THE TAKEAWAY
A useful estimate starts with your systems, downtime exposure, and recovery needs. A headline average cannot tell you what your business would face.
There is no single price for a breach
A breach can affect far more than the IT budget. A business may need to investigate what happened, restore systems, work through legal and contractual questions, and communicate with customers while ordinary work continues.
Published averages can provide context, but they are not a quote for your business. An incident involving one account is different from a disruption across several locations. The information involved, available evidence, system dependencies, and recovery arrangements all shape the work.
A better planning question is: what would we need to keep operating, establish the facts, and recover responsibly?
The costs worth planning for
- Investigation and response: Technical help to establish the scope, coordinate actions, and document findings.
- Operational disruption: Delayed orders, unavailable systems, interrupted work, and temporary manual processes.
- Restoration: Rebuilding systems, checking dependencies, and validating that recovered services are usable.
- Professional advice and communications: Support to assess obligations and explain the situation accurately.
- Follow-up improvements: Changes to access, processes, and controls identified during recovery.
Keep cash expenses separate from estimates of lost productivity or revenue. Otherwise, the same interruption may be counted more than once. Document the assumptions so leadership understands what is known and what is still an estimate.
Build a planning estimate around your operations
Start with a business process rather than a generic industry number. Choose something important, such as scheduling appointments, processing orders, or running payroll. Identify the systems, people, and providers it relies on.
Work through three possible interruption lengths that make sense for that process. For each, discuss which work could continue, which costs would be additional, and which customer commitments might be affected. These are planning scenarios, not predictions.
Process → critical dependencies → interruption scenario → temporary workaround → additional costs → recovery owner.
Ask finance and operational owners to review the assumptions. Use the result to compare preparation options and decide which uncertainties need investigation.
Include the work of establishing the facts
The FTC’s Data Breach Response guide recommends bringing together the appropriate technical, legal, and business expertise, preserving evidence, and planning communications. Your response budget should account for this coordination.
Notification obligations depend on the circumstances and applicable requirements. Obtain appropriate advice instead of treating a generic online checklist as a decision about your incident. Clear ownership also helps prevent contradictory messages while the investigation is still developing.
Turn the estimate into a practical next step
Use the planning exercise to find actions with a clear purpose. You may discover that a recovery assumption needs testing, a critical process lacks an alternate owner, or leadership needs a better view of existing exposure.
A security risk assessment can organize risks and improvement priorities. A tabletop exercise can rehearse decisions. Virtual CISO support can help connect those priorities to ownership and investment.
Begin with the business outcome you want to protect. Then agree a scope and budget for the work needed to understand and improve it.
Free assessment