Blog / Reputation and business risk
Reputation and business risk
What a Breach Really Costs a 30-Person Business (It Is Not the USD 4.99 Million Headline)
The cost of a data breach, small business edition: not the USD 4.99 million headline but eleven days of lost closings, a bank that drops you, and payroll.
The ransom they did not pay was the cheapest part
The owner of a 30-person title company in the suburbs has a good month lined up: 62 closings on the calendar, three lenders sending steady work, a new escrow officer starting Monday. On Sunday night the file server, the escrow software and the phone system all go dark. The note on the screen asks for a sum that would have been a bad quarter.
He does not pay. Good decision, and he had backups, so by day four the servers are back. The cost has only started.
For eleven days the company cannot close. Lenders have a rule: if the title company cannot confirm its wire instructions are clean, the closing moves. Forty-one closings move to the competitor across the parking lot, and the agents who moved them discover the competitor is fine. Half do not come back.
On day nine the largest lender's vendor-risk team sends a two-page letter. Pending a third-party review, the company is off the approved list. That lender was 30% of revenue.
The final tally, six months later: no ransom, USD 38,000 in forensics and legal fees, USD 21,000 in notification and credit monitoring, and roughly USD 400,000 in revenue that went across the parking lot and stayed there. Insurance paid the first two lines. Nobody insures the third.
What the heck does this mean
The cost of a data breach is not one number. It is four buckets, and for a small business the biggest bucket is the one nobody puts on a spreadsheet.
Detection and escalation is the forensics firm, the lawyers, the hours your people spend rebuilding instead of working. Notification is the letters, the call center, the credit monitoring, the regulator filings. Response is the ransom if you pay it, the new hardware, the overtime. Lost business is the customers who left, the contracts that paused, the bank that dropped you, the deal that went to someone with a clean questionnaire.
Business interruption is the insurance term for the income you lose while you are down. It is covered, up to a limit and after a waiting period. Lost business, the customers who do not return, is not.
Here is the question I ask every owner, calmly, because it deserves a calm answer. What price are you willing to pay to let ten years of building go away because someone overseas tricked one employee into clicking a link? Not a careless employee. A normal one, on a normal Tuesday, doing their job. The link was designed by professionals to be clicked. The question is not about the employee. It is about what stood behind them.
The numbers that matter
The global average cost of a data breach is USD 4.99 million, and the US average is USD 11.5 million, with detection, escalation and lost business together making up nearly two-thirds of the total (IBM 2026 Cost of a Data Breach Report). Scale that shape down to 30 people and the lost-business share is still the one that hurts.
The median ransom payment was USD 139,875, and 69% of victims did not pay (Verizon 2026 DBIR). The title company was in the majority, and it still lost more than the median ransom three times over.
Sixty-four percent of cyber insurance claims closed with no out-of-pocket loss to the policyholder (Coalition 2026 Cyber Claims Report). That is the good news, and it covers the buckets insurers can see. The customers across the parking lot do not appear in any claim.
What to do this week
- Put a number on your own eleven days. Take last month's revenue, divide by working days, multiply by ten. Then add the one customer or lender you could not afford to lose. That figure is your real breach cost, and it is what your security budget should be measured against. (CIS 17 Incident Response Management)
- Test a restore this week, not a backup. Pick one server or one cloud service and time how long it takes to bring back a file from an offline copy. If nobody knows how, that is your first finding. (CIS 11 Data Recovery)
- Write the one-page plan with names and phone numbers: who calls the insurer, who calls the lawyer, who tells the lenders, who talks to customers. The title company lost two days deciding this while the phones were down. (CIS 17 Incident Response Management)
- Find the data that would make a breach reportable and shrink it. Old closing files, old customer lists, a copy of the payroll export in the finance inbox. Every record you delete is one fewer letter and one fewer reason for a customer to leave. (CIS 3 Data Protection)
- Train the team the way the attacker trains: with real-looking emails, scored, and a one-click way to report the suspicious one. The goal is a company where the first person to see the phish reports it in ten seconds, not one where someone is blamed for clicking. (CIS 14 Security Awareness and Skills Training)
- Ask your biggest customer or lender what they would need from you after an incident to keep working with you. Then make sure you could produce it in a day. (CIS 17 Incident Response Management)
Where AccuSights fits
Our assessment puts a real number on your eleven days, then shows which gaps would turn a bad week into a lost decade and what closing each one costs. Every engagement includes customized, scored security awareness and phishing training for your staff, with a one-click "report it" habit so the whole company stays protected, and no add-on charge per module. The Cyber Hygiene Test takes three minutes. A 15-minute call with an engineer gives you a plan you can show the bank.
We map the assessment to your regulators, and our read-only compliance agent shows where the gaps are and which controls have drifted, so you prioritize the right things and keep an eye on them. We have no access and do not remediate; you or your IT partner fix, and we show you where.
Questions people ask
What percentage of small businesses close after a cyber attack? Nobody has a reliable number, and the one you have probably seen, that most small businesses close within six months of a breach, has been publicly disowned by the National Cybersecurity Alliance as unverifiable. What can be measured is the shape of the loss: IBM's 2026 report finds that detection, escalation and lost business make up nearly two-thirds of breach cost. For a small business the lost-business share is the dangerous one, because it arrives after the incident is over and keeps arriving.
Does cyber insurance cover lost revenue? Many policies include business interruption cover, which pays for income lost while your systems are down, usually after a waiting period of several hours and up to a stated limit. What it rarely covers is the customer who quietly moved to a competitor during the outage and never came back, or the bank that removed you from its approved list. Read the business interruption section of your policy and note the waiting period and the limit before you need them.
How long does a small business take to recover? Systems come back in days if the backup was offline and tested, and in weeks if it was not. Cash flow takes longer, because invoicing stopped and receivables slipped. Reputation takes longest, and its timeline is set by the customers you lost during the outage rather than by anything you do afterward. The businesses that recover fastest had a written plan, a tested restore and a person who knew whom to call in the first hour.
The owner I work for is the one who finally takes the vacation they have earned and lands without wondering whether payroll is still there; everything above is how we get them on the plane.
Questions people ask
What percentage of small businesses close after a cyber attack?
Nobody has a reliable number, and the one you have probably seen, that most small businesses close within six months of a breach, has been publicly disowned by the National Cybersecurity Alliance as unverifiable. What can be measured is the shape of the loss: IBM's 2026 report finds that detection, escalation and lost business make up nearly two-thirds of breach cost. For a small business the lost-business share is the dangerous one, because it arrives after the incident is over and keeps arriving.
Does cyber insurance cover lost revenue?
Many policies include business interruption cover, which pays for income lost while your systems are down, usually after a waiting period of several hours and up to a stated limit. What it rarely covers is the customer who quietly moved to a competitor during the outage and never came back, or the bank that removed you from its approved list. Read the business interruption section of your policy and note the waiting period and the limit before you need them.
How long does a small business take to recover?
Systems come back in days if the backup was offline and tested, and in weeks if it was not. Cash flow takes longer, because invoicing stopped and receivables slipped. Reputation takes longest, and its timeline is set by the customers you lost during the outage rather than by anything you do afterward. The businesses that recover fastest had a written plan, a tested restore and a person who knew whom to call in the first hour.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
What a Cybersecurity Risk Assessment Actually Checks (and What a Free Scan Does Not)
What a cybersecurity risk assessment checks, what it costs for a company under 50 people, and why three free scans left a law firm unable to answer a client.
Practical controlsSecurity Awareness Training for a Small Business: Why the Report Button Beats the Delete Key
Security awareness training for small business that works: short, monthly, scored per person and team, tied to real threats, judged by who reports.
AI and new risksShadow AI: Your Staff Are Already Pasting Client Data Into Chatbots. Here Is the Policy.
Shadow AI is already in your business: what the 2026 breach data says about unapproved chatbots, and the one-page AI acceptable use policy that fixes it.
