DLC Tech Solutions - IT Support for Small Business
    Back to Blog

    The Real Cost of a Data Breach for a 20-Person Business

    ICO fines get the headlines. They are rarely what damages a small business after a breach. Here is what actually drives the cost, and what changes the calculation.

    4 May 20268 min read

    When people talk about the cost of a data breach, they usually reach for a large number. The average cost per record. The billion pound settlements at the top end. The ICO fines.

    For a 20 person business, those numbers feel abstract. And in some ways they are, the ICO fine for an SME is unlikely to be the thing that breaks you. What breaks you is everything else.

    The Obvious Costs

    • Incident response and recovery. IT support to contain the breach, assess the damage, rebuild systems if needed. Depending on severity, this could be a few thousand pounds or significantly more. If ransomware is involved and backups are not viable, the number climbs fast.
    • Legal and compliance. Understanding your reporting obligations, communicating with the ICO if required, and potentially notifying affected individuals. If you do not have a lawyer who handles data protection, you are paying for specialist advice at an unhelpful moment.
    • Regulatory fines. The ICO does fine SMEs. The level depends on the severity of the breach and the organisation's conduct. Having good practices in place and responding appropriately tends to reduce this significantly.

    The Less Obvious Costs

    Lost staff time. In the weeks following a serious breach, key people stop doing their jobs and start managing the incident. The MD is on calls with lawyers and insurers. The IT contact is rebuilding systems. The ops manager is writing notifications to affected clients. This has a real value, it just does not appear on an invoice.

    Client notification and management. If you have had to notify clients that their data may have been compromised, some of them will leave. Not all of them, loyal clients who respect how you handled it may stay. But some will go. The revenue impact of that is hard to predict and impossible to insure against.

    Reputational damage. For a small business, reputation is everything. A breach that becomes known, particularly one that was handled poorly, can affect the ability to win new business for years. References become awkward. Tenders become harder. Word travels.

    The Mental Load

    This one does not appear in any official cost estimate. But the experience of running a business through a serious cyber incident is genuinely difficult. The uncertainty of not knowing exactly what was accessed. The conversations with clients you dread. The feeling that something you were responsible for went wrong.

    Business owners who have been through it describe it as one of the most stressful periods of running their company. That matters.

    What Changes the Calculation

    The businesses that come through incidents in the best shape are the ones that had:

    None of that is expensive. All of it is significantly cheaper than the alternative.

    The most useful question is not "what would a breach cost us?" It is "what would it cost us if it happened tomorrow, with our current setup?" The answer to that question should inform what you do next.

    Want a clearer picture of your current exposure? Take our free IT and cyber health check.

    Stay informed

    Get expert cyber security insights delivered to your inbox.

    Stay Updated

    Subscribe to receive the latest insights on cyber security, compliance, and data protection.