The image represents the theme and title of the article: The Real Cost of a Cybersecurity Breach (And Why It’s More Than the Ransom). There is a photo of two people sitting in an office, and on the right handside, a large dollar sign composed of digital nodes.

The Real Cost of a Cybersecurity Breach (And Why It’s More Than the Ransom)

Quick Summary: What is the cost of a cybersecurity breach?

A single cybersecurity breach can cost a small business $50,000 to $500,000 or more, and recovery can take four to six weeks. This price tag goes far beyond any ransom payment. It includes lost productivity and downtime, customer attrition, reputational damage, and other recovery costs. By comparison, a baseline security program starting at around $1,000 a month makes prevention a far more manageable cost than dealing with the financial and operational fallout of a breach.

Most small and mid-sized business owners know a breach would be bad. What’s harder to know is how bad. Would it mean a few days of disruption and an IT bill, or weeks of lost revenue and customers who don’t come back? Without a concrete number attached, the cost of a breach is hard to picture, and harder to plan around.

That gap shows up most when it’s time to decide on security spending. If you’ve thought about upgrading your protection, the question probably stalled on whether it’s worth the money. For a smaller business, a monthly security bill is a line item that has to be justified against everything else in the budget. Doing nothing feels free by comparison, so the decision gets put off.

Ironclad TEK works with Calgary businesses of all sizes to prevent breaches and navigate the aftermath when they happen, and most owners we talk to want a clear picture of the stakes before they spend anything. In this article, we’ll break down the real cost of a breach, what that cost is made up of, and how it compares with the cost of putting stronger security in place before something goes wrong. Then you can decide what makes sense for your business.

Why the Math on Prevention vs. Recovery Is So Lopsided Now

For a smaller business, the clearest way to see the stakes is to put a monthly security budget next to the cost of a single incident.

“Smaller businesses are more budget-conscious, so they don’t really want to spend the money [on IT security],” says Chad Cunningham, Director of Business Development at Ironclad TEK. “It’s not to terrify people, but it’s the old saying: an ounce of prevention is worth a pound of cure. You might spend around $1,000 a month to secure all your devices, users, and email accounts, and that can seem like a lot of money. But a single event could cost you $50,000, $100,000, $500,000. And beyond the cost, there’s your company’s reputation, and how long your business is interrupted.”

The cost of prevention scales with the size of your business. Ironclad TEK estimates the annual prevention investment for a small business – fewer than 50 seats – would range from $10,000 to $50,000 per year, but a single breach event could cost 100 times that amount.

That’s in line with what most businesses already budget: according to Chad, most Canadian small and mid-sized businesses spend about 1% to 3% of revenue on IT, with 10% to 20% of that going to cybersecurity.

The gap gets wider once you account for the full national picture. IBM’s 2026 Cost of a Data Breach Report found that the average cost of a data breach at a Canadian organization reached $5.2 million in 2026, with global breach costs increasing 12% in the last year. This figure is not separated by company size, so it blends in large enterprises alongside small businesses like yours. Even well below that average, a single breach can cost many times what a year of prevention does.

Cybersecurity Economics
Typical Annual Prevention Single Breach
Canadian SMB $10K-$50K $50K-$500K
Financial Impact Predictable Budget Catastrophic Loss
Business Effect Reduced Risk Operational Disruption
ROI Controlled Investment Potentially Business-Threatening

Chad puts the cost-versus-risk calculation into a comparison most business owners can relate to: “It’s like having car insurance. You’ve got to have it; it’s the law. But if it was optional, a lot of people would say I’m not going to bother, because I don’t want to pay the money. But what happens when your car crashes? People tend to think short-term. They’d rather save five dollars today and risk $5,000 tomorrow.” Security spending runs on the same logic, minus the legal requirement forcing the decision. The four-figure monthly bill looks avoidable right up until the much larger one arrives.

“The factors are wildly off now compared to what they used to be,” says Trond Aarflot, Director of Technology and Operations at Ironclad TEK. “The average recovery is four to six weeks.” The four-to-six-week recovery window is a cost in its own right. A cyber incident that takes a month or more to fully recover from affects how your business operates long after the initial breach is contained. For a small business, that can mean weeks of closed doors or running on paper and phone calls, and that downtime is where the losses start to compound.

Downtime Costs You Customers Long Before the Technical Fix Is Done

You already know how quickly customers move on when your business is difficult to reach. A missed call, unanswered email, or delayed response can be enough to send someone looking elsewhere. Trond points to a common rule of thumb: if a call isn’t returned within two hours, customers try someone else. That’s the baseline standard for a business operating normally.

Now stretch that inconvenience from two hours to four to six weeks. Even if you can keep some operations running through manual workarounds, customers still need to be served. Questions need to be answered, and orders need to move. The longer those basic functions are disrupted, the more opportunities there are for customers to find an alternative.

Trond is direct about what that means: “If you’re down for four to six weeks, you’ve probably lost most of your customers.”

Reputational Damage Outlasts the Technical Recovery

Losing customers during an outage is only part of the damage. A prolonged disruption can change how customers, partners, and prospects perceive your business long after the technical problem has been resolved.

Email lockouts make this easy to picture. If your team suddenly loses access to email, customers don’t necessarily know there’s a technical problem behind the silence. They stop hearing from you. And if cybercriminals have taken over the account, they can keep using it to reply to your customers as if they were you. “Imagine a company is locked out of their email, and now you’ve got people responding to your customers,” says Chad. “That would be horrible. You may get it restored and get it back, but the damage that’s been done to your reputation is very hard to repair.”

The technical recovery has a defined endpoint: systems are restored, accounts are accessible, and operations can resume. Trust doesn’t work on the same timeline. A customer who experienced weeks of silence, or received messages from someone posing as you, may remember it the next time they’re deciding where to spend their money. A prospect may not get far enough into the relationship to experience your business at its best.

That’s why reputation belongs in the cost of a breach, even though it’s much harder to put a precise dollar figure on it.

What Actually Makes Up the Cost of a Breach

Downtime and reputational damage are only part of the total. When a breach hits, the costs arrive from different directions over weeks and months, often while you’re still trying to get your business running again. Most of them fall into a few categories:

  • Detection and investigation work to figure out what happened and contain it
  • Rebuilding systems and restoring data
  • Notification and legal obligations if customer or employee data was involved
  • Compliance remediation to close any regulatory gaps the breach exposed
  • The ransom or extortion payment itself, if one gets made
  • Lost business from customer turnover and downtime, covered above

Published research backs up how much of this cost sits outside the ransom payment. Sophos surveyed 3,400 organizations hit by ransomware for its State of Ransomware 2025 report and found that recovery alone, excluding any ransom paid, averaged US$1.53 million globally. The ransoms themselves were often just as large: just over half of ransom payments were US$1 million or more.

Ransomware is also far more common in small-business breaches. Verizon’s 2025 Data Breach Investigations Report found that ransomware was involved in 88% of breaches at small and medium-sized businesses, compared with 39% at larger enterprises. Smaller businesses tend to have fewer defenses to get through, which makes ransomware an easy, reliable way in for attackers.

Every breach is different, but the cost can quickly extend far beyond the technical problem itself. That potential outcome raises a critical question: what does it take to reduce that risk in the first place?

What a Realistic Prevention Baseline Actually Looks Like

Cybersecurity spending is easier to evaluate when you know what you’re paying for. Insurance can help offset certain costs after an incident, but it isn’t a substitute for prevention. A baseline security program should cover a specific, verifiable set of protections rather than a vague promise of “better security.”

Here’s what a baseline security program typically covers:

  • A regular risk assessment shows where your vulnerabilities are, so the rest of your security spending goes where it’s needed.
  • Multi-factor authentication, enforced rather than simply available as an option, on email, remote access, and admin accounts closes a common entry point attackers rely on.
  • Endpoint and network protection, including firewalls and antivirus on every device, not just the ones IT remembers to check, covers the full attack surface.
  • A consistent patching and software-update cadence closes known vulnerabilities before they get used against you.
  • 24/7 monitoring and threat detection, backed by a clear plan for responding when something is flagged, catches suspicious activity before it spreads across your network.
  • Backups tested on a regular schedule and kept isolated from your main network mean a ransomware event doesn’t also take out your recovery path.
  • Security awareness training, refreshed regularly and backed by simulated phishing tests, helps your team spot phishing emails and suspicious links before anyone clicks.

The last layer matters because even strong technical controls can’t account for every decision made by an employee during a normal workday. Phishing emails, malicious links, and other forms of social engineering can turn an otherwise well-protected environment into an entry point.

Your protection depends on these layers working together, which is why no individual piece is optional if the goal is to close the gap rather than check a box. The baseline above is the floor, regardless of which provider ends up delivering it.

Frequently Asked Questions About the Cost of a Cybersecurity Breach

How long does it typically take to recover from a cybersecurity breach?

In Ironclad TEK’s experience, recovery for small and mid-size businesses commonly takes four to six weeks, depending on how far the attack spread and how quickly it was contained. That window can mean operating on manual processes, or not operating at all, depending on which systems are affected.

Does cyber insurance cover the cost of a breach?

Not as reliably as most business owners assume. Cyber policies typically come with conditions attached, often requiring you to have specific security controls like MFA or regular patching in place at the time of the breach, and insurers can and do deny claims when those conditions weren’t met. Coverage also tends to come with sub-limits on specific cost categories (ransom payments, business interruption, legal fees), so a policy’s headline coverage amount doesn’t always reflect what actually gets paid out once a claim is processed. Treat a policy as one layer of protection against the financial hit, alongside the baseline prevention work covered above.

Does the cost of a breach vary by business size?

Larger organizations tend to see higher absolute costs, but small businesses are disproportionately affected relative to their size, since they typically have smaller cash reserves and less dedicated IT support to absorb the disruption.

Is the cost of prevention really lower than the cost of recovery?

In most cases, yes. A baseline security program can start at around $1,000 a month. A single breach can run $50,000 to $500,000 for one incident, before you count downtime, lost customers, and reputational damage.

Can a small business survive a major breach?

It depends on how long the business is down. In Ironclad TEK’s experience, a business that’s down for four to six weeks has probably lost most of its customers before systems are even back online. That gap between surviving the technical event and surviving the business consequences of it is the core argument for prevention over recovery.

The Bottom Line: Prevention Is the Cheaper Bill

A single breach can cost a small business $50,000 to $500,000 or more, with recovery taking four to six weeks. Ransom, when one is paid, is only one piece of the total. Compared with a baseline security investment starting at around $1,000 a month, the choice is stark. One is a predictable investment you can plan for. The other is a potentially enormous, unpredictable cost that arrives when you’re least prepared for it.

Time matters as much as money. Two hours is already long enough for customers to expect a response, while a serious breach can disrupt your business for four to six weeks. By the time your systems are back online, some of the relationships affected may be much harder to recover.

If you’re weighing how security fits into your overall IT budget, our breakdown of managed IT services costs in Calgary walks through what businesses typically pay, what drives the price, and how a security baseline is built into the monthly rate.

Not sure what a realistic security budget looks like for a business your size? Talk to us for a no-pressure security assessment to find out where you stand, identify the biggest gaps, and see what a realistic budget looks like before you’re dealing with the much higher cost of recovering from an incident.