Data Breach Costs: What SMBs Pay in 2025

by The Creator | Jul 29, 2026

Business owner reviewing data breach costs and cybersecurity liability expenses on financial documents

Data breach costs have climbed to an average of nearly $5 million per incident worldwide, a figure that sounds abstract until you translate it into the language of a small manufacturer or professional services firm. For a business doing $10 million in annual revenue, a breach of that magnitude isn’t a line item. It’s an existential threat. The question most SMB owners ask isn’t whether breaches are expensive in theory, but what they’ll actually pay if an attacker gets in, and whether they can survive it.

What drives data breach costs for small and mid-size businesses?

The $5 million average masks wide variation. Healthcare breaches top the list at more than $9 million per incident, but manufacturing and professional services organizations face their own steep bills. The difference is that for smaller firms, even a $500,000 breach (well below the global average) can mean closing doors. The costs break into two buckets: direct and indirect.

Direct costs are the ones you can invoice. Forensic investigators charge $200 to $500 per hour to determine what was taken and how the attacker got in. Outside legal counsel bills for breach notification compliance, which varies by state but often requires written notice to every affected individual within 30 to 60 days. If you hold credit card data, Payment Card Industry Data Security Standard (PCI DSS) fines start at $5,000 per month until you prove remediation. If you’re a healthcare provider or business associate, Health Insurance Portability and Accountability Act (HIPAA) penalties range from $100 to $50,000 per violation. Credit monitoring services for affected customers run $15 to $30 per person per year, and if 5,000 records were exposed, that’s $75,000 to $150,000 before anyone has even filed a lawsuit.

Indirect costs hurt more because they compound over time. Customers leave. A regional accounting firm that suffers a breach loses clients who can’t afford the reputational risk of staying. Manufacturing partners halt orders until you pass a new security audit. Your cyber insurance premiums double or triple at renewal, if the carrier renews at all. Employee productivity drops during the scramble to rebuild systems, and if you’re down for three days, that’s three days of zero output and payroll you still owe.

How does AI increase data breach costs?

Attackers now use artificial intelligence to accelerate reconnaissance, craft convincing phishing emails, and exploit vulnerabilities faster than manual methods allowed. The same report that surfaced the $5 million average noted a measurable rise in AI-driven attacks, which shorten the time between initial compromise and data exfiltration. For defenders, that means less time to detect and contain the breach, and time is money. Every day a breach goes undetected adds cost. The longer an attacker has access, the more systems they touch, the more data they copy, and the harder forensics becomes.

AI also shapes the defense side. Organizations that deploy AI-powered security tools (anomaly detection, behavioral analysis, automated threat hunting) detect breaches an average of 100 days faster than those relying only on traditional signature-based tools. Faster detection directly reduces breach-related downtime and liability, because you stop the bleeding sooner. The gap between AI-assisted and manual response is widening, and SMBs without access to these tools face longer containment windows and higher bills.

What does a $5 million breach look like for a Connecticut manufacturer?

Consider a hypothetical precision parts manufacturer in Litchfield County with 80 employees and $15 million in revenue. An attacker gains access through a phishing email that harvests credentials, then moves laterally into the engineering file server and customer database. The breach goes undetected for 90 days. By the time the finance team notices unusual wire transfer requests, the attacker has copied CAD files, customer contracts, and employee Social Security numbers.

The direct costs start immediately. Forensics: $60,000. Legal counsel for breach notification and regulatory filings: $40,000. Notification letters to 1,200 customers and 80 employees: $8,000. Credit monitoring for two years: $50,000. PCI fines because the customer database included some payment card information: $25,000 over five months. Immediate tally: $183,000.

Indirect costs emerge over the next year. Two major customers terminate contracts, citing security concerns. Lost revenue: $1.2 million. Cyber insurance premium increases from $18,000 to $55,000 annually. Three employees leave during the chaos, and replacement hiring and training costs run $90,000. Productivity loss during two weeks of partial downtime and recovery: $200,000 in missed shipments and overtime to catch up. The manufacturer’s total breach impact approaches $1.7 million, and the business takes 18 months to rebuild its customer base.

That scenario sits well below the $5 million average, yet it nearly sank the company. Larger enterprises absorb similar hits because they have deeper reserves. SMBs don’t.

Do small businesses actually pay less than the $5 million average?

Often, yes, in absolute dollars. But the pain is proportionally greater. A $500,000 breach for a $3 million revenue firm is a 17 percent hit. A $5 million breach for a $500 million enterprise is one percent. The smaller company is far more likely to face bankruptcy, sell at a distressed valuation, or shutter entirely.

The other wrinkle: many SMBs don’t carry enough cyber liability insurance to cover even half the breach cost. Policies with $1 million limits sound generous until you tally forensics, legal, notification, fines, lost business, and the inevitable lawsuit from a customer whose data was exposed. Read your policy. Does it cover business interruption? Ransomware payments? Regulatory defense? Many exclude or cap those line items, leaving you to fund the gap out of operating cash.

What steps reduce data breach costs before an attack happens?

Preparation is the single biggest cost reducer. Organizations with a tested incident response plan and a designated response team cut breach costs by an average of $1.5 million compared to those without. A plan doesn’t need to be a 200-page binder. It needs contact information for your forensics firm, your legal counsel, your insurance broker, and your IT provider. It needs a decision tree: who declares the breach, who talks to customers, who notifies regulators, and who handles the press if it comes to that.

Encrypted, offline backups cut ransomware costs dramatically. If you can restore systems from a clean backup within hours, you don’t pay the ransom, and you avoid the reputational hit of negotiating with criminals. Test restores quarterly. A backup you’ve never restored is a backup you don’t actually have.

Employee training reduces the likelihood of the breach in the first place. Phishing remains the top initial access vector. Monthly simulated phishing campaigns with immediate feedback (not annual compliance videos) train your team to pause before clicking. The cost of a training platform is $3 to $10 per employee per month. Compare that to $500,000 in breach costs.

Endpoint detection and response (EDR) tools and managed detection services give you visibility into unusual behavior. A $15,000 annual investment in EDR for 50 endpoints can catch an attacker in the reconnaissance phase, before they exfiltrate data. Early detection is the difference between a $50,000 scare and a $1 million disaster.

How does cyber insurance fit into the cost equation?

Cyber liability insurance doesn’t prevent breaches, but it transfers some of the financial risk. Policies typically cover forensics, legal fees, notification, credit monitoring, regulatory fines (up to limits), and sometimes ransomware payments. Premiums for SMBs range from $1,500 to $15,000 annually depending on revenue, industry, and security posture. Carriers now require proof of multi-factor authentication, encrypted backups, and endpoint protection before they’ll quote. If you can’t demonstrate those controls, expect higher premiums or outright denial.

Insurance also gives you access to a breach response panel: pre-vetted forensics firms, PR consultants, and legal teams who’ve handled hundreds of incidents. When you’re in the middle of a breach at 2 a.m., that panel is worth its weight in gold. You’re not Googling “data breach lawyer near me” while your systems are offline.

One caution: insurance follows the policy terms. If your policy excludes social engineering (which many do), and your breach started with a phishing email that tricked your CFO into wiring $200,000, you’re on your own. Read the exclusions as carefully as the coverage grants, and ask your broker to explain every carve-out.

What should an SMB owner do tomorrow to prepare?

Start with an honest inventory. Do you have offline backups? When did you last test a restore? Do you have cyber insurance, and does it cover your actual risks? Do your employees know how to report a suspicious email? If any answer is no, that’s your starting point.

Next, document your incident response contacts. Your IT provider, your insurance broker, a local forensics firm, and an attorney who understands breach notification laws in Connecticut and any other states where you do business. Put those contacts in a printed folder (because in a breach, email may be unavailable) and share it with your leadership team.

Finally, talk to your IT provider or a cybersecurity-focused managed service provider about a security assessment. A good assessment identifies gaps (unpatched systems, missing multi-factor authentication, weak password policies) and prioritizes fixes by risk. Addressing the top five findings often costs less than $10,000 and can cut your breach likelihood and cost dramatically.

Breaches are no longer hypothetical. The $5 million average is a benchmark, not a ceiling. For SMBs, the real question isn’t whether you can afford better security. It’s whether you can afford not to invest in it.

Keep reading

Sources

Source: The Average Cost of a Data Breach Rises to $5 Million