Cyber FAQs

How much does a data breach actually cost a small business?

Quick answer: A data breach affecting 100 customer records can cost $50,000 or more to remediate, including notification, credit monitoring, and legal fees.

A data breach can cost a small business anywhere from tens of thousands to well over $100,000 when you add up every consequence. The headline technical expense is rarely the biggest line item. Recovery costs, legal notification duties, customer attrition, and regulatory exposure usually hurt more than the initial intrusion.

What costs hit a business immediately after a breach?

The first costs arrive fast and stack up simultaneously. Technical forensics to identify and close the intrusion typically run $10,000 to $50,000 depending on complexity. Most states, including Georgia, require notification to affected customers, which means letters, postage or email platform costs, and call-center staffing to handle inbound questions. Credit monitoring services for affected individuals add another layer. Emergency IT remediation, replacing compromised systems, and engaging legal counsel all happen at the same time.

For example, a small Atlanta dental practice with 15 employees gets hit by ransomware. Even without paying the ransom, the practice spends $30,000 on IT recovery and forensics, $15,000 on breach notifications and credit monitoring for patients, and loses $25,000 in revenue during the week it cannot access patient records normally. That is $70,000 from one incident, before any lawsuit or regulatory fine.

What costs follow after the immediate response?

The longer-term costs are less visible but often larger. Customers who lose confidence in a breached business do not always return. Regulatory investigations can follow when health records or financial data are involved, and fines for HIPAA violations or state consumer data law violations can reach six figures for small practices. A lawsuit from affected customers, even one that settles early, carries legal defense costs that quickly exceed the initial technical damage.

For example, a Buckhead retail business that stores customer payment data suffers a point-of-sale breach. The technical fix costs $20,000, but the payment card brands assess fraud reimbursement penalties through the acquiring bank, and two months of reduced foot traffic from press coverage adds another $40,000 in lost revenue. The final cost exceeds $100,000 for an intrusion that the IT team resolved in under a week.

What does cyber liability insurance actually cover?

A cyber policy is built to cover the costs a standard commercial policy excludes (see our guide on claims-made vs occurrence policies). It typically pays for forensic investigation, mandatory breach notification, credit monitoring for affected parties, legal defense costs, regulatory fines where insurable under state law, and business income lost during the outage. Most policies also provide immediate access to a breach response team that helps contain the incident in the first critical hours, before costs escalate further.

What businesses carry the most cyber exposure?

Any business that stores customer names, payment cards, health records, social security numbers, or login credentials has meaningful exposure, even with only a handful of employees (see our guide on does a small business need cyber insurance). Medical offices, law firms, retailers, service businesses that take card payments, and any company using cloud-based software with customer data are all in this group. The size of the business does not determine the size of the exposure: a small practice or boutique can hold as much sensitive data as a large company and typically has fewer defenses in place.

How does cyber coverage fit with other business policies?

Standard general liability and business owners policy (BOP) forms exclude cyber events. A cyber policy is typically purchased alongside a BOP or general liability policy, not instead of one. Some carriers offer a cyber endorsement on a BOP, but a standalone cyber policy generally provides broader limits and more responsive breach services (see what businesses qualify for a BOP). Cyber coverage options and pricing depend heavily on the business type, data stored, and security controls in place, including multi-factor authentication and employee training. A free coverage review can assess your current protection and your cyber exposure so a single incident does not threaten the business you have built.