Can’t find what you’re looking for? Call 1300 688 648 for expert IT assistance

A cyber attack on an Australian small business costs, on average, $49,600 per reported incident according to the ACSC Annual Cyber Threat Report 2023-24. For a Business Email Compromise with confirmed financial loss, that figure climbs to $55,000. And for ransomware, the attack that shuts everything down, you are looking at three to four weeks of downtime before normal operations resume. If you have been wondering what a cyber attack actually costs, this post gives you the honest numbers: direct, indirect, and the ones nobody warns you about.

This is part two of our 12-week Cybersecurity for Business series. Last week we covered what a cyber attack actually is. This week, we follow the money.

The Direct Costs: What You Pay Immediately

When an attack hits, the first wave of costs is immediate and unavoidable.

Ransom Payments

Ransomware attackers demand payment in cryptocurrency, typically ranging from tens of thousands to hundreds of thousands of dollars depending on business size. Paying does not guarantee you get your data back. According to published research, a significant proportion of businesses that pay a ransom still do not fully recover their data. Paying also puts you on a list as a business that pays.

IT Recovery Costs

Whether you pay the ransom or not, your IT environment needs to be rebuilt. This includes forensic investigation to understand how the attacker got in, rebuilding systems from scratch or from backups, security patching, and hardening to prevent re-entry. For a 25-person business, this engagement with an external incident response firm typically costs between $20,000 and $80,000 depending on complexity and the state of your backups.

Legal and Compliance Costs

Under the Australian Privacy Act, if personal information is involved in a data breach, you are required to notify affected individuals and the Office of the Australian Information Commissioner (OAIC). Organisations with a turnover above $3 million have mandatory obligations under the Notifiable Data Breaches scheme. Legal review of your breach obligations, drafting notifications, and potential regulatory response costs real money. Budget at least $5,000 to $20,000 for legal fees at the low end.

Regulatory Fines

If you fail to meet your Privacy Act obligations or your breach is found to result from serious or repeated failures in data handling, the OAIC can pursue civil penalty orders. Since the Privacy Act amendments in 2022, the maximum civil penalty increased substantially to the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover during the relevant period. Regulators do not pursue every breach, but they do pursue egregious ones.

The Indirect Costs: The Ones That Keep Adding Up

Direct costs are painful. Indirect costs are what actually cripple a business.

Downtime and Lost Productivity

The average downtime following a ransomware attack is 21 to 24 days. That is three to four weeks where your staff cannot do their jobs properly, your systems are partially or fully offline, and revenue-generating activity slows or stops completely. For a 25-person professional services firm billing at even conservative rates, three weeks of disrupted operations represents a significant revenue hole that never comes back.

Staff Time Diverted to the Incident

During and after an attack, your internal people are not doing their jobs. They are on calls with IT support, liaising with lawyers, managing upset clients, and rebuilding manual workarounds. This is not captured in any invoice, it is invisible cost. In a 25-person business, a serious incident can absorb hundreds of hours of management and staff time over the following weeks.

Client Churn and Reputational Damage

Professional services firms sell trust. When clients learn you have suffered a data breach, especially one involving their information, some will leave. The cost of client churn from a serious incident is highly variable, but even losing one or two clients represents material revenue impact. Rebuilding trust with the market takes time that cannot be billed.

The Hidden Costs Nobody Warns You About

These are the costs that catch businesses off guard, even those that planned reasonably well.

Cyber Insurance Excess

If you have a cyber insurance policy, you almost certainly have an excess. Depending on your policy, this can range from $5,000 to $50,000 or more. You pay that before the insurer covers anything.

Public Relations and Crisis Communications

If the breach becomes public , through media reporting, client notifications, or OAIC involvement, you may need external PR support to manage the narrative. Crisis communications firms charge premium rates. Even a basic engagement can run $10,000 to $30,000.

Customer Notification and Credit Monitoring

If personal information was accessed, you may need to notify every affected individual. Depending on your customer base, this involves printing and mailing letters, setting up a hotline, and potentially offering credit monitoring services to affected people. For a business with hundreds or thousands of client records, this cost scales quickly.

Productivity Loss From Rebuilding

After the acute crisis, your systems are restored but your team is not operating at full capacity. People are re-learning rebuilt environments, re-entering data that was lost, and dealing with residual anxiety. This drag on productivity often persists for weeks or months after the incident is technically resolved.

Does Cyber Insurance Cover Everything?

Honest answer: no. Cyber insurance is worth having, but it is not a substitute for cybersecurity investment, and it does not cover everything.

Most cyber insurance policies cover incident response costs, legal fees, notification costs, and some business interruption losses. However, they commonly exclude or limit coverage for:

  • Pre-existing vulnerabilities that were known but unpatched
  • Incidents resulting from failure to follow basic security practices (multi-factor authentication, patching)
  • Reputational damage and client churn
  • Ransomware payments in some jurisdictions or under some policy conditions
  • Third-party liability if client data is compromised

Insurers are also tightening their requirements. It is increasingly common for insurers to require evidence of multi-factor authentication, endpoint detection, and regular backups before issuing or renewing a policy. If your security posture does not meet their minimum standards, you may find your claim denied or your policy void.

Cost of Prevention vs. Cost of an Attack

This is the comparison every business owner should make before deciding cybersecurity is too expensive.

Basic cybersecurity for a 25-person business typically includes managed endpoint detection and response, email security (including anti-phishing), multi-factor authentication, regular patching, and a managed backup solution. Delivered through a managed security service, this commonly sits in the range of $30 to $80 per user per month. For a 25-person business, that is $750 to $2,000 per month, or $9,000 to $24,000 per year.

Compare that to a minimum realistic cost of a ransomware incident for a business of that size: $100,000 to $250,000 when you total direct costs, downtime losses, staff time, legal fees, and the excess on your insurance policy. The prevention cost is a fraction of the incident cost, and it is a predictable, budgetable expense. An attack is not.

Small Business vs. Enterprise: A Different Cost Profile

Large enterprises attract bigger ransom demands and face higher regulatory exposure, but they also have more resources to respond. They have security teams, incident response retainers, business continuity plans, and communication infrastructure already in place.

Small and medium businesses face a different risk profile. The ACSC 2023-24 report specifically noted that costs for small businesses rose by 8% in FY2023-24, reaching an average of $49,600 per reported incident. SMBs typically have:

  • No dedicated security staff
  • Fewer or no tested backups
  • No incident response plan
  • Thinner margins to absorb the financial hit
  • Greater dependency on a small number of key clients

The result is that SMBs hit by a serious attack are disproportionately likely to suffer lasting business damage, or to close entirely. According to widely cited research, a significant proportion of small businesses that suffer a serious cyber incident do not survive the following 12 months.

A Realistic Scenario: 25-Person Professional Services Firm

Here is what a ransomware incident realistically looks like for a 25-person professional services firm in Australia, an accounting practice, a law firm, or a consultancy.

Monday morning: Staff cannot access files. Systems are locked. A ransom note appears demanding $85,000 in Bitcoin.

Week 1: IT support called in. Incident confirmed as ransomware. External forensics firm engaged. Systems isolated. Business operations running on email and manual workarounds. Estimated cost so far: $15,000 in IT fees, approximately $40,000 in lost billable capacity across 25 staff, and growing.

Week 2-3: Systems rebuilt from backups (assuming good backups exist, if not, this takes longer). Legal advice sought on breach notification obligations. OAIC notified. Client notification letters drafted and sent. Total IT recovery spend: $35,000. Legal fees: $12,000. Ransom payment decision: not paid.

Week 4: Systems restored. Staff productivity at approximately 70% of normal. Three clients have requested their files and indicated they are reviewing the relationship. Cyber insurance claim submitted with $10,000 excess payable immediately.

Total realistic cost: $120,000 to $180,000 when you include IT recovery, legal fees, productivity losses, notification costs, insurance excess, and the lost revenue from the clients who left. And this is a scenario where backups existed and the ransom was not paid.

What Microsoft Copilot and AI Can Help With

AI tools like Microsoft Copilot are not a cybersecurity solution in themselves, but they are genuinely useful during and after an incident.

Documenting the incident: Copilot can help you rapidly draft a timeline of events, which you will need for your insurer, for legal purposes, and for your OAIC notification. Clear documentation speeds up the claims process and reduces legal fees.

Drafting insurance claims: Insurance claim documents require specific language and completeness. Copilot can help non-lawyers draft comprehensive, well-structured claims documentation that covers the necessary grounds.

Communicating with clients: Drafting client notifications after a breach is stressful. The language needs to be clear, honest, legally appropriate, and not unnecessarily alarming. Copilot can help you draft these communications faster and with better structure than starting from a blank page.

These tools do not prevent the attack. But they reduce the time and cost of the aftermath, which matters when every day of disruption is costing you money.

Frequently Asked Questions

What is the average cost of a cyber attack for an Australian small business?

According to the ACSC Annual Cyber Threat Report 2023-24, the average self-reported cost of cybercrime for small businesses in Australia was $49,600 per reported incident. For Business Email Compromise with confirmed financial loss, the average was $55,000.

How long does it take to recover from a ransomware attack?

The average downtime following a ransomware attack is 21 to 24 days. Full recovery, including staff productivity returning to normal and business processes stabilising, often takes longer.

Does cyber insurance cover the full cost of an attack?

No. Cyber insurance covers some costs including incident response, legal fees, and notification costs, but it does not cover reputational damage, client churn, or incidents where basic security practices were not in place. You also pay an excess before the insurer covers anything.

What is the cheapest way to protect my business from a cyber attack?

The highest-value foundational steps are multi-factor authentication, regular software patching, tested backups stored offsite, and staff awareness training. These reduce your risk significantly and are the minimum most cyber insurers now require. A managed cybersecurity service bundles these and more at a predictable monthly cost.

Should I pay the ransom if my business is attacked?

The Australian Government and the ACSC advise against paying ransoms. Paying does not guarantee recovery of your data, can mark your business as a willing payer, and may potentially breach sanctions laws depending on who the attacker is. Engage an incident response firm before making any decision.

How do I know if my business is at risk?

All businesses with internet-connected systems and staff who use email are at risk. Professional services firms are specifically targeted because they hold sensitive client data and often have limited security investment relative to the value of that data. The ACSC 2023-24 report confirmed that ransomware accounted for 11% of all cyber security incidents ASD responded to that year, with the frequency increasing year on year.

The Bottom Line

A cyber attack does not cost tens of thousands of dollars. It costs hundreds of thousands of dollars when you account for everything, and it can cost your business its future if you are not prepared to absorb that kind of hit.

The businesses that recover well are the ones that invested in prevention before they needed it. Backups, multi-factor authentication, trained staff, and a managed security layer are not nice-to-haves. They are the difference between an incident you survive and one you do not.

If you want to understand where your business stands and what a realistic security posture would cost, book a no-obligation conversation with the Otto IT team. We work specifically with professional services firms across Australia, and we will give you straight answers about what you actually need.

managed it support articles

Related Blog Articles

Discover more insights to optimise your business with the latest IT trends and best practices. Stay ahead of the curve by learning how to leverage cutting-edge technology for success. Explore expert advice and valuable guidance to navigate the evolving world of IT solutions

Learn More