The costs you can see
There’s the immediate hit: paying for emergency IT help, recovering or rebuilding systems, and — if you’re unlucky and unprepared — a ransom. The UK Government’s annual Cyber Security Breaches Survey consistently shows these direct costs running well into the thousands for a serious incident, and far higher for larger or regulated organisations.
The costs you can’t see (but feel)
- Downtime: every hour your systems are down is work not done and customers not served — often the single biggest cost.
- Lost data: files, records and work that may never be fully recovered.
- Lost customers and trust: clients who leave because their data was exposed, or who simply lose confidence.
- Regulatory exposure: a data breach can bring reporting obligations and potential fines under UK GDPR.
- Your time: days of yours and your team’s time spent firefighting instead of running the business.
Why prevention is the bargain
Here’s the maths that matters: the basic protections that stop the majority of attacks — MFA, email security, patching, backups, a bit of staff training — cost a small fraction of a single serious incident. Cyber Essentials certification on top gives you a recognised baseline and reassures your customers. Spending a little to prevent is almost always cheaper than spending a lot to recover.
Protect your business for less than a breach
Frequently Asked Questions
It varies hugely, but the direct costs of a serious incident typically run into the thousands — and much more once downtime, lost data and lost customers are counted. The indirect costs usually dwarf any ransom.
Almost always. The basic protections that stop most attacks cost a small fraction of a single incident, so prevention is far cheaper than recovery. We build proportionate protection at competitive rates.

