Expected Cost of Open-Source Risk

Calculate the potential financial impact of open-source vulnerabilities, dependencies, and licensing issues based on your company's scale.

One-time costs are per incident — multiply by your estimated annual incident frequency for annualized exposure. All developer cost calculations assume a fully-loaded salary of $150,000/year.

Company Profile

Expected One-Time Costs (Per Incident)

Security Breach $0

Basis: ORX MOVEit deep-dive models impact at ~$130 per record. IBM 2025 Report established the $4.9M/$10.2M averages. Cybersecurity Ventures notes 60% of small businesses close, meaning maximum impact effectively caps at total annual revenue.

Dependency Failure (Forced Migration) $0

Basis: Bus Factor in Practice & Tidelift report finding and replacing an abandoned dependency takes ~6 person-months (0.5x developer salary).

IP Litigation / Compliance $0

Basis: EU NIS2 Directive fines represent 2% of annual revenue for supply-chain violations. Quandary Peak cites cases like Entr'ouvert v. Orange S.A. resulting in $1M+ in damages.

Expected Ongoing Costs (Annual)

Security Patches (Engineering Time) $0

Basis: IDC 2024 InfoBrief & YesWeHack note developers spend 19% of their working hours addressing security concerns.

Dead Dependencies (SBOM Debt) $0

Basis: Stripe Developer Coefficient calculates 42% of developer time is spent on technical debt; we attribute 30% of that debt specifically to managing external dependencies (SBOM).

License Remediation $0

Basis: Qt TCO model estimates $851 per developer annually for routine legal checks and obligation management.