Threats 7 min read

The Real Cost of a Data Breach for a Small Business

IBM's annual "Cost of a Data Breach" report says the average breach costs $4.88 million. That number is useless for you. Here is what a breach actually costs a company with 12 employees — broken down line by line, based on real cases.

Three real small business breaches — actual costs

Case 1: Law firm, 8 employees. Email account compromised via phishing. Attacker accessed 3 years of client communications. Total cost: $87,000. Forensic investigation: $18K. Legal counsel: $22K. Client notification: $12K. Credit monitoring for affected clients: $5K. Lost billable hours during recovery: ~$30K. Insurance covered $65K after $10K deductible.
Case 2: E-commerce retailer, 5 employees. WooCommerce site compromised. Payment skimmer installed on checkout. 1,200 customer cards stolen over 3 weeks before detection. Total cost: $52,000. Forensics + site cleanup: $15K. PCI-DSS fine: $10K. Customer notification + credit monitoring: $8K. Chargeback fees: $5K. Revenue lost during 4-day site shutdown: $14K.
Case 3: Accounting firm, 15 employees. Ransomware via unpatched firewall. All files encrypted including tax returns in progress during tax season. Total cost: $215,000. Ransom payment: $50K (they paid). Forensics + restoration: $35K. Hardware replacement: $20K. Lost revenue (2 weeks downtime during tax season): $80K. Reputation damage / client churn (estimated): $30K.

Where the Money Goes — Line by Line

Every breach is different, but the costs fall into the same buckets every time. The order and amounts vary, but the buckets are consistent:

Cost CategoryTypical RangeWhat It Pays For
Forensic Investigation$10K–$50KDetermining what happened, what data was taken, whether the attacker is still in your systems. This is the first call you make, and it is never cheap.
Legal Counsel$15K–$40KUnderstanding your notification obligations across 50 states (or multiple countries), defending against lawsuits, negotiating with regulators.
Customer Notification$5K–$20KMailings, call center, credit monitoring for affected individuals. Some states require credit monitoring for 1-2 years if SSNs were exposed.
Regulatory Fines$5K–$100K+GDPR, HIPAA, state AGs, PCI-DSS. This varies wildly based on what data was exposed and whether you were negligent.
System Remediation$5K–$35KCleaning malware, rebuilding servers, restoring from backups, upgrading the systems that failed.
Business Interruption$10K–$100K+Revenue lost while your business is partially or completely offline. This is usually the biggest line item, and it is almost never fully covered by insurance.
Reputation / Client Loss$0–$50K+Clients who leave, deals that fall through. Hard to quantify immediately, but real.

The Insurance Math

Cyber insurance helps — but it is not a free pass. Here is what a typical small business policy looks like in practice:

  • Deductible: $5,000–$25,000. You pay this first, before insurance kicks in.
  • Coverage limit: $250K–$1M for a typical small business policy. Above that, you are on your own.
  • What is covered: Forensics, legal, notification costs, credit monitoring, ransom payments (usually with sub-limits).
  • What is usually NOT covered: Lost revenue, reputational damage, regulatory fines (varies by policy), the cost of upgrading systems after the breach.
  • What voids your policy: Not having MFA enabled. Not having backups. Lying on your insurance application about your security measures. All three of these are increasingly common reasons for claim denial.

The Single Most Expensive Mistake

In all three cases above — and in nearly every small business breach I have studied — the root cause was something that would have been prevented by one of these four things:

  1. MFA on email. Prevents account takeover. Free. Takes 10 minutes. Blocks the #1 attack vector.
  2. Automatic updates. The e-commerce breach was a WooCommerce plugin with a patch that had been available for 6 months.
  3. A tested backup. The accounting firm had backups — on the same network as their main systems. The ransomware encrypted both. The off-site backup they "kept meaning to set up" would have saved them $50K and two weeks of downtime.
  4. Someone asking "does this look right to you?" The law firm breach started with a phishing email that three people recognized as suspicious — but nobody reported it because they assumed someone else would. Create a culture where reporting suspicious emails is celebrated, not ignored.

The Takeaway

A data breach will cost you somewhere between $50,000 and $250,000 depending on your size, your industry, and how fast you detect it. Insurance will cover 60-80% of the direct costs — if you have it and if you have not voided your policy by neglecting basic security.

Or you can spend two hours enabling MFA, setting up automatic updates, and testing a backup. That costs approximately nothing and reduces your breach risk by an order of magnitude.

The frustrating thing about small business security is that the most effective measures are also the cheapest. The expensive part is fixing things after they break.