
Every year, a headline number makes the rounds: the average data breach now costs millions of dollars. It’s meant to grab attention, and it does — but it also leaves most small business owners with the wrong idea. That multimillion-dollar figure is pulled from a global sample dominated by large enterprises. It tells you almost nothing about what a breach would actually cost a five-person shop or a twenty-employee firm.
So let’s separate the headline from the reality, and look at what breaches actually cost businesses your size — and where that money goes.
The headline number, and why it doesn’t apply to you
IBM’s 2026 Cost of a Data Breach report put the global average incident at roughly $4.4–5 million, with U.S. organizations averaging over $10 million. Those figures come from a sample that includes major corporations with huge customer databases, regulatory exposure, and breaches that make national news. A small business with a few thousand customer records isn’t playing in that league, and using that number to size up your own risk will either scare you into paralysis or, just as often, make your actual risk feel unbelievable and easy to dismiss.
Download the cyber security business checklist

What a small business breach actually costs
The more useful numbers come from research that looks specifically at smaller organizations:
- IBM’s most recent breakdown by company size put the average breach cost for organizations under 500 employees at around $3.31 million — still a large number, but this includes mid-sized firms with hundreds of employees.
- Verizon’s Data Breach Investigations Report puts a more realistic range for typical small business incidents at roughly $120,000 to $1.24 million.
- Industry tracker TechAisle estimates the broader small-and-mid-size business average closer to $1.6 million.
- A large share of breached small businesses land well below the eye-popping averages: research from security firm Astra found about two-thirds of breached SMBs reported losses between $10,000 and $100,000, with roughly 1 in 7 exceeding $100,000.
The honest takeaway: most small business breaches don’t cost millions, but even the lower end of that range is a serious hit. A $50,000–$150,000 loss is enough to wipe out a quarter’s profit for a lot of small operators, and that’s before counting the time and stress of dealing with it.
Where the money actually goes
A breach isn’t one bill — it’s several, and they show up in different places:
- Detection and forensics. Figuring out what happened, what was accessed, and whether attackers are still inside your systems usually means bringing in outside specialists.
- Downtime. Recent industry research puts the cost of cyberattack-related downtime at tens of thousands of dollars per hour for businesses that depend on their systems to operate — and breaches commonly take days or weeks to fully contain.
- Notification and legal costs. Most states require you to notify affected customers, and some require credit monitoring or regulatory reporting, each with its own cost and deadline.
- Lost customers. Trust doesn’t recover instantly. Multiple surveys find a meaningful share of consumers say they’d stop doing business with a small company after a breach involving their data.
- Ransom payments, where relevant. The majority of small business breaches now involve ransomware, and even when a ransom is paid, it rarely covers the full cost of recovery — downtime and rebuilding systems typically cost more than the ransom itself.
- Rising insurance premiums. A breach on your record makes cyber insurance more expensive, or harder to qualify for, going forward.
A myth worth retiring
You’ve probably seen the claim that 60% of small businesses close within six months of a cyberattack. It’s one of the most repeated cybersecurity statistics — and it’s also been publicly disavowed by the organization it’s usually attributed to, which could no longer trace it to a credible source. Repeating it doesn’t help anyone make better decisions.
The real risk is less dramatic but still serious: in one recent survey, 40% of small business owners said a cyberattack costing $100,000 or less would be enough to put them out of business. You don’t need a mythical statistic to justify taking this seriously — the real numbers already do that.
What actually lowers the cost
The research is consistent on a few things that measurably reduce what a breach ends up costing:
- Having an incident response plan. IBM’s data shows that organizations with a tested plan save an average of roughly $230,000 per breach compared to those without one — largely because they contain the incident faster and avoid guessing under pressure.
- Tested backups. Businesses that can restore clean data quickly avoid both ransom payments and extended downtime.
- Multi-factor authentication and basic access controls. These remain some of the cheapest, highest-impact defenses available, and they show up repeatedly in breach reports as a factor that limits how far an attacker gets.
- Cyber insurance. It won’t prevent a breach, but it changes who absorbs the forensic, legal, and notification costs when one happens.
The bottom line
A data breach probably won’t cost your business $5 million. But research on businesses your size suggests it could realistically cost anywhere from tens of thousands to well over a million dollars — and the businesses that come out the other side intact are almost always the ones that had a plan before they needed one.
If you haven’t assessed where your business stands, the companion Small Business Cybersecurity Risk Checklist walks through the most common gaps — weak passwords, missing employee training, delayed updates, untested backups, and unsecured networks — and gives you a simple score to work from.
Leave a Reply