By J. Mesa
A cybersecurity breach is expensive, and the cost lasts long after the systems are back on. For a small business, one incident can decide whether the company survives the year.
This post breaks down what a breach costs, where the money goes, and what lowers the bill.
How much does a data breach cost a small business?
Estimates vary with the study and the size of the company.
- The Hiscox Cyber Readiness Report 2019 put the mean cost of a firm’s largest single cyber incident at just under $200,000, across businesses of all sizes. That figure counts recovery, lost revenue, and lost customers.
- IBM’s yearly Cost of a Data Breach Report covers organizations of all sizes. It measured a global average of $4.24 million in 2021 and $4.35 million in 2022, and the 2024 report put it at $4.88 million.
Your number depends on what data you hold, how long you are down, and how prepared you are. A small breach caught early may cost a few thousand dollars. A ransomware attack with no usable backup can cost far more than $200,000.
What are the direct costs of a breach?
- Incident response. Forensic investigators and IT specialists to find and remove the attacker
- System recovery. Rebuilding computers, restoring data, replacing equipment
- Legal advice. An attorney to guide notification and liability
- Notification. Letters, a call center, and credit monitoring for the people affected
- Regulatory fines. Penalties under rules such as HIPAA, the FTC Safeguards Rule, or state privacy laws
- Card brand penalties. Assessments under PCI-DSS if payment card data was involved
- Ransom. If you choose to pay, with no guarantee of results
What are the hidden costs?
- Downtime. Every hour your systems are down is an hour you can’t sell, bill, or serve customers.
- Lost customers. People leave a business that loses their data, and they tell others.
- Damaged reputation. Winning new clients gets harder.
- Higher insurance premiums. Your cyber policy costs more after a claim.
- Staff time. Your team spends weeks on recovery in place of their jobs.
- Lost contracts. Larger clients may drop a vendor after an incident.
For many small businesses, the downtime and the lost customers cost more than the technical cleanup.
What makes a breach more expensive?
- Sensitive data. Stolen card numbers, health records, and Social Security numbers bring notification duties and fines. A breach that touches only internal systems costs less.
- Slow detection. The longer an attacker stays inside, the more they take.
- No backups. Without a clean backup you rebuild from nothing or face the ransom.
- No plan. Decisions made in a panic cost time and money.
- Compliance gaps. Regulators penalize a business that skipped required safeguards.
What makes a breach less expensive?
Studies of breach costs point to the same factors each year.
- An incident response plan that the team has practiced
- Employee training, which reduces successful phishing
- Multi-factor authentication and limited access
- Encryption of sensitive data
- Tested backups, kept offline or offsite
- Fast detection through monitoring and alerts
Each one shortens the incident or shrinks the amount of data exposed.
Can a small business survive a breach?
Many do. The ones that recover have backups, a plan, insurance, and cash reserves to cover the gap. You may have heard a claim that 60 percent of small businesses close within six months of an attack. That number circulates widely, and nobody has produced a study that supports it. The honest answer is that survival depends on preparation.
Does cyber insurance cover the cost?
A cyber insurance policy can pay for investigation, legal help, notification, business interruption, and sometimes extortion payments. Before you rely on one, know three things:
- Insurers require controls such as multi-factor authentication and backups, and they can deny a claim if your application was inaccurate.
- Policies have limits, deductibles, and exclusions. Read them.
- Insurance pays bills. It does not restore lost customers.
How do I estimate my own risk?
- List the data you hold and how many people it covers.
- Estimate what one day of downtime costs in lost sales and wages.
- Ask how long a full restore from backup would take.
- Check which laws and contracts apply to your data.
- Add the cost of outside help: IT, legal, and notification.
That rough total shows how much prevention is worth to you.
How much should a small business spend on cybersecurity?
No single figure fits every company. Match your spending to your risk. Start with the low-cost basics that prevent the most common attacks, then add assessment and monitoring as your data and your contracts demand.
Compare the cost of each measure with your estimate above. A password manager and multi-factor authentication cost a few dollars per user per month. A day of downtime costs far more.
What steps prevent or reduce the cost of a breach?
- Use strong, unique passwords with a password manager.
- Turn on multi-factor authentication for email, banking, and remote access.
- Update software and security systems on a schedule.
- Train employees on cybersecurity best practices, and repeat the training.
- Back up your data and test the restore.
- Encrypt laptops and phones.
- Write an incident response plan and keep a printed copy.
- Limit the data you keep.
- Review your vendors’ security.
What should I do in the first 24 hours of a breach?
- Disconnect affected systems from the network.
- Call your IT provider or incident response firm.
- Notify your cyber insurer. Many policies require prompt notice.
- Call your attorney.
- Preserve evidence. Don’t wipe systems before they are examined.
- Change passwords from a clean device.
- Document every action and the time you took it.
Fast, orderly action in the first day lowers the final cost more than anything you do afterward.
Your next step
The cost of a breach is significant, and most of it is avoidable. Investing in strong cybersecurity measures protects your business from financial and reputational damage. Cerberus Cybersecurity helps small businesses find their gaps with risk and compliance assessments, write practical policies, and train their teams. Contact us to find out where you stand.
