The real cost of cybersecurity for businesses

Last update: April 2th 2026
  • Data breaches, ransomware, and human error generate losses in the millions that far exceed preventive investment in cybersecurity.
  • There is a growing gap between the cost of cybercrime and the budgets allocated to security, especially in SMEs and strategic sectors.
  • The new Cybersecurity Law requires thousands of companies to invest large sums in risk management, incident response, and training.
  • The cost of complying with these requirements is less than the financial, legal, and reputational impact of an unmanaged serious cyber incident.

The true cost of cybersecurity

Talking about the true cost of cybersecurity is no longer just about antivirus licenses or hiring an IT specialist to help out when something goes wrong. Today, the money a company risks in a serious security incident far exceeds any reasonable investment in protection , and data from insurers, consultancies, and public agencies makes this quite clear.

While the volume and sophistication of cyberattacks are skyrocketing, many companies remain underprotected , with tight budgets, piecemeal measures, and a "it won't happen to me" mentality that, when the first incident occurs, proves very costly. From large industrial and energy groups to local SMEs, the mismatch between the risk assumed and the money actually allocated to mitigating it is becoming increasingly evident.

The direct cost of cyber incidents: frightening figures

When analyzing cyber insurance claims on a large scale, it becomes clear that data breaches and information leaks are the most frequent type of incident and, moreover, the one that ultimately generates the greatest financial losses. We're talking about cases ranging from a handful of affected individuals to incidents impacting more than a million customers, with all that this entails in terms of notifications, crisis management, legal representation, penalties, and reputational damage.

A global study based on 4.650 insurance claims in nearly 90 countries over a decade puts the average cost of a cyberattack at around $2,4 million per incident. When the problem involves a massive data breach, the impact increases even further: the average cost of a data breach is around $3,9 million, including technical, legal, operational, and reputational costs.

Furthermore, the impact of "major incidents" is enormous: only 4% of incidents exceed the $10 million mark, yet this small group accounts for approximately 91% of total recorded losses. At the extreme, some claims have reached staggering figures as high as $331 million, illustrating the devastating potential of a well-targeted attack on a highly exposed organization.

One factor that appears repeatedly is the lack of adequate security measures . Around a quarter of the losses analyzed originate from poor protection: unpatched systems , weak access controls, lack of vendor oversight, or a lack of response and recovery plans that allow for a quick return to operations.

Main causes of losses: third parties, human error and ransomware

Looking at the origin of many of these incidents, it becomes clear that a significant portion of losses from data breaches are linked to suppliers and third parties . Approximately half of these incidents stem from failures or attacks affecting partners who store or process customer and employee data. This necessitates a thorough and regular cybersecurity review throughout the entire supply chain, not just within the organization itself.

Human error remains a classic culprit. Around 24% of losses associated with data breaches are related to carelessness or poor practices by employees or partners: clicking on links in phishing emails, responding to fraudulent messages, sending sensitive documents to the wrong recipient, or sharing credentials without sufficient precautions. A good onboarding and training program significantly reduces these risks.

Meanwhile, ransomware attacks continue their upward trend. This type of malware encrypts or locks systems and data, demanding a ransom in exchange for restoring access. In many cases, it's combined with data theft and publication to increase the pressure. The model has become so sophisticated that operators have emerged offering ransomware-as-a-service , providing kits, infrastructure, and support to other criminals in exchange for a percentage of the ransom.

This scenario makes it essential to have a well-designed, tested, and up-to-date business continuity and recovery plan : robust and isolated backups, clear procedures for isolating compromised systems, coordinated internal and external communication, and, above all, regular drills to avoid improvisation when the company is under attack.

The gap between risk and budget in cybersecurity

While attackers refine their tools and methods, spending on protection doesn't always keep pace. In markets like Spain, recent estimates suggest that the cost of cybercrime could skyrocket by up to 148% by 2028, reaching around €69.000 billion. However, the budget allocated to cybersecurity is growing at an annual rate of just under 6%, creating an increasingly worrying gap between the volume of risk assumed and the level of actual defense.

This situation is especially critical in strategic sectors , where a disruption of activity not only generates economic losses but also impacts on a country's security, supply, and essential services. In the last year, the manufacturing industry accounted for approximately a quarter of the recorded attacks, followed by the energy and supply sectors, and transportation, which also suffered a significant percentage of incidents.

  Smart Cameras vs. Conventional Video Surveillance: A Complete Guide

High-profile cases such as the cyberattack on a major British car company, considered one of the most costly in that country, make it clear that a single incident can paralyze production, disrupt supply chains, damage reputation, and lead to multimillion-dollar compensation claims.

Despite this outlook, many organizations still exhibit low levels of cybersecurity maturity. Recent reports indicate that only a small fraction of companies, around 2%, have deployed a comprehensive cyber resilience strategy—that is, a holistic approach that not only attempts to prevent attacks but also to withstand them and recover from them quickly and in a controlled manner.

The good news is that a large majority of executives now recognize the need to strengthen this area. More than three-quarters of companies expect to increase their cybersecurity budgets in the short term, and a significant number are planning double-digit increases, aware that continuing to postpone these investments only makes future costs higher.

Digitization, connectivity and a new attack surface

Digital transformation has revolutionized work practices in sectors as diverse as emergency services, logistics, infrastructure maintenance, and defense. Connected mobile and laptop devices allow access to real-time information, optimize routes, coordinate teams, and reduce downtime. However, this same connectivity also expands the playing field for attackers . Digital transformation requires specific measures to avoid multiplying the risk.

In remote or field environments, where direct IT team oversight is limited or nonexistent, risks multiply: unauthorized access to corporate systems, loss or theft of devices containing sensitive data, connections to unsecured wireless networks, and the use of uncontrolled applications. All of this creates a perfect scenario for a seemingly minor security breach to escalate into a serious problem.

Ruggedized devices (portable laptops and tablets) used in these sectors are designed to operate in extreme conditions and offer advanced connectivity, whether 4G LTE or 5G, even in isolated areas. However, increased connectivity without a proper security strategy is a recipe for disaster: more entry points, more devices to patch, and more identities to manage.

To mitigate these risks, a multi-layered, endpoint-centric protection approach makes sense: hardware with enhanced security features from the firmware level, operating systems configured with default security principles, robust identity controls (such as multi-factor authentication), full disk and communication encryption, and monitoring tools that allow for the detection of suspicious activity in real time.

On that basis, it is advisable to add additional layers such as the systematic use of secure VPNs for remote access, strict policies for managing software and firmware updates (avoiding leaving windows open to known vulnerabilities) and incident response plans that consider the specific context of field work.

Measure cyber risk and prioritize investment

One of the biggest challenges for many companies is moving from decisions based on intuition or general fears to a quantitative approach to cyber risk management . Most executives agree that measuring cyber risk will be key to deciding where to allocate funds, which projects to prioritize, and which controls are most cost-effective in terms of reducing exposure.

However, only a minority of organizations report allocating resources in a way that is truly aligned with the highest-risk areas. Among the most frequent obstacles are uncertainty about the true extent of threats , a lack of reliable data, difficulty in transforming that information into business-understandable metrics, and distrust of available quantification models.

Despite this, the use of financial impact assessments for different types of incidents is gaining ground. These solutions help estimate, for example, how much a prolonged outage of a critical system could cost, or what impact a massive customer data breach would have depending on the sector, applicable regulations, and the company's response capacity.

Beyond large corporations, even SMEs could benefit from simpler approaches to quantifying this, if only to compare an approximate figure for potential losses against current spending on protection. This comparison is often revealing and highlights how inexpensive investing in cybersecurity actually is compared to the cost of a serious incident.

In this context, close collaboration with insurers and specialized brokers can be very useful. Sharing information about providers, technology architecture, and business processes allows for better adjustment of policy limits, coverage, and exclusions, reducing the likelihood of unpleasant surprises in the event of a claim.

What is actually spent: the case of Spanish SMEs

If we look at the level of small and medium-sized enterprises (SMEs), the reality is that investment in cybersecurity is usually very low . A recent survey based on interviews with more than a thousand Spanish SMEs shows that nearly half of them spend less than 500 euros a year on digital security, a clearly insufficient amount considering the risks they face.

  How to safely erase all data from a PC before selling it

In the next segment, around 18% of SMEs report allocating between €500 and €2.000 annually, while only a small percentage exceed the €2.000 mark. Among the main obstacles to investment, the perception that implementation costs are too high stands out , something that often stems more from a lack of understanding than from actual figures.

Other barriers are more cultural or related to perception: a quarter of SMEs believe there's no need to go beyond what they already have (although that often amounts to little more than a basic antivirus). Added to this is the feeling that cybersecurity is too complex to manage or that qualified personnel are unavailable, leading many companies to avoid taking the plunge, despite the existence of managed solutions and services tailored to almost any budget.

Furthermore, approximately half of these companies perceive European regulations on digitalization as more of a hindrance than a help, forcing them to comply with requirements they consider difficult to meet with their current resources. Paradoxically, many of these same organizations acknowledge that investments in digitalization and cloud services are already generating economic benefits and operational efficiencies.

In fact, four out of ten SMEs report already seeing a positive return on digitalization, and a significant percentage view cybersecurity as a factor that can have a beneficial impact on their bottom line. The problem is usually not a lack of evidence of value, but rather the difficulty of translating that value into concrete and sustainable budgetary decisions.

AI, productivity, and new security challenges

Another relevant aspect of the true cost of cybersecurity is the adoption of artificial intelligence tools . In the SME sector, just over a third report already using AI-based solutions, with generative assistants playing a significant role in document management, text processing, data analysis, and support for marketing, sales, or customer service.

Among those who have begun using these technologies, the main motivation is to increase productivity and efficiency : reducing manual work, accelerating content generation, improving customer service with chatbots, or facilitating decision-making through automated analysis. A significant number of these companies plan to increase their investment in AI in the coming months.

However, among SMEs that haven't yet made the leap, the main obstacle is usually not the financial cost, which only a very small percentage cite as their primary problem. What weighs more heavily is the lack of a clear use case in their daily business or a lack of awareness of the available solutions. This means that many organizations are missing opportunities to improve their competitiveness and, at the same time, strengthen their security with AI-based tools.

It's important to remember that AI itself has also become a weapon in the hands of attackers. Automatically generated phishing , voice and video deepfakes, and more sophisticated social engineering attacks raise the bar for distinguishing a fraudulent attempt from legitimate communication. This puts even more pressure on companies to strengthen their AI security programs and technical controls.

In this context, the combination of AI to improve processes and threat detection, along with clear policies for the responsible use of these tools, can make the difference between gaining efficiency without losing security, or inadvertently opening new vulnerabilities in the organization.

The role of cyber risk policies and their limitations

Cyber ​​risk insurance policies have become an important element of the risk management ecosystem. Generally speaking, this type of insurance covers claims associated with incidents such as phishing with data breaches, business interruptions, ransomware attacks, and other events related to digital systems and assets.

Claims analysis shows that, in most data breaches, around 94% of losses are covered by these policies, provided the incident meets the contracted conditions. However, when the cause of the problem lies within the insured organization itself, that percentage of effective coverage drops to around 83%.

Among the reasons for coverage conflicts, three stand out in particular: the filing of claims outside the deadline , the failure to activate certain clauses that required specific actions by the insured, and decisions made by the company without obtaining the prior consent of the insurer, which in some cases may invalidate part of the guarantees.

To avoid these situations, it is crucial that organizations fully understand exactly what their policy covers, what its exclusions are, and what their obligations are in the event of an incident. Early and fluid communication with the broker and insurer, providing information about critical suppliers, sensitive assets, and known vulnerabilities, ensures that the insurance policy is truly tailored to the company's exposure.

Furthermore, integrating the policy within a broader cyber resilience strategy prevents the false impression that insurance will solve everything. Financial coverage helps absorb the impact, but it neither prevents attacks nor replaces the need for robust procedures, trained personnel, and appropriate technology.

  Complete Guide to Antivirus Protection for Mac

The new Cybersecurity Law and the cost of complying with it

In Europe, the transposition of the NIS2 directive through a new Cybersecurity Law is raising the bar for obligations for thousands of companies, especially those operating in sectors considered critical or essential to the economy and society. In Spain, it is estimated that nearly 6.000 organizations will have to adapt to this regulation and bear the associated implementation costs.

The law distinguishes between essential and important entities . Essential entities primarily correspond to companies in highly critical sectors (energy, transport, banking, healthcare, water management, digital infrastructure, ICT services for third parties, space, or the nuclear industry) that also exceed certain size and revenue thresholds, as well as providers of trusted services, domains, and public communications networks, among others. All other organizations that fall within the scope of the law but do not meet the essentiality requirements are considered important entities.

The cost of adaptation varies significantly depending on the starting point. For large organizations that practically have to build their cybersecurity infrastructure from scratch, the average estimated investment is around €180.000. Those that already have approximately 27% of the required measures implemented could see adaptation costs of around €131.000.

In the case of essential entities , the figures skyrocket: those starting from a very low level of implementation may require investments exceeding €2 million, while those that already meet about half of the requirements would need around €1,19 million. Companies already regulated under the previous framework (NIS1) have a much lower additional cost, in the region of €100.000, to adapt to the new requirements.

If all these efforts are combined, the Government estimates that the entire affected production sector could invest around €2.250 billion in adapting to the new law. This is a significant figure, but it must be interpreted in light of the cost, both in terms of money and social impact, of a series of serious incidents in strategic sectors without a common minimum level of protection.

Required measures: from risk management to sanctions

The Cybersecurity Law goes beyond generic recommendations: it obliges companies within its scope to adopt a comprehensive set of measures , ranging from risk management to staff training. Key requirements include the development of robust security policies, regular risk analyses, systematic vulnerability management , and the establishment of clear incident response procedures.

The need for frequent and reliable backups, disaster recovery mechanisms , and crisis management protocols to prevent security incidents from paralyzing operations for days or weeks is also emphasized. Supply chain security is once again at the forefront, forcing organizations to monitor the security of their suppliers and technology partners.

Another important area is incident resolution and reporting . Companies must have services capable of responding quickly when they detect a problem, mitigating its impact, and restoring normalcy as soon as possible, as well as notifying the relevant authorities and affected individuals within well-defined timeframes and with clearly defined information.

The regulation also requires the appointment of an information security officer to serve as an internal point of contact and liaison with the authorities. It reinforces the importance of ongoing cybersecurity training for managers and staff, recognizing that technology alone is insufficient if people cannot identify and manage risks.

To ensure compliance, certification mechanisms are planned for essential entities, guided self-assessments for important entities, and broad powers for supervisory authorities, who will be able to conduct audits, request information, and impose sanctions. In the most serious cases, fines could reach up to €10 million, and measures such as the suspension of certifications or the temporary restriction of duties for senior officials until the identified deficiencies are rectified are also being considered.

When you compare the investment figures needed to strengthen security with the potential economic, legal, and reputational impact of a serious incident, it becomes quite clear that turning a blind eye is far more expensive . Understanding the true cost of cybersecurity means recognizing that protecting systems, data, and processes is not an incidental expense, but a core component of the business model; the sooner companies internalize this, the less they will pay the price for inaction when the next attack occurs.

resilient template for CISO
Related articles:
Resilient template for CISO: a practical guide to leading cybersecurity