What a Data Breach Actually Costs

Reading Time: 2 minutes
Add as a preferred source on Google

What a data breach actually costs a business

The cost of a data breach is mostly not the penalty. It is the investigation to establish what happened, notifying everyone affected, the time the business cannot trade normally, and the customers who leave afterwards. For a small business those costs arrive at once and are disproportionate to the size of the breach.

Five costs, and prevention is cheaper than any of them.

Investigation and notification

You must establish what was accessed, which usually requires outside technical help charged at day rates. Until you know, you cannot tell anyone anything accurate.

Then notification: data protection law requires you to inform the regulator and the people affected where a breach creates risk, overseen by the Information Regulator. That is a real administrative cost and a very public one.

Downtime and recovery

Systems may be unusable while being examined or rebuilt, and ransomware means either restoring from backup or not operating. A business that cannot invoice or trade for days loses revenue that never returns.

This is where a tested backup pays for itself many times over, and where an untested one fails at the worst possible moment.

Customers, contracts and insurance

Customers leave after a breach, particularly where their information was involved, and corporate clients increasingly impose data protection obligations contractually, so a breach can cost a contract as well as a relationship.

Cyber cover pays some of this, and insurers increasingly require specific controls such as two-factor authentication and tested backups as a condition. Not having them can void a claim entirely, which turns a covered loss into an uncovered one.

Prevention is the cheapest line

Two-factor authentication on email and banking, unique passwords in a password manager, prompt updates, access limited to what each person needs, and a backup you have actually restored.

Those five prevent most incidents and cost almost nothing. The most expensive attack on small businesses is not sophisticated: it is a compromised email used to send changed banking details, prevented by phoning a number you already held.

Frequently asked questions

What is the largest cost of a breach?

Not the penalty. Investigation, notification, downtime and lost customers usually exceed it, and arrive at once.

Do I have to tell anyone?

Yes. Data protection law requires notifying the regulator and affected people where the breach creates risk.

Why does downtime cost so much?

Because systems may be unusable while examined or rebuilt, and a business that cannot invoice or trade loses revenue permanently.

Will insurance cover it?

Partly, and only if you met the conditions. Missing controls such as two-factor authentication or tested backups can void a claim.

What prevents most incidents?

Two-factor authentication, unique passwords, prompt updates, limited access and a backup you have actually restored.

Originally published in July 2018. Updated September 2026 into an account of what a data breach actually costs a small business.

Tshepho Joel - author photo

Edited by
Tshepho Joel

Tshepho Joel is an experienced digital strategist with a proven track record of lifting user retention, leads, and revenue. Drawing on a robust background in performance marketing, he brings a data-driven, results-first eye to his work. Above all, he is dedicated to helping South African entrepreneurs start, fund, and grow their businesses.

Get Weekly 5-Minutes Business Advice

Global Subscription Form
Global Subscription Form