Category: Reports

  • How Much Does a Data Breach Cost a Small Business?

    By J. Mesa

    A cybersecurity breach is expensive, and the cost lasts long after the systems are back on. For a small business, one incident can decide whether the company survives the year.

    This post breaks down what a breach costs, where the money goes, and what lowers the bill.

    How much does a data breach cost a small business?

    Estimates vary with the study and the size of the company.

    • The Hiscox Cyber Readiness Report 2019 put the mean cost of a firm’s largest single cyber incident at just under $200,000, across businesses of all sizes. That figure counts recovery, lost revenue, and lost customers.
    • IBM’s yearly Cost of a Data Breach Report covers organizations of all sizes. It measured a global average of $4.24 million in 2021 and $4.35 million in 2022, and the 2024 report put it at $4.88 million.

    Your number depends on what data you hold, how long you are down, and how prepared you are. A small breach caught early may cost a few thousand dollars. A ransomware attack with no usable backup can cost far more than $200,000.

    What are the direct costs of a breach?

    • Incident response. Forensic investigators and IT specialists to find and remove the attacker
    • System recovery. Rebuilding computers, restoring data, replacing equipment
    • Legal advice. An attorney to guide notification and liability
    • Notification. Letters, a call center, and credit monitoring for the people affected
    • Regulatory fines. Penalties under rules such as HIPAA, the FTC Safeguards Rule, or state privacy laws
    • Card brand penalties. Assessments under PCI-DSS if payment card data was involved
    • Ransom. If you choose to pay, with no guarantee of results

    What are the hidden costs?

    • Downtime. Every hour your systems are down is an hour you can’t sell, bill, or serve customers.
    • Lost customers. People leave a business that loses their data, and they tell others.
    • Damaged reputation. Winning new clients gets harder.
    • Higher insurance premiums. Your cyber policy costs more after a claim.
    • Staff time. Your team spends weeks on recovery in place of their jobs.
    • Lost contracts. Larger clients may drop a vendor after an incident.

    For many small businesses, the downtime and the lost customers cost more than the technical cleanup.

    What makes a breach more expensive?

    • Sensitive data. Stolen card numbers, health records, and Social Security numbers bring notification duties and fines. A breach that touches only internal systems costs less.
    • Slow detection. The longer an attacker stays inside, the more they take.
    • No backups. Without a clean backup you rebuild from nothing or face the ransom.
    • No plan. Decisions made in a panic cost time and money.
    • Compliance gaps. Regulators penalize a business that skipped required safeguards.

    What makes a breach less expensive?

    Studies of breach costs point to the same factors each year.

    • An incident response plan that the team has practiced
    • Employee training, which reduces successful phishing
    • Multi-factor authentication and limited access
    • Encryption of sensitive data
    • Tested backups, kept offline or offsite
    • Fast detection through monitoring and alerts

    Each one shortens the incident or shrinks the amount of data exposed.

    Can a small business survive a breach?

    Many do. The ones that recover have backups, a plan, insurance, and cash reserves to cover the gap. You may have heard a claim that 60 percent of small businesses close within six months of an attack. That number circulates widely, and nobody has produced a study that supports it. The honest answer is that survival depends on preparation.

    Does cyber insurance cover the cost?

    A cyber insurance policy can pay for investigation, legal help, notification, business interruption, and sometimes extortion payments. Before you rely on one, know three things:

    • Insurers require controls such as multi-factor authentication and backups, and they can deny a claim if your application was inaccurate.
    • Policies have limits, deductibles, and exclusions. Read them.
    • Insurance pays bills. It does not restore lost customers.

    How do I estimate my own risk?

    1. List the data you hold and how many people it covers.
    2. Estimate what one day of downtime costs in lost sales and wages.
    3. Ask how long a full restore from backup would take.
    4. Check which laws and contracts apply to your data.
    5. Add the cost of outside help: IT, legal, and notification.

    That rough total shows how much prevention is worth to you.

    How much should a small business spend on cybersecurity?

    No single figure fits every company. Match your spending to your risk. Start with the low-cost basics that prevent the most common attacks, then add assessment and monitoring as your data and your contracts demand.

    Compare the cost of each measure with your estimate above. A password manager and multi-factor authentication cost a few dollars per user per month. A day of downtime costs far more.

    What steps prevent or reduce the cost of a breach?

    1. Use strong, unique passwords with a password manager.
    2. Turn on multi-factor authentication for email, banking, and remote access.
    3. Update software and security systems on a schedule.
    4. Train employees on cybersecurity best practices, and repeat the training.
    5. Back up your data and test the restore.
    6. Encrypt laptops and phones.
    7. Write an incident response plan and keep a printed copy.
    8. Limit the data you keep.
    9. Review your vendors’ security.

    What should I do in the first 24 hours of a breach?

    1. Disconnect affected systems from the network.
    2. Call your IT provider or incident response firm.
    3. Notify your cyber insurer. Many policies require prompt notice.
    4. Call your attorney.
    5. Preserve evidence. Don’t wipe systems before they are examined.
    6. Change passwords from a clean device.
    7. Document every action and the time you took it.

    Fast, orderly action in the first day lowers the final cost more than anything you do afterward.

    Your next step

    The cost of a breach is significant, and most of it is avoidable. Investing in strong cybersecurity measures protects your business from financial and reputational damage. Cerberus Cybersecurity helps small businesses find their gaps with risk and compliance assessments, write practical policies, and train their teams. Contact us to find out where you stand.

  • The Top 5 Cyber Threats to Small Businesses, by the Numbers

    By J. Mesa

    Small businesses face growing risk from cyberattacks and organized digital crime. Hacking tools are easy to obtain, and attackers use them to steal sensitive information, disrupt operations, or extort payment.

    Numbers make the risk concrete. This post walks through five common threats, what studies say each one costs, and how to defend against it.

    A note on the numbers

    The cost figures below come from industry reports published around 2020, and several of them measure organizations larger than a small business. Use them to compare the threats and to see the scale. Your own costs will depend on your size, your data, and how prepared you are.

    1. What is ransomware, and what does it cost?

    Ransomware encrypts a company’s data and demands payment for the key to unlock it. A victim faces financial loss and damage to its reputation.

    Datto’s Global Ransomware Report 2020 found an average ransom of $5,600 among small businesses, and an average downtime cost of $274,200. The downtime cost nearly fifty times the ransom.

    How to defend:

    • Keep offline, tested backups
    • Patch systems, and put internet-facing ones first
    • Require multi-factor authentication on remote access
    • Train staff to spot phishing

    2. What is phishing, and what does it cost?

    Phishing tricks people into giving up login credentials or financial information through fake emails and messages that appear to come from legitimate sources. Attackers use what they collect to enter company systems or steal data.

    PhishMe’s 2017 Enterprise Phishing Resiliency and Defense Report put the average cost of a successful phishing attack on a mid-sized company at $1.6 million.

    How to defend:

    • Train employees with real examples
    • Turn on multi-factor authentication
    • Use email filtering
    • Confirm payment requests by phone

    3. What is malware, and what does it cost?

    Malware is software built to damage or disrupt a computer system or to steal from it. The category includes viruses, spyware, trojans, and ransomware.

    Accenture’s research in 2020 put the average cost of a malware attack at $2.6 million.

    How to defend:

    • Run security software on every device
    • Keep software updated
    • Limit administrator rights
    • Block downloads from untrusted sources

    4. What is a denial of service attack, and what does it cost?

    A denial of service (DoS) attack floods a website or network with traffic until legitimate users can’t reach it. When the traffic comes from many sources at once, it is a distributed denial of service, or DDoS, attack.

    Estimates from 2020 put the cost at $20,000 to $40,000 per hour of outage.

    How to defend:

    • Use a hosting or DNS provider that includes DDoS protection
    • Put a content delivery network in front of your website
    • Know who to call at your provider when an attack starts

    5. What is an insider threat, and what does it cost?

    An insider threat comes from inside the organization. It can be an employee who steals data on purpose, or one who exposes it by accident.

    The Ponemon Institute’s Cost of Insider Threats study found an average annual cost of $8.76 million in 2018, rising to $11.45 million in 2020.

    How to defend:

    • Give each person access to only what the job requires
    • Remove access on an employee’s last day
    • Log and review access to sensitive data
    • Train staff on safe data handling

    Which threat is most common for small businesses?

    Phishing. It is cheap to send, it reaches every employee, and it opens the door to most other attacks, including ransomware and payment fraud. If you can fund only one defense, make it phishing training with multi-factor authentication.

    Why do attacks cost so much?

    The ransom or the stolen money is a small part of the bill. The larger costs come from:

    • Downtime. Sales and work stop.
    • Recovery. Investigators, IT labor, and replacement equipment.
    • Legal and notification costs.
    • Lost customers and damaged reputation.

    The Datto figures show the pattern. Being down costs more than the ransom.

    What is organized digital crime?

    Many attacks come from organized groups that run like businesses. They have developers, support staff, and affiliates. Some sell ransomware as a service: one group builds the tool, and others rent it and share the profits.

    That model means an attacker needs little skill to hit a small business. It also means the attacks are well tested.

    Who is behind attacks on small businesses?

    • Criminal groups seeking money
    • Individual opportunists using rented tools
    • Insiders, through intent or error
    • Automated scanners that look for weak systems across the whole internet

    Most of them are not targeting you by name. They are looking for any business with an open door.

    How does a small business protect itself?

    Technology:

    • A firewall and security software
    • Multi-factor authentication
    • Automatic updates
    • Tested backups
    • Monitoring for suspicious activity

    People:

    • Regular cybersecurity training
    • A simple way to report suspicious messages

    Process:

    • Strict rules for who can access company information and systems
    • A written incident response plan
    • A review of access and controls every quarter

    How do I estimate my own exposure?

    1. Work out what one day of downtime costs you in lost sales and wages.
    2. Count the customer and employee records you hold.
    3. Ask how long a full restore from backup would take.
    4. Multiply the daily cost by the restore time.

    That figure is a floor. It leaves out legal costs and lost customers.

    Are these numbers still accurate?

    The reports cited here date from 2017 to 2020, and costs have risen since. Newer editions of the same studies show higher figures each year. The ranking and the lesson hold: downtime and recovery cost far more than the attack itself, and prevention costs far less than either.

    Should I work with a cybersecurity consultant?

    A consulting service gives a small business a direct route to protection. A consultant identifies the threats that apply to your operations, ranks them, and helps you fix the most serious ones first. That saves you from buying tools you don’t need.

    Your next step

    Small businesses face a rising threat from hackers and organized digital crime. Investing in effective security and educating your employees protects you. Cerberus Cybersecurity offers risk and compliance assessments that show which of these five threats put your business at the most risk. Contact us to schedule one.

  • What Is a CVE? How to Prioritize Software Vulnerabilities

    What Is a CVE? How to Prioritize Software Vulnerabilities

    By J. Mesa

    In 2021, researchers recorded more software vulnerabilities than in any year before it. The record has been broken several times since. For a business, the lesson is practical: you can’t fix everything, so you need to know what to fix first.

    This post explains what a vulnerability is, how the industry tracks them, and how to set priorities.

    What is a software vulnerability?

    A vulnerability is a flaw in software or hardware that an attacker can use to do something the designer never intended, such as running their own code, reading private data, or crashing a system. Vendors fix vulnerabilities with updates, also called patches.

    What is a CVE?

    CVE stands for Common Vulnerabilities and Exposures. It is a public catalog that gives each known vulnerability a unique ID, such as CVE-2021-44228. The nonprofit MITRE runs the program with funding from the US government.

    A CVE ID gives everyone the same name for the same flaw. Vendors, researchers, and security tools all use it.

    What is the National Vulnerability Database?

    The National Vulnerability Database (NVD) is run by the National Institute of Standards and Technology. It takes each CVE and adds detail: a severity score, the affected products, and links to fixes.

    How many vulnerabilities were disclosed in 2021?

    A report by Risk Based Security and Flashpoint counted 28,695 vulnerabilities disclosed in 2021, the highest number on record at the time. Three findings stood out:

    • 28,695 vulnerabilities were disclosed during the year.
    • 29 percent had no CVE ID. Another 4 percent had an ID in “reserved” status, which meant the NVD held no usable information about them yet.
    • 4,108 were remotely exploitable and had both a documented public exploit and an available fix.

    That last group matters most. The report found that an organization could cut its risk and its immediate workload by nearly 86 percent by putting those vulnerabilities first.

    Why does the number keep rising?

    • More software exists, and more of it connects to the internet
    • More researchers look for flaws, and more vendors run reward programs
    • Software is built from shared components, so one flaw affects many products
    • Reporting has improved

    A rising count partly reflects better discovery. It still means more work for whoever maintains your systems.

    What does a severity score mean?

    Most vulnerabilities receive a score from the Common Vulnerability Scoring System (CVSS), on a scale of 0 to 10.

    • 9.0 to 10.0: critical
    • 7.0 to 8.9: high
    • 4.0 to 6.9: medium
    • 0.1 to 3.9: low

    The score measures how bad a flaw could be. It does not tell you whether attackers are using it, or whether your business is exposed.

    Do I need to patch every vulnerability?

    Over time, yes. Right away, no. Nobody can install every fix at once. What matters is the order.

    Which vulnerabilities should I patch first?

    1. Flaws attackers are using right now. CISA publishes the Known Exploited Vulnerabilities catalog, a list of flaws with confirmed attacks. Start there.
    2. Flaws in systems that face the internet. Firewalls, VPNs, email servers, and websites are reachable by anyone.
    3. Flaws that can be exploited remotely and have public exploit code.
    4. Critical and high scores on systems that hold sensitive data.
    5. Everything else, on a regular schedule.

    This is the same lesson the 2021 report drew. A small share of vulnerabilities carries most of the real risk.

    What is a zero-day?

    A zero-day is a vulnerability that attackers use before the vendor has released a fix. You can’t patch it, so other layers have to protect you: limited access, network controls, monitoring, and backups. When the fix arrives, install it at once.

    What is patch management?

    Patch management is the routine of finding, testing, and installing updates. A simple version for a small business:

    1. Keep a list of your devices and software.
    2. Turn on automatic updates wherever you can.
    3. Check once a month for updates that need manual installation, such as firewalls and business applications.
    4. Install urgent fixes for internet-facing systems within days.
    5. Replace products the vendor no longer supports.
    6. Record what you did.

    How fast should I patch?

    Many organizations aim to fix critical flaws on internet-facing systems within days and everything else within 30 days. Attackers often begin using a new flaw within days of its disclosure, so speed on the most exposed systems matters more than perfect coverage.

    How do I find out which vulnerabilities affect my business?

    • Turn on update notifications from your vendors
    • Subscribe to CISA alerts
    • Run a vulnerability scan, which checks your systems against the list of known flaws
    • Ask your IT provider for a report on what is out of date

    A scan gives you a list. A risk assessment tells you which items on the list matter.

    What if a system can’t be patched?

    Some older systems have no fix available. Reduce the risk another way:

    • Take the system off the internet
    • Put it on a separate network segment
    • Limit who and what can connect to it
    • Plan and budget for its replacement

    Why do so many vulnerabilities lack a CVE ID?

    The CVE program depends on vendors and researchers to request IDs, and the process takes time. Some flaws are published on a vendor’s site or a researcher’s blog and never enter the catalog. Tools that rely only on CVE data miss those. It is one more reason to follow your vendors’ own security notices.

    Does this apply to a small business?

    Yes. You use the same operating systems, browsers, routers, and business applications as large companies, and attackers scan for the same flaws. The good news is that you have fewer systems to keep track of.

    What should I do this month?

    1. List your devices and software.
    2. Turn on automatic updates.
    3. Check your firewall and router for updates.
    4. Look up CISA’s Known Exploited Vulnerabilities catalog and compare it with the products you use.
    5. Schedule a vulnerability scan.

    Your next step

    As the world changes, so does the threat landscape. Diligence and awareness build resistance, and a community that shares what it learns protects everyone in it. Get in touch with our team to learn how Cerberus Cybersecurity can find and rank your vulnerabilities with a risk and compliance assessment. Contact us today. At Cerberus Cybersecurity, our stance on cybersecurity is and will remain people first.