When you hear about the cost of a data breach, it’s easy to focus on the obvious expenses. A ransom payment. Stolen funds. An emergency call to your IT provider.
But those are only part of the picture.
According to the Identity Theft Resource Center’s 2025 Business Impact Report, 62.5% of small businesses that experienced a breach reported a total financial impact of more than $250,000. More than a third reported costs exceeding $500,000.
How does the bill get that high?
For many businesses, it’s the combination of everything that happens after an incident. Employees may not be able to work. Customers may not be able to reach you. You may need outside cybersecurity experts, legal counsel or help recovering data. And once everything is running again, there’s still work to do to make sure the same thing doesn’t happen twice.
That’s why the actual cost of a data breach can be much higher than the amount stolen or demanded by an attacker.
Where does the money go after a data breach?
Every incident is different. An employee clicking a phishing link that gets caught quickly is a much different situation than ransomware spreading across your network overnight.
Still, most of the costs tend to fall into a few areas.
Lost time and productivity
Downtime gets expensive quickly.
Think about the systems your employees use throughout a normal workday. Email, shared files, accounting software, customer records, business applications and even phones may depend on your IT environment.
If those systems suddenly aren’t available, you could have a team of people who are ready to work but can’t.
Meanwhile, payroll continues. Customer requests keep coming in. Orders and projects may get delayed. If the outage lasts several days, you may start losing revenue or customers.
For many small to medium businesses, this is where a cyber incident starts to have a much bigger financial impact than expected.
Investigation and recovery
Once you know something happened, you need to figure out exactly what you’re dealing with.
Where did the attacker get in? What did they access? Was anything stolen? Are they still in the network? Is it safe to restore your systems?
Those questions often require more than a standard IT support call. Depending on the incident, you may need cybersecurity specialists, forensic investigators, legal counsel or your cyber insurance provider involved.
Then there’s the work of getting everything back to normal. That could include restoring data, rebuilding systems, resetting credentials, securing compromised accounts and fixing whatever weakness allowed the attack to happen.
If customer, employee, financial or other sensitive information was exposed, there may also be legal, regulatory or notification requirements to work through.
Ransomware, fraud and stolen information
Some cyberattacks also come with a direct financial loss.
Ransomware is one of the biggest concerns for small businesses. The Verizon 2025 Data Breach Investigations Report found that ransomware was involved in 88% of the SMB breaches included in its small-business analysis.
But even with ransomware, the payment demanded by the attacker is only part of the concern.
Whether you pay a ransom or not, you still have to recover. Systems may need to be rebuilt, data restored and the source of the attack addressed. If information was stolen before it was encrypted, you may also have a data breach to deal with.
Other attacks skip ransomware entirely. A compromised email account, for example, can be used to impersonate an executive or vendor and convince an employee to send money to a fraudulent bank account.
Different attack, same problem: a cyber incident can affect much more than your IT budget.
Why does one business recover quickly while another struggles?
This is where preparation really starts to matter.
Say two businesses experience similar ransomware attacks.
One has current backups that are regularly tested. Multi-factor authentication is already in place. Its network is being monitored, and the company has an incident response plan with clear steps for who to call and what to do.
The other discovers that its backups haven’t been tested recently. No one is quite sure when the attack started or which systems are affected. There’s no response plan, so the team is making decisions as they go.
Those two companies could experience very different levels of downtime and very different recovery costs, even if the initial attack looked similar.
A few factors can make a big difference:
- How quickly the incident is detected
- Whether the attacker reached critical systems or sensitive data
- Whether reliable backups are available
- How much of the business can continue operating during recovery
- Whether there is already a plan for responding to an incident
This is why cybersecurity planning isn’t only about preventing an attack. You also want to be ready to respond when something goes wrong.
What can an SMB do to reduce the risk?
You don’t need to eliminate every possible cyber risk. That isn’t realistic for any organization.
Instead, focus on making your business harder to compromise and easier to recover.
For most SMBs, that means getting the basics right: using multi-factor authentication, keeping systems patched, protecting endpoints, training employees, maintaining reliable backups and monitoring the network for suspicious activity.
The Cybersecurity and Infrastructure Security Agency (CISA) also recommends that small businesses develop an incident response plan so employees know what to do and who to contact if an incident occurs.
These protections are most effective when they work together.
Employee training might stop someone from clicking a phishing email in the first place. Endpoint protection can help catch malicious activity that gets through. Monitoring can help identify a problem sooner. And good backups can make recovery much easier if systems are damaged or encrypted.
What this looks like at CTS
At Computer Technology Solutions, we spend a lot of time helping businesses think about cybersecurity before they’re dealing with an emergency.
That means looking at the full environment and asking practical questions. Where are the biggest risks? What happens if a device or account is compromised? How quickly would we know? How would we recover?
Through our Astral Security program, CTS provides layers of protection that include security awareness training, endpoint detection and response, vulnerability management, privileged access management, SIEM, 24/7 security monitoring and incident response planning.
No cybersecurity provider can promise that a business will never be targeted or compromised. What we can do is make it harder for an attack to succeed, improve the chances of catching suspicious activity early and make sure there’s a plan for what comes next.
So, how much could a data breach cost your business?
There’s no one-size-fits-all answer.
A smaller incident that’s caught early may have a relatively limited impact. An attack that shuts down operations for several days or exposes sensitive information could cost considerably more.
The Identity Theft Resource Center finding that 62.5% of breached small businesses reported more than $250,000 in financial impact is a good reminder of how quickly those costs can add up.
For a small to medium business, the more useful exercise is to look at your own operation. How dependent are you on your technology? How long could you function without your critical systems? And if something happened tomorrow, would your team know what to do?
If you’re not sure, CTS can help you take a closer look at your current security and where there may be gaps worth addressing.
Talk to CTS about your cybersecurity risk
Frequently Asked Questions
How much does a data breach cost a small to medium business?
There isn’t one average cost that applies to every business. The severity of the attack, amount of downtime, type of information involved and recovery process all affect the total. In the Identity Theft Resource Center’s 2025 Business Impact Report, 62.5% of small businesses that experienced a breach reported more than $250,000 in total financial impact.
What are the biggest costs after a data breach?
For small businesses, major expenses can include downtime, lost productivity and revenue, cybersecurity and forensic support, data recovery, legal expenses and security improvements. Some incidents may also involve ransom payments, stolen funds or customer notification costs.
How can a small to medium business prepare for a data breach?
Start with the fundamentals: multi-factor authentication, endpoint protection, employee security training, regular patching, reliable backups and ongoing monitoring. It’s also important to have an incident response plan so your team knows what to do if something happens.
Is ransomware a concern for small to medium businesses?
Yes. Verizon’s 2025 Data Breach Investigations Report found ransomware was involved in 88% of the SMB breaches included in its small-business analysis.


