Ask a business owner what a cyber attack would cost and the answer is usually a shrug toward the ransom figure in last week’s headline. The ransom, if there is one at all, is routinely the smallest line on the real invoice. The actual bill is an accumulation of ordinary business costs arriving all at once: payroll for staff who cannot work, specialists at emergency rates, customers told bad news, and weeks of management attention spent on recovery instead of revenue. This page itemises that bill honestly, because the itemised version is what makes prevention spending rational rather than fearful.

For local calibration: Scottish businesses lose an estimated £386 million a year to cyber crime, and the Scottish incident picture shows the pattern is automation finding exposed SMEs, not targeting. The costs below are what “found” means.

The invoice, line by line

Downtime: the line that dwarfs the others

The moment ransomware fires or a mailbox compromise is discovered, some portion of the business stops. Staff idle at full pay, orders untaken, jobs unbilled: a 20-person business carries payroll and overhead of thousands of pounds per working day whether or not anyone can work, and SME ransomware recoveries are measured in days to weeks, not hours. This is why the RTO conversation is secretly a financial one: every hour of recovery time you have not engineered away is inventory you are pre-committed to buying during an incident.

Recovery labour

Emergency IT response bills at emergency rates, and incidents burn a lot of hours: containment, forensic triage of what was reached, rebuilding machines, restoring from backup, credential resets across every system. Well-prepared businesses (tested backups, an incident response plan, EDR that caught it early) buy days of this; unprepared ones buy weeks, and the difference is usually four figures against five.

The ransom line, and why it is a trap either way

Paying is legal in most UK cases but discouraged, funds the next wave, offers no guarantee (decryption tools are often slow or partial, and stolen data stays stolen), and increasingly sits outside what insurers will simply cover. Not paying means recovery rests entirely on your backups, which is the correct plan and the reason backup separation is the single most cost-determining control on this page. Either way, the businesses that face the ransom decision calmly are the ones for whom it is moot.

Notification and regulatory exposure

If personal data was involved (customer records, staff files, client matters), UK GDPR duties activate: assessing the breach, notifying the ICO within 72 hours where required, and telling affected individuals where risk is high. The costs are legal advice, communication at scale, and management time; ICO penalties exist at the far end but the routine cost is the process itself, plus contractual notifications to any larger customers whose supply-chain terms you signed.

Reputation and the quiet churn

Some customers leave, quietly, and prospects mid-decision go elsewhere; for B2B firms the harder hit is procurement: “have you suffered a breach?” appears on questionnaires for years, and the honest yes costs bids. The mitigations are genuine: businesses that notify promptly, explain clearly and demonstrate fixes retain far more trust than those that go silent. The continuity plan’s communication templates earn their keep here.

The uninsured remainder

Cyber insurance done properly covers a real share: forensics, recovery labour, interruption, notification. What it does not cover: excesses, sub-limits, premium rises for years after, anything traceable to a questionnaire answered optimistically, and the management months the claim itself consumes. Insurance is the shock absorber, not the airbag.

The worked shape

Pulling the lines together for a 20-person professional-services firm hit by ransomware with decent-but-untested backups: a week of half-capacity operation (five figures of unproductive payroll), several days of emergency response and rebuild (mid four figures), legal and notification costs (low four figures), and a customer-facing apology exercise. Total: comfortably £25,000 to £60,000 before any ransom, any regulatory action, or any lost contracts, and that is a middle-of-the-road incident, not a horror story. UK survey data consistently puts *average* breach costs for smaller businesses in the low-to-mid four figures precisely because most detected incidents are small; the distribution’s tail, where ransomware lives, is what the figure above describes, and the tail is what planning is for.

What prevention buys, priced against that

The controls that most change the invoice are not exotic: MFA everywhere (removes the commonest entry), monitored EDR (turns incidents into interceptions), separated and tested backups (converts ransom leverage into an inconvenience), staff phishing training and an IR plan (compresses the expensive first hours). As a bundle inside managed support, this stack runs a few thousand pounds a year for a 20-person firm: against a single mid-range incident it returns multiples, and it also buys the lower insurance premium and the Cyber Essentials badge along the way. That is the whole argument, made with the only numbers that matter.

Frequently asked questions

What does the average cyber attack cost a UK small business?

Averages mislead here: most detected incidents cost little, while a serious one (ransomware, mailbox compromise with fraud) lands in the tens of thousands for a typical SME once downtime, recovery, notification and aftermath are counted. Plan against the serious case; the average handles itself.

What’s usually the biggest cost in an incident?

Downtime: payroll and lost work while systems are rebuilt. It is also the most controllable cost, because it is a direct function of backup quality and recovery planning done in advance.

Should a business ever pay a ransom?

The strong default is no: payment is unreliable, funds the ecosystem, and does not un-steal data. The practical goal is to make the question irrelevant, which is what separated, tested backups do; businesses that pay are mostly businesses that discovered their backups’ condition during the incident.

Do we have to report a cyber attack?

If personal data is involved and risk thresholds are met: to the ICO within 72 hours, and to affected individuals where the risk is high. Contracts may add customer notification duties. Building the assessment into your incident plan beats making the judgement at 2am.

Does cyber insurance cover all of this?

The insured lines, minus excess and sub-limits, provided your questionnaire answers were true and conditions were met. It does not restore reputation, management time or next year’s premium, and it increasingly requires the very controls that shrink the incident anyway.

What’s the single best-value prevention step?

If forced to one: MFA everywhere that matters, closing the commonest entry route for a near-zero cost. If allowed two: backups that ransomware cannot reach, tested with a restore. Those two alone reshape the entire invoice above.

Price your incident before it prices itself

The free IT health check includes exactly this arithmetic for your business: your realistic downtime day-rate, your backup posture tested against the ransom scenario, your insurance answers checked against reality, and the prevention stack priced beside the incident it prevents. Get in touch; the maths is much friendlier this side of the incident.