A cyberattack can interrupt revenue, consume staff time and create recovery and reporting obligations. Understanding those costs helps an SMB decide what to protect first and how to prepare for disruption.

Use evidence without turning averages into forecasts
Cyber incidents affect businesses of many sizes. In its release on 2023 cybercrime impacts, Statistics Canada estimated that Canadian businesses spent CAD $1.2 billion recovering from cybersecurity incidents, roughly twice the 2021 total.
The survey covered enterprises with at least 10 employees across most sectors, excluding public administration. It measured incidents businesses considered impactful. The total is not an average breach cost for an SMB and does not describe every attempted attack.
Your exposure depends on the systems affected, information involved, interruption length and ability to restore operations. A useful estimate starts with those details, not a dramatic industry number.
Ask what stops working. Identify the services your business cannot operate without, then estimate what disruption would mean for customers, staff and cash flow.
Map the costs that arrive first
The immediate bill can include technical investigation, containment, system restoration and specialist advice. An incident can also delay orders, appointments or invoices while employees work around unavailable systems.
Separate the different types of impact| Area | What to estimate |
|---|---|
| Response and recovery | External specialists, restoration work, necessary replacements and emergency support. |
| Business interruption | Lost contribution from cancelled work, delayed collections and the cost of temporary processes. |
| Staff effort | Overtime, backlog clearance and time diverted from planned work. |
| Customer support | Enquiry handling, communication and any appropriate remediation. |
| Legal and contractual work | Advice, required notices, claim handling and obligations that apply to the incident. |
Separate new cash expenses from lost revenue, lost margin and deferred work. If staff costs are already included in a downtime estimate, do not add them again as a separate loss.

Plan for the consequences that last longer
Restoring access is not always the end of recovery. Teams may still need to reconcile records, reschedule work, investigate account changes and answer customer questions. Managers can spend time on the incident that would otherwise go toward operations or growth.
Customer confidence can also be affected. Avoid assigning an invented percentage to reputational damage. Instead, track observable indicators such as complaints, cancelled renewals and additional support demand, while acknowledging that other factors may contribute.
For planning, consider a short disruption and a longer recovery scenario. Identify which work can be postponed, which can continue manually and which would be lost entirely. The difference matters when estimating financial impact.
Treat ransom demands as a crisis, not a recovery plan
Ransomware can create pressure to make a rapid payment. That does not mean payment is inevitable or reliable. A statement published by Public Safety Canada and Counter Ransomware Initiative partners strongly discourages paying and warns that it does not guarantee data recovery, malware removal or the end of an incident.
Prepare a response route before a demand arrives. Identify the incident lead, technical responders, legal adviser, insurer contact and law-enforcement reporting route. Preserve evidence and obtain qualified advice on the specific situation.
Protect recovery options by testing restoration and restricting access to backups. The ability to restore a file is different from the ability to bring an entire business service back safely. See our backup and disaster recovery guide.
Know your reporting and coverage obligations
For organizations subject to PIPEDA, the Privacy Commissioner’s breach guidance requires reporting and notification when a breach involving personal information poses a real risk of significant harm. Records must be kept for all breaches of security safeguards. The applicable assessment and other provincial, sector or contractual obligations should be reviewed with an appropriate adviser.
A cyberattack does not automatically result in a regulatory fine. Avoid assuming that every incident has identical legal consequences. Document the facts, decisions and advice that support your response.
Insurance is another part of planning. Insurance Bureau of Canada’s Cyber Savvy resources explain that coverage can help with specified response and restoration costs, but varies by policy. Ask about limits, deductibles, waiting periods, exclusions, approved providers and notification requirements.
Do not assume a general business policy covers every cyber loss. Review the actual wording and endorsements with your broker, including scenarios involving fraudulent payments or a critical supplier.
Build a simple exposure estimate
Choose one essential service, such as order processing, case management or payroll. Work with the business owner and IT lead to describe a plausible interruption and recovery sequence.
- Define the disruption. State which systems and people are affected and what still works.
- Estimate operating impact. Separate cancelled work from work that can be completed later.
- Price the response. Use supplier estimates where possible and identify uncertain items.
- Add recovery work. Include restoration, validation, backlog clearance and communication.
- Review funding. Identify immediate cash needs and possible insurance recovery separately.
Use ranges where information is uncertain and record the assumptions. Do not subtract an assumed insurance payment as though approval and timing were guaranteed.
Revisit the estimate when applications, staffing or suppliers change. It should help prioritize improvements, not present a false prediction of the next attack.
Turn preparation into assigned work
The Canadian Centre for Cyber Security’s baseline guidance provides a starting point for controls such as strong authentication, updates, backups, security software, training and incident planning.
- Identify critical systems and the person responsible for each.
- Review account access and MFA coverage, especially for administration and remote access.
- Confirm that supported devices receive updates and security monitoring.
- Test restoration and record whether recovery targets were met.
- Practise reporting suspicious activity and running an incident exercise.
- Keep response contacts and necessary instructions accessible during an outage.
Monitoring needs a response owner. A tool generating an alert is only useful if someone can investigate and act. Review service hours, escalation and exclusions in your support agreement.
Talk to us about your security and recovery priorities. Confirm which Cyber360 services and any insurance arrangements apply to your business. Avoid treating a headline coverage amount as a guarantee of recovery or complete protection.
Frequently asked questions
01What does a cyberattack cost a small business?
There is no reliable single figure for every business. Estimate the affected operations, response work, recovery time and applicable obligations using your own systems and financial information.
02Does restoring a backup end the incident?
Not necessarily. Responders still need to address the cause, validate restored systems and investigate possible account or data exposure. Operational backlogs may remain.
03Should we include a ransom payment in our recovery plan?
Do not make payment your recovery strategy. Paying does not guarantee recovery. Establish specialist contacts and tested restoration options before an incident.
04Does every cyber incident require a privacy report?
The answer depends on the information involved, applicable law and risk assessment. Under PIPEDA, reporting and notification apply to qualifying breaches posing a real risk of significant harm; record-keeping obligations are broader.
05Where should we start with a limited budget?
Identify the services whose loss would hurt most, then address verified control and recovery gaps. Assign owners and test the improvements rather than buying tools without an operating plan.
Prepare around what your business depends on.
Talk to us about identifying critical systems, reviewing recovery gaps and building a practical security plan.
Talk it through