Average UK breach cost is £3.4 million (IBM 2024). SME incidents average £8,500-£25,000 directly, but total impact including downtime, reputation, and recovery often exceeds £100,000. The cost of prevention is almost always less than the cost of breach.
Quick answer: Average UK breach cost is £3.4 million (IBM 2024). SME incidents average £8,500-£25,000 directly, but total impact including downtime, reputation, and recovery often exceeds £100,000. The cost of prevention is almost always less than the cost of breach.
The Numbers
Large organisations
IBM Cost of a Data Breach Report 2024:- UK average: £3.4 million per breach
- Healthcare highest: £5.1 million average
- Financial services: £4.5 million average
- 277 days average to identify and contain
SMEs
UK Government Cyber Security Breaches Survey 2024:- Average cost (all incidents): ~£8,500
- Material breach average: £15,000-£25,000
- Does not include indirect costs
Cost Components
Immediate costs (obvious)
Incident response
- Forensic investigation: £5,000-£50,000+
- Legal counsel: £10,000-£100,000+
- PR/crisis communications: £5,000-£50,000
- Regulatory notifications: Time and resources
- System restoration: £10,000-£100,000+
- Security improvements (emergency): £20,000-£200,000+
- Data recovery: Variable
- New security tools: Capital expense
- ICO fines: Up to £17.5 million or 4% global turnover
- Sector-specific regulators: Additional penalties
- Most SME fines: £10,000-£500,000 range
Hidden costs (often larger)
Business interruption
- Revenue loss during downtime
- Productivity loss
- Contract delays
- Opportunity cost
- Customer churn (varies by industry)
- Customer notification costs
- Credit monitoring provision
- Customer compensation
- Brand value decrease
- Lost future business
- Damaged partnerships
- Trust erosion
- Increased insurance premiums
- Higher security spending
- Ongoing legal exposure
- Recruitment challenges
Real SME Scenarios
Scenario 1: Ransomware attack
Fictional 50-person professional services firmDirect costs:
- 5 days downtime: £75,000 lost revenue
- Incident response: £15,000
- System rebuild: £25,000
- Improved security: £20,000
- Staff overtime: £10,000
- Project delays: £30,000
- One client lost: £50,000/year ongoing
- Insurance increase: £5,000/year
Scenario 2: Data breach (customer data)
Fictional 30-person online retailerDirect costs:
- Forensics and legal: £25,000
- ICO fine: £50,000
- Customer notification: £5,000
- Credit monitoring offer: £15,000
- Lost sales during incident: £40,000
- Customer churn (20%): £100,000+ ongoing
- Reputation recovery: Unknown
Scenario 3: BEC fraud
Fictional manufacturer, finance team trickedDirect loss: £180,000 transferred Recovery: £0 (funds gone) Investigation: £10,000 Additional controls: £15,000 Insurance claim: £150,000 recovered (policy limit)
Net loss: £55,000 plus unquantified trust damage
Cost vs Prevention
| Prevention Measure | Annual Cost | Breach Cost Avoided |
|---|---|---|
| MFA everywhere | ~£0 (built in) | Most account takeover |
| EDR/MDR | £3,000-£8,000 | Ransomware, malware |
| Security training | £2,000-£5,000 | Phishing, BEC |
| Proper backup | £2,000-£6,000 | Ransomware recovery |
| Email security | £2,000-£5,000 | Phishing, BEC |
Prevention costs less than one incident.
Making the Business Case
To leadership:
- Average breach cost vs security investment
- Probability of breach (1 in 3 businesses report incidents annually)
- Competitor incidents (public examples)
- Insurance requirements
- Cost of controls: £X/year
- Breach probability reduction: Y%
- Potential breach cost: £Z
- Expected value of protection: Z × Y
- Compare X to (Z × Y)
What We Help With
We help clients understand and manage breach risk:
- Prevention: Security controls that reduce breach likelihood
- Preparation: Incident response planning
- Response: Support when incidents occur
- Recovery: Getting back to normal quickly
---
*Disclaimer: Cost figures are based on industry research (IBM, UK Government surveys) and indicative scenarios. Actual breach costs vary enormously based on breach type, data involved, response effectiveness, and regulatory outcomes. These figures illustrate potential impact, not predictions for your organisation.*
---
about security assessment.
---
