = $1.0M/year

Financial Modeling
1 year3 years10 years
0%10%20%

$1.5M/yr net × 3 yr, discounted @ 10% = NPV -$95K

Sensitivity — NPV impact at ±30%
-$1.6M-$800K$0$800K$1.6MCost per ProductHorizon (years)Breach ProbabilityPenalty perIncidentAnnual Opex %Discount Rate

Bars show NPV delta when each driver moves ±30% from its current value. Longest bars are your most material assumptions — defend them first.

Calculation Methodology

Investment: Capex (products × per-product cost) plus annual opex modeled as a % of capex. Typical ongoing opex covers HSM maintenance, key rotation, and audit — industry defaults are 10–20% of capex.

Risk reduction: Industry breach baseline (IBM Cost of a Data Breach Report 2025) × a composed quantum amplification factor × annual breach probability. The amplification factor is the sum of three defensible components — HNDL exposure (fraction of data at risk of retroactive decryption), post-CRQC attacker uplift (new capability ceiling once a CRQC exists), and detection-timeline uplift (mean time to detect will lengthen).

Regulatory exposure: Number of applicable regulatory frameworks × average penalty per incident × a 10% annual incident probability per framework.

NPV: Σ (netAnnualBenefit / (1 + WACC)^t) − capex, where netAnnualBenefit = grossAnnualBenefit − annualOpex.

Payback: capex / (netAnnualBenefit / 12). Uses annual (not horizon) benefit so payback is not understated by the horizon.

Sensitivity: Each driver is varied ±30% from its current value while all others are held constant; the resulting NPV delta indicates which assumption most moves the business case.

Qualitative factors not modeled: Operational efficiency from crypto agility, competitive advantage from early PQC adoption, customer trust.

Which costing model this is: a bottom-up parametric estimate (assets × unit cost) with deterministic ±30% sensitivity. It is one of several model families — top-down budget-percentage anchoring, probabilistic Monte-Carlo bands, and expert-elicited scenario ranges are the others. No single method is reliable for PQC under deep uncertainty, so triangulate: treat agreement across two or three independent estimates as confidence, and divergence as a prompt to revisit assumptions. See the Learn tab's “Choosing a Costing Model” section for the full comparison.

Educational estimates for planning. Pair with your finance function's discounted cash-flow model before committing capital.

PQC Migration ROI — Export

Export the ROI analysis above as markdown, PDF, or DOCX for board distribution. The artifact is also saved to your Command Center Risk Artifacts list.

Try it

Halve the Annual Breach Probability input. What tells you the case did not depend on the scary number?

Next step

Next in Risk & Strategy: Board Pitch Builder

Board Pitch Builder is the next Risk & Strategy tool in the Command Center.