How much will a data breach actually cost you?

What comes to mind when someone says "data breach"? Maybe you picture it as a big problem you'll resolve in a few days — at worst, a few weeks; that it'll hurt but won't sink you, and you won't have to live with it for…

What comes to mind when someone says "data breach"? Maybe you picture it as a big problem you'll resolve in a few days — at worst, a few weeks; that it'll hurt but won't sink you, and you won't have to live with it for long. If so, I have bad news: up to 49% of all costs tied to data breaches show up more than a year later. In today's post I'll show how these breaches can drag on for you.

Financial damages

Let's start with the obvious. Data breaches cost serious money in things like:

·         Lawsuits

·         Customer notifications

·         "Compensation" for customers

·         Hardening your cybersecurity posture

Reputation damage

If you suffer a breach, it's going to follow you for a long time. This is the cost item that drags on the longest and ends up costing you the most over time. Loss of customer trust translates, for most businesses, into bankruptcy. Not to mention that potential new customers can be put off by it.

Operational disruption

A data breach almost always leaves a mark on company operations too. Put simply: you can't focus on everything. If you're rebuilding a system, you can't run as usual and earn money. So it's also worth flagging the lost income while you're not operating.

Loss calculation

It's worth running at least a rough loss calculation. The real cost of an attack like this is the sum of:

·         Penalties and litigation costs

·         The cost of reputation damage

·         Lost income for the duration of the recovery

Of course these numbers will vary a lot, but it's good to put yourself in context — even based on a hypothetical case — and find out how big a problem this would actually be for your business.

2026 update: what our own data says

When we first wrote this article, the numbers were theoretical. Today we have our own: 262 companies have run our free online audit. 151 of them — more than half — had at least one serious finding visible from the internet: leaked employee passwords, vulnerable services exposed to the network, open access points. And 191 companies — seven in ten — had misconfigured e-mail (SPF, DKIM or DMARC), which is precisely the gap that lets an attacker send your customers an invoice that looks like yours. Just with a different account number.

A data breach rarely starts with anything dramatic. It starts with a password leaked elsewhere and tried on your accounts; access left open after a former colleague; an update postponed for a year. How to close those doors is covered in our articles on patch management and EDR — and if you want to know where you stand right now, run the free audit: 13 checks, 5 minutes, no meeting. The report lands in your inbox. We only get in touch if something changes for the worse.