OSS Supply Chain Risk: Normalized Cost & Likelihood Model
The Normalization Problem
Nobody has published a model specifically for OSS supply chain incident cost normalized by company size. What exists:
| Source | What They Normalize | Metric Used |
|---|---|---|
| Cyentia IRIS 20/20 | All cyber incidents | Revenue band, employee count |
| IBM Cost of Data Breach | All breaches | Industry, geography, employee count |
| Hiscox Cyber Readiness | All cyber attacks | Employee count (<250 = “small”) |
| Kaspersky IT Security Economics | All incidents | SMB vs Enterprise |
| FAIR / Open FAIR | Scenario-specific | Loss Event Frequency × Loss Magnitude |
None of these isolate OSS supply chain incidents. So the model below is a synthesis — a guesstimate built by:
- Taking Cyentia’s size-segmented breach frequency/cost data
- Applying IBM’s finding that supply chain compromise = 15% of all breaches at $4.91M average
- Scaling by Sonatype’s dependency surface area data
- Cross-checking with Hiscox/Kaspersky SMB actuals
Recommended Normalization Metric: Dependency Surface Area
Why not just employee count? A 200-person manufacturing firm with 2 internal apps has radically different OSS exposure than a 200-person SaaS company with 50 microservices.
Dependency Surface Area (DSA) = number of applications × average dependencies per app
| Company Profile | Apps | Avg Deps/App | DSA | Relative Exposure |
|---|---|---|---|---|
| 10-person startup, 1 product | 1-3 | 180 | ~400 | 1× (baseline) |
| 50-person SaaS | 5-15 | 180 | ~1,800 | 4.5× |
| 200-person mid-market | 20-50 | 180 | ~6,300 | 16× |
| 1,000-person enterprise | 100-300 | 180 | ~36,000 | 90× |
| 10,000-person large enterprise | 500-2,000+ | 180 | ~225,000 | 560× |
180 deps/app is Sonatype’s 2024 enterprise average (direct + transitive). Ranges from 25 to 800+.
But for cost modeling, revenue is still king — because breach cost correlates more with regulatory exposure, customer base, and data volume than with dependency count. DSA drives likelihood; revenue drives magnitude.
Guesstimated Annual Likelihood of an OSS Supply Chain Incident
Sources: Cyentia IRIS (all-incident frequency by size), IBM 2025 (supply chain = 15% of breaches), BlackBerry 2024 (75% of orgs hit by supply chain attack), Verizon 2025 DBIR (third-party breaches doubled to 30%).
| Company Size (employees) | Annual Probability of ANY Cyber Incident | Est. Annual Probability of OSS Supply Chain Incident | Rationale |
|---|---|---|---|
| 1-10 | ~5-10% | ~1-2% | Cyentia: SMBs <2% for any breach. Low target value, but also low defenses. Most attacks are opportunistic phishing, not supply chain. |
| 11-50 | ~10-15% | ~2-4% | More apps, more dependencies, still low target value. Supply chain incidents mostly undetected at this scale. |
| 51-250 | ~15-25% | ~4-8% | Sweet spot for “big enough to have complex dependencies, too small for dedicated AppSec.” Hiscox: 43% of SMBs faced ≥1 attack. |
| 251-1,000 | ~25-40% | ~8-15% | Cyentia: ~25% of Fortune 1000 have annual incident. Multiple apps, CI/CD pipelines, growing dependency surface. |
| 1,001-5,000 | ~40-60% | ~15-25% | Large dependency surface, regulatory scrutiny, attractive target. Most will have ≥1 vulnerable OSS component exploited. |
| 5,000+ | ~60-80% | ~25-40% | Cyentia: 60%+ of Fortune 1000 had incident in past decade. At this scale it’s near-certain over a 3-year window. |
Key caveat: “OSS supply chain incident” here ranges from “pulled in a malicious npm package that got caught by EDR” to “SolarWinds-scale compromise.” Most incidents at the low end are never reported or costed.
Guesstimated Cost Per Incident by Company Size
Sources: IBM 2025 ($4.91M supply chain average), Cyentia IRIS ($196K median all-breach), Hiscox ($8.3K median SMB), Kaspersky ($117-149K SMB average).
| Company Size | Typical (Median) Incident Cost | Severe (90th Percentile) | Catastrophic (99th Percentile) |
|---|---|---|---|
| 1-10 employees | $5K-$15K | $50K-$150K | $500K+ (company-ending) |
| 11-50 | $15K-$50K | $150K-$500K | $1M+ (company-ending) |
| 51-250 | $50K-$200K | $500K-$2M | $3-5M |
| 251-1,000 | $200K-$800K | $2M-$5M | $10-20M |
| 1,001-5,000 | $800K-$3M | $5M-$15M | $30-50M |
| 5,000+ | $3M-$10M | $15M-$50M | $100M-$1B+ |
Where the cost hides (breakdown):
| Cost Category | % of Total | Notes |
|---|---|---|
| Detection & investigation | 25-35% | Longer for supply chain (267 days avg vs 241 overall — IBM 2025) |
| Business disruption | 25-30% | System downtime, blocked deploys, emergency patching |
| Post-breach response | 15-20% | Customer notification, credit monitoring, PR |
| Regulatory & legal | 10-20% | Scaling fast — IBM found fines now exceed $1M for 12% of breaches |
| Lost business / churn | 10-15% | Hardest to measure, often excluded from SMB estimates |
Annualized Loss Expectancy (ALE) by Company Size
ALE = Annual Probability × Average Cost Per Incident
This is what you’d use to justify tooling spend.
| Company Size | Annual Probability | Typical Cost | ALE (Expected Annual Loss) | Context |
|---|---|---|---|---|
| 1-10 | 1.5% | $10K | $150/yr | Less than a Snyk license |
| 11-50 | 3% | $30K | $900/yr | About 1 day of eng time |
| 51-250 | 6% | $125K | $7,500/yr | Justifies basic SCA tooling |
| 251-1,000 | 12% | $500K | $60K/yr | Justifies dedicated AppSec hire |
| 1,001-5,000 | 20% | $2M | $400K/yr | Justifies full supply chain security program |
| 5,000+ | 33% | $6.5M | $2.1M/yr | Justifies enterprise SCA + SBOM + dedicated team |
Important: ALE is a mean expectation. It smooths over the fat-tailed distribution. A 1,000-person company might go 5 years with $0 in incidents, then get hit with a $10M event. The 90th/99th percentile columns above matter more for budgeting.
What Drives Cost Variation (Risk Factors)
These are the multipliers that make a 200-person company look like a 2,000-person company (or vice versa):
| Factor | Low Risk (0.5×) | Medium (1×) | High Risk (2-5×) |
|---|---|---|---|
| Industry | Manufacturing, non-tech | General SaaS, services | Healthcare, fintech, gov contractor |
| Data sensitivity | No PII, no financial data | Standard customer PII | PHI, payment cards, credentials |
| Regulatory exposure | Minimal | SOC 2, state privacy laws | HIPAA, PCI-DSS, DORA, NIS2 |
| Dependency surface | <500 total deps | 500-5,000 | >5,000 (or critical infra deps) |
| Dependency hygiene | Automated updates, SCA in CI | Periodic manual review | 80%+ deps un-upgraded >1 year |
| CI/CD exposure | Air-gapped builds | Standard cloud CI | GitHub Actions with 3P actions, public runners |
| OSS in revenue path | Internal tools only | Part of product | OSS IS the product (e.g., OSS distribution) |
Existing Models Worth Knowing
Cyentia IRIS 20/20 — The closest thing to what you want. Key findings:
- Median breach cost: $196K (geometric mean, all sizes)
- 95th percentile for Fortune 250: approaches $100M
- 6% chance a Fortune 1000 firm loses $100M+ in a 12-month period
- Loss distribution is lognormal — cost-per-record is “flat-out wrong”
- Multi-party incidents (i.e., supply chain): median cost $4.7M, 10× higher than single-party
FAIR (Factor Analysis of Information Risk) — The only ISO standard for quantitative cyber risk. Framework:
- Risk = Loss Event Frequency × Loss Magnitude
- LEF = Threat Event Frequency × Vulnerability (probability of success)
- Best for scenario-specific modeling (“what’s our risk from a compromised npm package?”)
- Black Kite and Safe Security offer automated FAIR-based CRQ products
Hiscox Cyber Readiness Report — Insurance-industry data, most relevant for SMBs:
- Median annual cost to US small business: $8,300 (2023, down from $10K)
- Average: $25,612 (2021)
- Includes all cyber incidents, not just supply chain
Bottom Line
For your tool (OSS Risk Guard), the pitch is:
“The average enterprise application has 180 OSS dependencies with 13 critical/high vulns discovered per year. 80% of those dependencies go un-upgraded for over a year. Supply chain breaches cost $4.91M on average and take 267 days to detect — the longest of any attack vector. Your annualized expected loss from OSS supply chain risk scales from $7.5K (mid-market) to $2.1M+ (enterprise), and a single severe incident can cost 10-50× that.”
The normalization metric to use in your product/marketing:
- Dependency Surface Area for likelihood/exposure scoring
- Revenue band for cost projection
- ALE for ROI justification (“our tool costs X, your expected annual loss is Y”)
All estimates are synthesis-based guestimates. No single source validates these specific numbers for OSS supply chain incidents in isolation. The data desert is real.