Est.

Data Breach Costs for Companies Under 500 Employees

Micro firms face $15,000 to $200,000 breach costs driven by fixed forensics and legal fees.

Staff Writer · · 8 min read
Cover illustration for “Data Breach Costs for Companies Under 500 Employees”
people who are worried about a data breach, ransomware, how SMBs can avoid being hacked, · September 26, 2026 · 8 min read · 1,744 words

IBM's 2026 Cost of a Data Breach Report put the global average breach cost in the millions, with one country's organizations averaging several times that. Articles aimed at small business owners quote this figure constantly. That's the problem: it doesn't describe small businesses.

The sample behind it skews heavily toward large enterprises, and IBM stopped breaking out results by organization size after its 2023 report. So when you see a multi-million dollar figure slapped onto a 40-person accounting firm or a 15-person medical practice, someone's stretching a statistic well past what it was ever built to measure. No fresh, first-party number for companies under 500 employees has been published since then, yet the figure keeps appearing in blog posts, vendor pitches, and webinars aimed at owners who have no reason to know the number was never about them.

Before trusting any breach-cost figure, check the employee bracket and the report edition. Two numbers that both claim to represent "the small business average" can come from different company sizes, different years, or different cost categories. If that check is skipped, the number is close to meaningless.

What the evidence shows for companies under 500 employees

IBM's 2023 report, the last one that broke costs out by headcount, put organizations under 500 employees at a multi-million dollar figure. Treat that as a ceiling reflecting companies sitting right up against the 500-employee line, not the ten-person shop down the street.

Verizon's 2026 Data Breach Investigations Report gives a more useful benchmark: a typical SMB incident runs between $120,000 and $1.24 million. That range tells a business owner something the enterprise-skewed average never could. TechAisle's 2025 SMB tracker is in between, putting average breach loss above a million dollars across small and mid-size firms, which lines up with the simple fact that breach cost scales with company size instead of hitting every business the same way.

The scaling is uneven, but it's predictable:

Micro businesses (1 to 9 employees) run $15,000 to $50,000, driven almost entirely by fixed costs: the forensics base fee, a legal retainer, notification expenses. None of that shrinks just because the company is small. Small businesses (10 to 49 employees) run $50,000 to $200,000, same fixed-cost structure, slightly larger footprint. Medium businesses (50 to 249 employees) run $200,000 into seven figures, where per-record costs and real business interruption join the fixed costs. Mid-market businesses (250 to 499 employees) run from seven figures up to the ceiling IBM cited for under-500-employee firms, where per-record costs and lost business start driving the total.

The floor matters as much as the ceiling here. Even a one-person shop can't get below roughly $15,000, because forensic investigation and legal notification carry a fixed cost no matter how small the breach actually was.

Diagram: Breach Cost Scales With Company Size — Not a Flat Number. Visualizes: Show four tiers of small business, each mapped to its estimated breach cost range, making the scaling pattern visible at a glance.

Where the money goes after a small business breach

Direct financial damages hit first: a ransom payment if it's ransomware, immediate recovery costs, and the forensics fee. That fee doesn't move with company size, so even a micro-business breach starts at roughly $15,000.

Employee hours cost more than most owners budget for going in. Executive time in incident meetings runs $500 to $1,000 an hour once everyone in the room is accounted for. IT and security staff time runs $75 to $150 an hour. None of that hour is spent generating revenue, and none of it comes back once the crisis passes.

Downtime is the cost that sneaks up on people. VikingCloud Research puts average downtime cost at $53,000, and a system outage lasting a few hours can end up costing more than the ransom itself. That flips the common assumption on its head. The ransom demand rarely sinks a small business. The hours it can't operate do.

Then come the outside firms: incident response, legal counsel, PR support to manage what customers and partners hear. Small businesses almost never have any of this on retainer, so all of it gets negotiated under pressure, in the worst week of the year.

How detection speed changes the total cost

Diagram: 247 Days: The Detection Gap That Doubles the Bill. Visualizes: Visualize the average breach lifecycle — 183 days to identify, plus 64 days to contain, totalling 247 days — as a single horizontal timeline bar split into two labeled phases…

IBM's 2026 report clocked the average breach at 247 days to identify and contain: 183 days to spot it, another 64 to shut it down. That's most of a year spent with an intruder already inside.

Speed moves the bill hard. Breaches with a lifecycle past 200 days averaged a noticeably higher multi-million dollar figure than breaches caught and contained under 200 days. Same category of incident, same reporting method, a sizable swing driven by one variable: how fast someone noticed.

For small businesses, slow detection is a structural problem. It's structural. Most SMBs run no dedicated security monitoring, so a breach sits undetected while an attacker moves through the network, pulls data out, and quietly plants a way back in for later. Layer on outdated tools: Many SMBs still lean on firewalls and traditional antivirus as their main defense, neither built to catch phishing or credential-based intrusions. Most SMBs have no formal incident response plan, so most businesses have no process that would even flag something as off.

Every day a breach goes unnoticed, forensics scope grows, the number of records needing notification climbs, and customer data exposure spreads further than it would have on day three instead of day thirty.

Why small businesses get attacked more often

There's a real gap between belief and reality here. 64% of small businesses don't think they're an attractive target, and 26% specifically agree with "we're too small to be targeted." The numbers say the opposite, and by a wide margin.

SMBs saw roughly four times more confirmed breaches than large organizations in 2024, with 2,842 confirmed breaches recorded, a figure that reflects how frequently small businesses are targeted. The frequency backs it up further: 80% of small businesses suffered at least one cyberattack in 2025, 59% of SMEs globally reported an attack in the past 12 months, and companies in one region. companies in that survey averaged 62 cyber incidents. Sixty-two, not once or twice.

Small businesses get targeted because they hold the same valuable data as big companies, customer records, payment details, sometimes healthcare information, without the defenses that make a large company slower and harder to hit. Ransomware-as-a-Service has industrialized the math: criminal groups rent out infrastructure, automation handles the scale, and small businesses pay more often because detection is slower and the chances of a successful attack are higher.

Budget explains why the odds stay in the attacker's favor. 47% of businesses with fewer than 50 employees spend zero dollars on cybersecurity. Employees at small businesses receive targeted malicious emails at a rate of 1 in every 323, the highest rate of any organization size, with businesses under 100 employees seeing 350% more social engineering attempts than employees at large enterprises. That's not a target that looks small to an attacker. It looks efficient.

The attack methods that account for most SMB breaches

Phishing sits at the top, and it isn't close. 92% of malware infections arrive through email. Business Email Compromise makes up 33% of attacks aimed specifically at small businesses and costs an average of $50,000 per incident, tailored well enough now to slip past consumer-grade filters that used to catch the obvious ones.

Ransomware comes second, and it hits small businesses disproportionately: 88% of SMB breaches in 2025 involved ransomware, against 39% for large organizations, while ransomware overall rose 20% in 2025 alone.

Double-extortion is the default now, not the exception. Attackers steal a copy of the data before encrypting the rest, so the victim faces two threats at once: pay to get systems back, or pay to keep stolen data from going public. One ransom note, two forms of leverage.

Vulnerability exploitation rounds out the list, and it's climbing fast. The 2025 Verizon DBIR found exploitation of known vulnerabilities as an entry point rose 34% year over year, and nearly half of known perimeter vulnerabilities sat unpatched at the time of breach. The door was left open long before anyone walked through it.

First steps for a business with no security team

Skip the idea of building a full security program overnight. Close the specific gaps that appear in the numbers above, in order.

Start with multi-factor authentication. A large share of SMBs still don't use it, despite MFA being widely recognized as one of the most effective defenses against automated account takeover attempts. It addresses the credential reuse behind a huge share of breaches, and it costs close to nothing to turn on. This is the highest-leverage move on the list, full stop.

Patching comes next, because vulnerability exploitation rose 34% as an entry point in 2025 and known perimeter vulnerabilities frequently go unresolved long enough for attackers to exploit them. Keeping operating systems, applications, and network hardware current closes the easy doors, and attackers look for the easy doors first.

Basic identity and access management finishes the list. Enforce role-based access so employees reach only the data their job requires, and cut off accounts the moment someone leaves. None of this stops an attacker from getting in the front door, but it limits what they reach once inside, often separating a contained incident from a company-wide one.

Security Platform Features for Businesses Without a Security Team

Firewalls and traditional antivirus remain the default at 91% of SMBs, and neither was built for the threat mix doing the damage today: phishing, credential attacks, automated intrusion tooling. Stacking more point tools on top of that outdated foundation just adds dashboards nobody has time to check.

Staffing reality should drive the buying decision, not feature lists. A business with no dedicated security person needs a platform that keeps enforcing its own rules day after day without an expert babysitting the configuration. Any setup that needs regular expert tuning to stay effective will drift out of date quietly, usually right when it matters most.

Running the cost and detection numbers back through that lens makes the requirements write themselves. Detection needs to happen in hours rather than the 247-day average IBM reported, since that gap is what turns the lower multi-million dollar breach figure into the higher one. MFA enforcement has to be built in and automatic, not dependent on each employee opting in. Patch and vulnerability visibility has to run constantly, given that known perimeter gaps frequently remain open long enough for attackers to exploit them. And the whole setup has to work without a dedicated analyst on staff, because most businesses under 500 employees don't have one and aren't hiring one this quarter.

Sources

  1. Do Hackers Attack Small Businesses? Statistics Say Yes
  2. Data Breach Cost Register, IBM 2026 Data
  3. Cost of a Data Breach: 2026 Statistics & SMB Impact
  4. The Real Cost of a Data Breach for Small Businesses
  5. cnicsolutions.com
  6. Cost of a Data Breach Report 2026 | IBM

More in people who are worried about a data breach, ransomware, how SMBs can avoid being hacked,