If you think of cybersecurity as an expense, it is probably because you have never worked out the cost of a cyberattack for your own business. The bill does not arrive as one line item. It arrives as several separate lines, spread over weeks, and most of them never touch the IT budget at all. If you run an SME with 10 to 50 employees, you can work out that number yourself, from figures you already have, without relying on anyone else's statistics.

The cost of a cyberattack, line one: days with operations stopped

Ransomware locking your servers, a compromised invoicing inbox, an order system down: all of these share one effect, they stop the business while they get fixed. That time is not free. Take your average revenue and divide it by the working days in a month: that is roughly what one full stoppage day costs you. Multiply it by the days it would realistically take to get back to normal operations, not the days you would like it to take.

That number changes a lot depending on whether you have tested backups and a plan to restore them, or whether the first time you need them is the first time you find out they do not work. The gap between those two situations is measured in days, and every day carries the price you just calculated.

Staff hours that nobody bills for

While an incident runs its course, someone has to handle it. Usually that is whoever also happens to manage your IT, plus admin staff, customer service explaining delays, and management coordinating the response. That time disappears from their normal work and never shows up on an invoice. It still has a real cost: their hourly cost multiplied by the hours spent putting out the fire instead of doing their job.

In a company with no dedicated security function, this diversion tends to run longer than expected, because someone has to learn what happened before anyone can fix it.

Emergency outside help and rebuilding systems

If you do not already have a trusted provider when the incident happens, you end up hiring whoever can show up that week, and that work gets billed at emergency rates, not at the price of a planned contract. On top of that comes the rebuild: reinstalling systems from scratch, recovering or recreating data that had no clean backup, and reconfiguring everything that was lost. That is separate work from the stopped days, and it gets invoiced separately too.

A cybersecurity risk assessment done calmly, before anything happens, is exactly what surfaces these weak points (untested backups, unpatched systems, poorly configured access) so the response to an incident does not start from zero.

Customers and contracts that leave quietly

Most customers lost after an incident do not send a letter explaining why. They simply do not renew, or they hand the next contract to a different supplier. If your company works with larger clients, it is increasingly common to receive a security questionnaire before signing or renewing a contract, and a recent incident makes those questions much harder to answer.

Think about how many of your current clients depend on you hitting deadlines and on trusting how you handle their data. That is the second number you can estimate yourself: how much each of those clients bills you a year, and how many of them you could afford to lose.

When personal data is involved: GDPR

If the incident affects personal data belonging to customers, employees or suppliers, GDPR comes into play. Article 33 requires notifying the supervisory authority within 72 hours of becoming aware of the breach, which means investigating the scope fast, almost always with legal help. On top of that comes notifying the affected individuals themselves, where required.

GDPR also sets maximum fine ceilings of up to 10 million euros or 2% of global turnover for certain infringements, and up to 20 million euros or 4% for the most serious ones. These are legal ceilings, not a prediction of what any single company will pay. They still explain why compliance work after a breach (documenting, notifying, answering questions from clients and the authority) is neither optional nor quick.

Insurance goes up and the questionnaires arrive

After a declared incident, renewing cyber insurance usually costs more and demands more paperwork to prove which controls you have put in place. And it is not only the insurer asking: clients who already send you security questionnaires before signing will make them more thorough if they know about the incident, and clients who do not send them yet will probably start.

A periodic security assessment generates exactly the documentation those questionnaires ask for: what was reviewed, what was fixed and when. Having it ready before it is requested changes how much internal time answering actually takes.

Work out your own number

None of these components needs an outside statistic. You can build your own figure from what you already know about your business:

  • Average daily revenue, multiplied by the real days of stoppage.
  • Staff hours diverted from their jobs, multiplied by their hourly cost.
  • Budget for emergency outside help and for rebuilding systems.
  • Annual billing from customers you could lose or who would not renew.
  • Legal and administrative hours if personal data was affected.
  • Expected increase in insurance and in time spent on client questionnaires.

Add up those six lines and compare them with what it would cost, month by month, to have the problem under control before it happens: tested backups, systems reviewed on a regular schedule, and a clear plan for who does what on day one of an incident. Prevention does not remove the risk. It turns an unpredictable bill into a monthly cost you can plan for. The practical first step is usually the same for any SME: know, from real data, where your weak points sit today.

Want to know how exposed your website is?

Ciphraverse's Security Assessment checks websites, portals and e-commerce with a professional external audit designed for SMEs.

Discover Security Assessment