
Someone clicks the wrong link, or a laptop shows a message it shouldn’t, and every business owner braces for the same thing: a number. Something enormous, something that sounds like the end of the business as you know it.
Most cyber security content is happy to hand you that number, usually an eye-watering average, quoted with total confidence and little explanation of where it came from. Here’s what UK data actually shows about the cost of a cyber incident, and it’s a different, more useful story.
What the data says about the cost of a cyber incident
The UK government’s own Cyber Security Breaches Survey asks businesses directly what their most disruptive breach cost them. For most, the answer is close to nothing, the median reported cost was £0 (DSIT, Cyber Security Breaches Survey 2025/2026). Most incidents turn out to be a manageable nuisance: a password reset, an awkward hour, then everyone moves on. That’s genuinely good news, and it doesn’t match the fear most business owners carry.
The part that still matters
The honest caveat: among the worst outcomes, the top 5% of cases, costs climbed to £4,000 for micro and small businesses, and £10,000 for medium and large ones. A small proportion of businesses get a genuinely serious hit, often at the worst possible moment for cash flow, and there’s no way to know in advance who that’ll be. That’s really what protection buys you: not immunity from the average outcome, but a buffer against the one you can’t predict.
The two costs the survey doesn’t ask about
The financial figure is only part of the picture, and often not the part that hurts most.
The first is reputational. Very few unhappy customers complain formally. Far more common is quiet erosion, a client who doesn’t renew, a contact who stops sending referrals, a supplier who asks a sharper question at the next review. None of it shows up in a survey or comes with an invoice, but for a business built on relationships, it can matter more than the technical clean-up.
The second is human. Somebody usually carries an incident personally, the employee who clicked the link and spends the week feeling responsible, or the office manager who’s quietly held “cyber security” as an unofficial part of their job for years, and now feels it’s landed on them by name. That stress is real, rarely talked about, and tends to outlast the technical fix.
Neither shows up as a number. Both are usually more disruptive, day to day, than the bill.
What this means practically
This isn’t an argument for doing nothing because most incidents are minor. It’s an argument for being clear-eyed about what you’re actually protecting, which is broader than a bank balance. A modest, predictable spend on proper protection is easier to justify once you frame it as protecting relationships and people, not just accounts.
A more useful question than “how much would this cost us” is: if something happened tomorrow, would our customers still trust us, and would whoever was involved feel supported rather than blamed?
If you’d like to talk through where your business actually stands, on the technical side or the human side, get in touch. We’re happy to just listen first and see where the conversation goes.
Source: Department for Science, Innovation and Technology (DSIT), Cyber Security Breaches Survey 2025/2026, GOV.UK.





