ClearSecurity VISION
EN / RO
← All articles

Risk · 6 July 2026 · 6 min read

What a security incident really costs your business

No global-report averages: the real cost structure of a security incident for a 30-person company — and the 10-minute calculation you can do yourself.

ClearSecurity Vision

Ask “what does a security incident cost” and you usually get a number from a global report: an average across corporations with thousands of employees, banks, and hospitals in other countries. That number tells you nothing about your 30-person company. The uncomfortable truth is that nobody can tell you your cost — but the good news is that you can work it out yourself, in about 10 minutes, with numbers you already have in your accounting.

Let’s do the calculation together. Working scenario: a company of roughly 30 people. One Monday morning, something stops working — a laptop with its files encrypted, an email account taken over by someone else, a server that won’t start. What exactly happened matters less than you’d think; the cost structure is almost always the same.

1. The days you pay people to wait

The first cost, and usually the biggest, isn’t technical. It’s time.

Do the exercise now: take your monthly payroll — gross, taxes included, the figure you see every month anyway. Divide by 20 working days. That’s what one day costs you when the company exists but doesn’t produce. Now multiply by 2–3 days — a realistic window in which systems are shut down, checked, and brought back, while people sit, ask questions, and improvise.

That’s just the beginning. We haven’t counted anything technical yet — only salaries paid for work that isn’t happening. And downtime is rarely all-or-nothing: after the restart come the days when the team catches up on backlog instead of moving forward.

2. Rebuilding the systems

The second line in the calculation: who fixes things, and at what price.

If you work with an external IT provider, an emergency intervention is billed differently from the monthly retainer — crisis-rate hours, possibly over a weekend. Systems get reinstalled, every computer gets checked, passwords get changed everywhere, and the backup gets tested to see whether it can actually be restored (many companies find out only now). Sometimes you need new hardware, or an outside specialist to understand what really happened.

Don’t invent a figure: call your IT provider and ask them directly what a multi-day emergency intervention at your company would cost. It’s a five-minute question that gives you the second real number in your calculation — and, in passing, tells you something about how prepared your IT provider is for that day.

3. Customers: the notification, the questions, the contracts that slip

If customer data was touched in the incident, you have a legal obligation to inform them. But beyond the obligation lies the hard part: every customer notified means someone on your team on the phone, and a string of uncomfortable questions that deserve honest answers.

Then comes the quieter effect. The delivery that should have shipped Wednesday ships two weeks later. The proposal under negotiation gets a “we’ll think about it.” The big client who had just sent you their security questionnaire — filled in with optimism — now wants details. None of this shows up on an invoice, but put at least one delayed contract into your calculation and write next to it what it’s worth.

4. The costs that never make it into a spreadsheet

Three things have no line in your accounting, but you feel them for months:

  • Customer trust. Built over years, repaired slowly. It doesn’t vanish overnight — but at the next renewal decision, the incident is in the room.
  • Team fatigue. Two weeks of crisis — evening calls, lost weekends, tension — leave a mark. Good people remember how it felt.
  • Your own time. Possibly the most expensive of all: the weeks in which the manager isn’t selling, hiring, or running the company, but managing the crisis. Everything you postponed during that period is a cost too.

And one line that often gets forgotten: if you carry insurance that covers cyber risk, the premium gets recalculated at renewal with the incident on file.

5. If you fall under NIS2: the regulated layer

For most small companies, the calculation ends with the points above. But if your company falls under NIS2 — transposed in Romania through OUG 155/2024 — there’s an extra layer: significant incidents must be reported to DNSC on strict deadlines, starting with an early warning within the first 24 hours, and failing those obligations can bring fines calculated as a percentage of turnover. We’ve written separately about how the reporting cascade works — if you’re in that territory, it’s worth reading before the incident, not on the day of it.

The 10-minute calculation, in short

Take a sheet of paper or a fresh row in a spreadsheet and fill in:

  1. Payroll per day (monthly payroll ÷ 20) × 3 days of downtime
  2. The IT emergency intervention — the figure your IT provider gave you over the phone
  3. Your team’s time with customers — who calls, who answers, how many days
  4. One delayed or lost contract — the most plausible one, not the darkest one
  5. A line called “unknowns” — for everything you can’t know in advance

Add it up. The number you get is yours — nobody’s average — and it’s the most honest argument in any budget conversation.

The honest part: this is not the apocalypse

Let’s be clear: most companies that go through an incident recover. We’re not writing this to scare you, and anyone selling you security through fear is selling it badly. The point is the comparison. Put the figure you just calculated next to the cost of the basics — a regularly tested backup, two-factor authentication, people trained to recognize a phishing email. Prevention costs a fraction of the number on your sheet. Not because a report says so, but because you just did the math with your own numbers.


If you’ve done the exercise and want to turn the number into a plan — what to cover first, what can wait, what costs almost nothing — get in touch. The first step is a 30-minute briefing, free and with no sales pitch: we look at your calculation together and you leave with your next steps, whether or not we end up working together.

Or see where you stand against NIS2 directly: get started with CERTO.

newsletter

Get new articles by email.

NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.