Incident response
Combine digital forensics and initial legal review, then locate the equivalent crisis-response, expert-cost, or incident-response wording in the policy.
Model up to three data breach, ransomware, or system interruption incidents against verified category limits, waiting periods, deductibles, per-incident limits, and the remaining annual aggregate.
Use verified schedule values to compare up to three incidents against category limits, deductibles, waiting periods, and aggregates. The tool does not price insurance, predict incidents, interpret policy wording, or decide Korean breach-reporting duties.
Enabled incidents consume annual capacity from number 1 onward. If that is not your expected order, move the values between cards.
Copy amounts from the schedule, endorsements, or renewal quote. For an annual category, enter the currently remaining amount after earlier use.
Incident response
Digital forensics and initial legal review
Privacy response
Per-person notification and call-center support
Data restoration
Data and system recovery or reconstruction
Business interruption
Hourly contribution-margin loss after the waiting period
Cyber extortion response
Separately reviewed response cost subject to legal and sanctions checks
Third-party liability
Defense costs and counsel-reviewed settlement or judgment exposure
Separate payroll, rent, tax, and supplier cash before treating the remainder as available incident liquidity.
The model applies the waiting period, category limits, deductible, per-incident limit, then the remaining annual aggregate.
Total incident cost
KRW 178,000,000
Estimated policy payout
KRW 100,000,000
Total coverage gap
KRW 78,000,000
Protection rate
56.2%
Annual aggregate remaining
KRW 0
Liquidity after protected cash
KRW 20,000,000
Modeled affordable deductible per incident
KRW 6,600,000
Largest retained cost for one incident
KRW 39,000,000
| Gap driver | Amount |
|---|---|
| Waiting-period gap | KRW 12,000,000 |
| Confirmed excluded cost | KRW 7,000,000 |
| Unconfirmed-coverage gap | KRW 0 |
| Category-limit gap | KRW 37,000,000 |
| Applied deductible | KRW 15,000,000 |
| Per-incident limit gap | KRW 0 |
| Annual aggregate gap | KRW 7,000,000 |
| Incident | Incident type | Confirmed | Incident cost | Estimated policy payout | Retained cost | Aggregate after incident |
|---|---|---|---|---|---|---|
| 1 | Personal data breach | Confirmed | KRW 64,000,000 | KRW 53,000,000 | KRW 11,000,000 | KRW 47,000,000 |
| 2 | Ransomware or extortion response | Confirmed | KRW 74,000,000 | KRW 46,000,000 | KRW 28,000,000 | KRW 1,000,000 |
| 3 | Network or system interruption | Confirmed | KRW 40,000,000 | KRW 1,000,000 | KRW 39,000,000 | KRW 0 |
| Coverage category | Gross cost | Coverage-eligible model | Limit before incident | Estimated payout | Uncovered |
|---|---|---|---|---|---|
| Incident response | KRW 12,000,000 | KRW 12,000,000 | KRW 30,000,000 | KRW 7,000,000 | KRW 5,000,000 |
| Privacy response | KRW 15,000,000 | KRW 15,000,000 | KRW 20,000,000 | KRW 15,000,000 | KRW 0 |
| Data restoration | KRW 2,000,000 | KRW 2,000,000 | KRW 30,000,000 | KRW 2,000,000 | KRW 0 |
| Business interruption | KRW 8,000,000 | KRW 4,000,000 | KRW 20,000,000 | KRW 4,000,000 | KRW 4,000,000 |
| Cyber extortion response | KRW 0 | KRW 0 | KRW 0 | KRW 0 | KRW 0 |
| Third-party liability | KRW 25,000,000 | KRW 25,000,000 | KRW 30,000,000 | KRW 25,000,000 | KRW 0 |
These are rounded comparisons from your entered losses, not product or limit recommendations.
| Coverage category | Basis | Current usable limit | Modeled need | Rounded review value | Gap to current limit | Category limit remaining |
|---|---|---|---|---|---|---|
| Incident response | Current annual remainder | KRW 30,000,000 | KRW 30,000,000 | KRW 30,000,000 | KRW 0 | KRW 15,000,000 |
| Privacy response | Current annual remainder | KRW 20,000,000 | KRW 15,000,000 | KRW 20,000,000 | KRW 0 | KRW 5,000,000 |
| Data restoration | Current annual remainder | KRW 30,000,000 | KRW 27,000,000 | KRW 30,000,000 | KRW 0 | KRW 7,000,000 |
| Business interruption | Current annual remainder | KRW 20,000,000 | KRW 32,000,000 | KRW 40,000,000 | KRW 20,000,000 | KRW 0 |
| Cyber extortion response | Current annual remainder | KRW 0 | KRW 10,000,000 | KRW 10,000,000 | KRW 10,000,000 | KRW 0 |
| Third-party liability | Current annual remainder | KRW 30,000,000 | KRW 45,000,000 | KRW 50,000,000 | KRW 20,000,000 | KRW 3,000,000 |
| Combined per-incident limit | — | KRW 70,000,000 | KRW 65,000,000 | KRW 70,000,000 | KRW 0 | — |
| Annual aggregate | — | KRW 120,000,000 | KRW 179,000,000 | KRW 180,000,000 | KRW 60,000,000 | KRW 0 |
A cyber incident can trigger digital forensics, legal review, data-subject notification, call-center support, restoration work, interrupted operations, and third-party claims at different times.
A large limit on the policy cover sheet may sit above much smaller category limits, an interruption waiting period, a deductible for every incident, and an annual aggregate already reduced by an earlier claim.
Comparing one total loss number with one nominal policy limit can therefore hide the part that must be funded with company cash.
This calculator models up to three enabled incidents in displayed order and separates six coverage categories.
It removes waiting-period loss first, then applies category limits, the per-incident deductible, the combined per-incident limit, and the currently remaining annual aggregate.
The result is a transparent stress test for a policy discussion, not a premium quote, coverage opinion, loss adjustment, or legal notification decision.
A ransomware recovery calculator focuses on project costs such as restoration labor, replacement equipment, and downtime, then compares them with one confirmed insurance amount.
This tool starts where that estimate ends by asking which policy category receives each cost and how category limits, waiting periods, deductibles, and shared annual capacity change the estimated payout.
Use both when you need a detailed recovery budget and a separate policy-structure test.
Combine digital forensics and initial legal review, then locate the equivalent crisis-response, expert-cost, or incident-response wording in the policy.
Multiply affected people or records by the entered notification and support cost per person, while checking which communication and monitoring services the wording actually permits.
Enter direct recovery, reconstruction, and data recreation cost, but separate upgrades and security improvements that go beyond returning to the pre-incident state.
Multiply interrupted hours by contribution-margin loss per hour and remove the waiting period, using contribution margin rather than gross revenue.
Enter only a separately reviewed response scenario because this calculator never recommends a ransom payment or decides legality, sanctions, or law-enforcement coordination.
Combine defense cost with counsel-reviewed settlement or judgment exposure without automatically multiplying damages or treating regulatory penalties as covered.
Do not quietly mix fines, penalties, enhanced contractual liability, pre-incident improvements, or another wording exclusion into a covered category.
Enter only costs that the schedule or an adviser has identified as excluded, so the output distinguishes a category-limit shortage from a cost that the model never sends to the insurer.
The waiting-period gap, exclusion, category-limit gap, deductible, per-incident gap, and aggregate gap do not overlap in this model.
Their sum must equal gross incident cost minus estimated payout, which makes the result suitable for checking and explaining.
Actual wording may treat defense costs, deductibles, claim expenses, or related events differently, so the fixed order is a disclosed modeling convention rather than a legal interpretation.
Consider gross incident cost of KRW 41 million with only KRW 25 million left in the annual aggregate.
The model first identifies KRW 2 million of waiting-period loss, KRW 3.5 million above category limits, and KRW 1 million of confirmed excluded cost.
A KRW 4 million deductible, a KRW 0.5 million per-incident limit gap, and a KRW 5 million aggregate gap then leave an estimated payout of KRW 25 million and retained cost of KRW 16 million.
| Result | Amount | Interpretation |
|---|---|---|
| Gross incident cost | KRW 41.0M | All six cost categories plus confirmed exclusions |
| Estimated payout | KRW 25.0M | Amount left after every entered policy constraint |
| Coverage gap | KRW 16.0M | Modeled amount requiring another funding source |
| Protection rate | 61.0% | Estimated payout divided by gross incident cost |
The protection rate alone is not the decision.
A waiting-period problem calls for a different discussion from a privacy sublimit problem or an aggregate depleted by earlier claims.
Read the gap-driver and category tables before changing a limit or setting aside cash.
| Policy item | Calculator field | Question to ask |
|---|---|---|
| Schedule and endorsements | Six category limits | Is each amount per incident or shared for the annual period? |
| Retention wording | Deductible per incident | Can related events be treated as one incident? |
| Interruption section | Waiting hours and hourly margin | When does the wait start and how is covered profit defined? |
| Combined event limit | Per-incident limit | Do defense and expert costs erode this limit? |
| Annual aggregate | Nominal limit and prior payout | Do reserves or unresolved claims reduce current capacity? |
| Notice conditions | Coverage-confirmed switch | What are the discovery, insurer-notice, consent, and panel-provider rules? |
This amount becomes available again for each enabled incident in the model.
A separate combined per-incident limit can still cap the sum that passes all category limits.
This is shared by incidents and starts with the usable amount remaining after earlier loss.
The calculator reduces it by final category payout before moving to the next incident.
As checked on August 17, 2026, Article 34 of the current Korean Personal Information Protection Act provides the statutory basis for notifying data subjects after specified loss, theft, or leakage and for taking measures to minimize harm.
Article 39 of the Enforcement Decree generally requires notice within 72 hours after learning of the event unless a justified reason applies, with a publication method for situations such as unavailable contact details.
Article 40 of the Decree provides 72-hour reporting criteria involving at least 1,000 data subjects, sensitive or unique-identification information, or illegal external access, subject to the full legal conditions.
The checked texts are Act ID 011357, MST 270351, effective October 2, 2025, and Enforcement Decree ID 011468, MST 286175, effective May 19, 2026.
The affected-record input only multiplies notification and support cost.
Data type, access method, confirmed timing, mitigation, and exceptions also matter, so the tool cannot decide whether notice or reporting is legally required.
If an incident may have occurred, begin the legal and response review immediately rather than waiting for this financial model to be completed.
Article 39-7 of PIPA and Article 48-7 of its Enforcement Decree address insurance, mutual-aid membership, or reserves for certain personal-information controllers.
The basic size criteria in the current Decree use both at least KRW 1 billion of prior-year revenue and at least 10,000 average daily data subjects over the specified three-month period, while statutory exceptions and calculation rules still need review.
The table below restates Appendix 1-4 only as a reading aid.
| Average daily data subjects | Revenue above KRW 80B | Above KRW 5B to KRW 80B | KRW 1B to KRW 5B |
|---|---|---|---|
| At least 1 million | KRW 1B | KRW 500M | KRW 200M |
| 100,000 to below 1 million | KRW 500M | KRW 200M | KRW 100M |
| 10,000 to below 100,000 | KRW 200M | KRW 100M | KRW 50M |
Revenue measurement, data-subject counting, exceptions, and the relationship between insurance and reserves can change the conclusion.
The calculator therefore never replaces an entered policy limit with this table or declares that an organization is subject to the rule.
The official Appendix 1-4 serial identifier is 18138337 and should be read with current Decree Article 48-7.
Check the official Appendix 1-4 detail and the law in force at the decision date.
Enter the current policy and competing renewal schedules separately to see whether a larger headline aggregate leaves privacy response, interruption, or third-party category limits unchanged.
Place a data breach, ransomware event, and system outage in annual order to identify which later incident loses payout when shared category capacity or the aggregate is depleted.
Protect payroll and rent first, then compare the remaining liquidity per enabled incident with the current deductible before accepting more retained risk for a premium reduction.
No. Zero means no confirmed usable amount in this model, so verify any apparently unlimited wording against the combined incident limit, aggregate, and shared endorsements before entering a number.
Enabled incidents are treated as events that all occur in one policy period and consume capacity in displayed order, while alternative scenarios can be compared by enabling one incident at a time.
Variable costs may decline when operations stop, so gross revenue can overstate the economic loss, although the exact covered-profit definition and period still come from the policy.
The conservative setting prevents the tool from inventing partial cover before the trigger, retroactive date, discovery date, and notice conditions have been checked.
No. It is only the entered eligible cost rounded upward for a policy discussion and does not include probability, premium, financial capacity, other insurance, or a suitability assessment.
Do not add an automatic amount because insurability and liability depend on law, facts, and wording; enter only counsel-reviewed third-party exposure or a separately confirmed exclusion.
Copy actual category limits and their basis first, then place credible internal cost estimates into as many as three incidents.
Share which waiting period, category limit, deductible, or aggregate produced the gap with the insurer, broker, legal adviser, and response owner.
If retained cost crosses protected operating cash, coordinate emergency liquidity, supplier terms, backup recovery, and response priorities alongside any policy change.
The legal references reflect the current Korean PIPA and Enforcement Decree checked on August 17, 2026.
Recheck the law in force and the complete policy wording when making an actual decision.