The Fine Is Not the Maximum
Regulatory penalties need to be modelled as contingent secondary loss, not carried as a statutory ceiling with a currency symbol.
The Line Everyone Thinks Is Quantified
The regulatory fine is the one loss category every compliance programme claims to have covered and almost none has actually estimated.
On 3 September 2026, BleepingComputer reported that CNIL fined a French private hospital EUR 500,000, about USD 580,000, after inadequate security measures led to a breach exposing the personal data of approximately 727,000 patients and their relatives, including sensitive health information. The point is not that this is a spectacular fine, but that it is a usable modelling event.
Most compliance programmes still do something much less useful: they carry the statutory maximum as if it were the exposure. Under the GDPR, that upper bound is tied to global annual turnover. It is familiar, board-readable and conveniently severe. It is also not an estimate.
A maximum is a bound, not a forecast. It carries no probability. It cannot be added to response cost, compared against a control budget, or used to rank one breach scenario against another. It is a qualitative artifact wearing a currency symbol.
That habit survives because it feels conservative. It also evades the harder question: conditional on a primary event having occurred, how often does a regulator act, and how large is the penalty when it does?
The Missing Variable
In a quantitative cyber risk management methodology, Fines and Judgments belongs in secondary loss. That placement matters. Primary loss is what the organization loses directly from the threat action against the asset: productivity, response and replacement. Secondary loss is what the organization loses because secondary stakeholders react: regulators, customers, media and partners.
Fines and Judgments is therefore not just a magnitude line. It has two variables: secondary loss magnitude, how large the fine or judgment is if one lands, and secondary loss event frequency, the share of primary loss events that actually trigger that stakeholder reaction.
Compliance programmes that quantify at all almost always estimate only the magnitude, silently setting secondary loss event frequency to one. Every breach becomes an enforcement action, and every enforcement action becomes the selected fine amount. The result looks disciplined because the spreadsheet contains currency values, but the largest assumption is hidden.
That assumption is usually the largest error in the entire loss estimate, and it runs in both directions. It overstates exposure for the majority of incidents that never draw an enforcement action, and understates the tail for the minority that do, because once a regulator acts, the conditions of the event and the evidentiary record may matter more than the average case.
This is why the standard reference text on this methodology, by Freund and Jones, treats secondary loss event frequency as a separate term. Not every breach triggers a regulatory fine. Not every outage damages reputation measurably.
The separation also prevents over-scoping: including every form of loss in every analysis inflates loss magnitude and reduces credibility. A breach scenario may require notification cost, post-breach response cost and legal support without implying a regulatory penalty at all.
The line item does not become an estimate because the organization has named it. It becomes an estimate when the frequency term is derived separately from the magnitude term.
Magnitude Follows Evidence
The intuitive driver of fine magnitude is scale: more records, larger fine. The 3 September 2026 enforcement action does not support that simple reading.
The reported fact pattern involved approximately 727,000 affected people. Yet the stated basis for the penalty was the inadequacy of the security measures. That distinction is not cosmetic. For modelling purposes, record count may help explain why an event is noticed, notified and investigated. It does not necessarily explain the penalty amount once the regulator has formed a view of the controls.
The implication is uncomfortable: fine magnitude is often better modelled as a function of the documented state of controls and the decision record at the time of the event than as a function of record count alone.
That makes Fines and Judgments unusual: it is a loss category where the organization can still move its own exposure after the event, not by changing the breach but by changing what its records can prove. The question becomes whether deferred remediation was documented as a structured, risk-based decision or appears, after the fact, as neglect, and whether monitoring gaps and access control exceptions were known, owned, accepted and reviewed rather than simply discovered by the regulator.
This is where the broader regulatory drift toward evidence rather than policy documents matters to the number, not just to the audit. Corporate Compliance Insights argued on 7 September 2026 that documenting and justifying deferred vulnerability remediation, aligned with CISA guidance, is becoming the practical standard for explaining patch deferrals to auditors. The difference between “not patched” and “deferred under documented risk criteria” is not semantic when a regulator reconstructs the control environment.
The same publication made the adjacent point on 31 August 2026 in the AI governance context: a policy promising human review is not evidence that review occurred. A policy stating that privileged access is reviewed, that exceptions are approved, or that alerts are triaged is only a claim until the organization can produce the record.
For a quantitative model, this changes the input. The fine is not a percentage lookup but a conditional loss distribution shaped by jurisdiction, data sensitivity, prior conduct, notification behavior, control state and contemporaneous evidence.
Build The Estimate Properly
The public GDPR Enforcement Tracker maintained by CMS Law is useful here because it turns enforcement from anecdote into distributional context. In a 2026 sector benchmark of 3,202 fines, the Health Care sector showed 273 fines, total EUR 37,665,282, mean EUR 137,968, median EUR 10,000 and maximum EUR 5,000,000. These figures are enforcement-history context, not a forecast for any specific organization, and they only bear on processing with an EU nexus.
Against that context, the EUR 500,000 penalty reported on 3 September 2026 is neither small nor large in the abstract. It is 50 times the Health Care sector median of EUR 10,000, sits above the sector mean of EUR 137,968, and is one tenth of the largest Health Care penalty in the register, EUR 5,000,000.
That comparison is more useful than the statutory ceiling. The median is a defensible base-case anchor. The mean and maximum describe the tail. Across sectors, the same pattern appears: the mean is roughly 10 to 100 times the median because a small number of very large penalties dominates the total and drags the mean far above what a typical enforcement action costs.
The Finance, Insurance and Consulting sector in the same benchmark had 324 fines, mean EUR 419,752, median EUR 20,000 and maximum EUR 31,800,000. Industry and Commerce, the register’s broadest category and not a clean match for any given industrial organization, had 600 fines, mean EUR 625,195, median EUR 5,000 and maximum EUR 150,000,000. Sector taxonomies in enforcement registers are coarse, so the mapping exercise itself requires judgment.
IBM’s Cost of a Data Breach 2025 reinforces the gap from another angle. It reports a global average breach cost of USD 4.44 million, with detection and escalation about USD 1.47 million, post-breach response about USD 1.38 million, lost business about USD 1.20 million and notification about USD 0.39 million. Regulatory fines are not broken out as their own global cost component. Even the most cited breach-cost benchmark does not give the fine line item a number. That is precisely why programmes reach for the statutory maximum.
The better method is straightforward, but it requires discipline. Estimate secondary loss magnitude and secondary loss event frequency separately. Anchor magnitude on observed enforcement distributions rather than the statutory ceiling. Use the sector median as the base case and the sector maximum as the tail bound, adjusted only where the organization has a documented reason. Estimate the frequency term from the organization’s own notification history and jurisdictional footprint rather than defaulting it to one.
Then run the pair through Monte Carlo simulation so the output is a distribution, not a single line. The result should show annualized loss exposure as a range with a defensible tail, not a theatrical maximum.
The frequency term in particular cannot be calibrated from published data alone. It requires privacy, legal and control owners at the same table because the inputs are the notification record and the control evidence. The fine is not just what the law permits. It is what the regulator is likely to do, given what happened and what the organization can prove.