Connect with us

Hi, what are you looking for?

HEADLINES

Real business loss from cyberattacks now $861K per security incident

Although the most frequent cost is for additional staff wages, businesses reported significant spending due to lost business opportunities, improvement in IT security, employing external specialists and hiring new staff.

On average, a single cybersecurity incident now costs large businesses $861,000. Meanwhile, small and medium businesses (SMB) end up paying $86,500. Most alarmingly, the cost of recovery significantly increases depending on the time of discovery.

kaspersky

SMBs tend to pay 44% more to recover from an attack discovered a week or more after the initial breach, compared to attacks spotted within one day. Enterprises pay a 27% premium in the same circumstances.

These are the main findings of Kaspersky Lab’s report “Measuring the Financial Impact of IT Security on Businesses” based on the 2016 Corporate IT Security Risks survey.

In the 2016 survey, Kaspersky Lab for the first time compared an organization’s security budget to losses incurred from serious incidents. Overall, businesses expect IT Security budgets to grow at least 14% over the next three years, due to the increased complexity of IT infrastructure.

A typical small business currently spends 18% of their total IT budget on security, whereas enterprises allocate 21%. The research shows a significant disparity between businesses of differing sizes, with annual security budget varying from just $1,000 for very small businesses to more than one million US dollars for large companies.

Advertisement. Scroll to continue reading.

To estimate the total cost of recovery, Kaspersky Lab and B2B International asked businesses to report their losses from the most serious security incident in different categories.

Although the most frequent cost is for additional staff wages, businesses reported significant spending due to lost business opportunities, improvement in IT security, employing external specialists and hiring new staff.

Enterprises spend $79K on training and $85K on requesting help from external experts –19% of the total loss.

“Based on our worldwide survey, the average IT security budget is ‘worth’ just 2.5 cyberattacks once all direct and indirect losses are taking into account. With thousands of threats attacking corporate world every day, an efficient cybersecurity definitely pays off. Businesses understand the threat clearly; 59% of SMBs and 62% of enterprises say they will improve their security regardless of an ability to measure return,” said Vladimir Zapolyansky, head of SMB marketing, Kaspersky Lab. “However, the survey proves that reaction time post-breach has a direct impact on financial losses. This is something that cannot be remedied via budget increases. It requires talent, intelligence and an agile attitude towards protecting one’s business. As a security vendor, our goal is to provide tools and intelligence for businesses of all sizes, keeping in mind the difference in ability to allocate security budgets.”

Advertisement. Scroll to continue reading.
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Maya has already integrated National ID eVerify, the Philippine Statistics Authority’s identity-verification service, into its onboarding process. Since early this year, eligible customers have been...

HEADLINES

In 2025 alone, Converge denied nearly 12 billion entry requests to websites hosting dangerous, inappropriate, and harmful content that attempted to pass through its...

HEADLINES

The announcement represents one of the first major third-party technology integrations following the launch of Sophos Fusion, demonstrating Sophos' commitment to an open ecosystem...

HEADLINES

APAC consumers are more concerned about digital tech usage for crime than consumers globally (35% vs 32%). The awareness is highest in Thailand (39%),...

HEADLINES

To help organizations address the challenges they face as a result of the cyber skills gap, the award-winning Fortinet Training Institute provides one of the largest...

HEADLINES

“It is the time for Radenta to demonstrate that it is strongly committed to protecting client data,” remarks Nereo Bolante, Co-Director, Radenta Ethics, Compliance, and Governance Team...

HEADLINES

Attackers are operationalizing artificial intelligence (AI) to collapse attack workflows from weeks to days. The report finds that AI’s most immediate impact on cybercrime...

HEADLINES

In July 2026, researchers from the Kaspersky Global Research and Analysis Team (GReAT) team identified a new campaign, dubbed GoSerpent, representing a sophisticated and...

Advertisement