Why Phishing Still Works Even When Employees Know About It
Aug 07, 2026 / 41 min read
August 7, 2026 / 27 min read / by Team VE
The real cost is the pile-up of response work, downtime, legal exposure, lost trust, delayed sales, executive distraction, and security debt that gets called due all at once.
A cybersecurity breach can cost a growing company anything from a manageable emergency expense to a company-changing financial event. The final cost depends on what was exposed, how long attackers remained inside, how quickly the breach was contained, and whether critical operations were interrupted. The bill rarely comes from one place.
It builds across forensic investigation, incident response, downtime, legal support, customer notification, lost productivity, delayed deals, customer credits, regulatory work, and the security improvements required afterwards.
The better question is not, “What does the average breach cost?” It is, “What stops working, what obligations get triggered, which customers are affected, and how long does recovery take?”
A compromised finance mailbox, CRM, customer database, or cloud environment can each create a very different financial outcome. What they have in common is that a breach turns previously invisible security weaknesses into immediate costs in cash, operations, time, and customer trust.
A cybersecurity breach is an incident where an unauthorized party gains access to systems, accounts, data, infrastructure, or business processes in a way that compromises confidentiality, integrity, or availability.
In business terms, that means the company has lost control over something it is supposed to protect, whether that is customer data, employee records, intellectual property, financial systems, email accounts, production systems, cloud workloads, or operational continuity.
In September 2023, MGM Resorts discovered that attackers had gained access to parts of its network. The company did what incident-response teams are often forced to do in that situation: it shut systems down to contain the damage. The consequences were immediately visible.
Digital hotel keys stopped working, some slot machines went offline, online bookings were disrupted and hotel operations were affected. MGM later estimated that the incident reduced Adjusted Property EBITDAR by roughly $100 million, with additional spending on technology consultants, lawyers and other advisers.
This is the part of cybersecurity economics that gets lost when breach costs are reduced to a single industry average. MGM did not suddenly receive a “$100 million cyber bill.” The money disappeared through the business. Reservations were harder to make and systems had to be taken offline while employees had to work around technology they could no longer trust.
External specialists were brought in as customer information had been accessed, which created notification obligations. Lawsuits and regulatory inquiries followed. By the time the incident was contained, cybersecurity was no longer an IT problem. It had become an operations problem, a legal problem, a customer problem and a financial problem.
For a growing company, the same mechanics apply, often with less room for error. A 200-person business may not run casinos and hotels, but it can still depend on a surprisingly small number of systems to keep revenue moving: Microsoft 365, a CRM, an ERP, cloud infrastructure, customer databases, payment systems and a handful of SaaS platforms.
Growth tends to make that environment more complicated before it makes it more secure. New applications are added quickly. Vendors receive access. Employees accumulate permissions. Teams create workarounds because getting something shipped matters more in the moment than redesigning an access policy. None of this means the company is badly run. It is simply what happens when operational complexity grows faster than security governance.
This is why asking, “What does a data breach cost?” is usually the wrong starting point. The better questions are more uncomfortable: What happens if our CRM disappears tomorrow? How long could finance operate without access to its systems? What if customer records are copied rather than encrypted? Which major client could walk away? How quickly could we prove that an attacker was actually gone?
Two businesses with the same revenue and headcount can experience completely different losses from an apparently similar attack. One restores from clean backups before lunch. Another spends a week determining whether its backups can even be trusted.
The real cost of a breach is therefore determined less by the size of the company than by the business dependency behind the system that was compromised. What did the attacker reach? How sensitive was the data? How long were they inside? What had to be shut down?
How quickly could the company recover? And perhaps most importantly, how much of the business continued to function while the security team was figuring all of that out? This is when cybersecurity risk becomes financial risk.
When a breach is discovered, the first bill is rarely for new software. It is for urgent decision-making. Someone has to confirm whether the incident is real, isolate affected systems, preserve evidence, revoke compromised access, bring in forensic help, notify legal, brief leadership, and stop the attack from spreading. This happens while normal work is still expected to continue.
Many growing companies underestimate this stage because they think of cybersecurity as a tool problem. In reality, early breach response is coordination under pressure. If there is no incident response plan, every decision becomes slower and more expensive. Who can approve shutting down systems? Who talks to customers?
Who contacts cyber insurance? Who preserves logs? Who decides whether to involve law enforcement? Who can confirm whether backups are clean? If these questions are answered during the incident, cost rises because the company pays in hours, confusion, duplicate work, and missed containment windows.
This is why the NIST Cybersecurity Framework 2.0 is helpful for business leaders, not just security teams. Its Govern, Identify, Protect, Detect, Respond, and Recover functions make clear that breach cost is influenced by preparation long before an incident is detected. A company that knows its critical assets, logs important activity, manages access, practices response, and has recovery roles defined usually spends less time guessing when something goes wrong.
| Immediate response area | What it usually includes | Why it adds cost |
| Incident validation | Checking alerts, logs, systems, endpoint activity, cloud access, and reported anomalies. | False starts waste time, but delayed validation can let attackers remain inside longer. |
| Containment | Disabling accounts, isolating machines, blocking indicators, revoking tokens, and shutting down affected services. | Poor segmentation forces broad shutdowns, which increases downtime. |
| Forensics | External incident response, log review, malware analysis, timeline reconstruction, and evidence preservation. | Specialist work is urgent, scarce, and often billed at emergency rates. |
| Legal and compliance | Privilege management, breach notification analysis, regulator timelines, contract review, and external counsel. | Wrong communication or delayed notification can create secondary exposure. |
| Business continuity | Manual workarounds, customer messaging, finance controls, vendor coordination, and service restoration. | The longer operations run in emergency mode, the more expensive the breach becomes. |
A breach cost model should not begin with one headline number because the financial impact rarely arrives as one clean, isolated expense. For a growing company, the exposure is usually spread across several parts of the business at the same time.
One company may avoid a regulatory fine but lose a major customer, while another may pay no ransom yet spend heavily on forensic investigation, recovery, legal advice and additional security controls. A third may restore its systems relatively quickly but still face a longer commercial penalty because prospects begin asking tougher security questions, procurement slows down and existing customers want reassurance before renewing.
That is why the categories matter more than the average. They show where the financial pressure actually appears and, more importantly, how one cost can trigger another.
A technical response may lead to downtime, downtime may affect customers, customer disruption may create credits or lost revenue, and the incident itself may force legal, regulatory and insurance work that continues long after systems are back online. In practice, the cost of a serious breach is cumulative, with several categories often building on each other rather than occurring separately.
| Cost category | Examples | Typical business impact |
| Direct technical response | Forensics, incident response retainers, endpoint cleanup, cloud review, identity reset, backup validation, new monitoring. | Cash outflow starts immediately and often before root cause is fully known. |
| Operational downtime | Unavailable systems, paused production, delayed orders, interrupted customer support, manual finance workflows. | Revenue is delayed or lost while employees spend paid time on recovery. |
| Legal, compliance, and notification | Outside counsel, breach notification, regulator communication, privacy review, contract obligations, credit monitoring. | Costs depend heavily on what data was exposed and which jurisdictions apply. |
| Customer and revenue impact | Lost renewals, delayed deals, churn, credits, contract renegotiation, reduced buyer confidence. | Often appears weeks or months after the incident, which makes it harder to attribute. |
| Internal productivity loss | Executive meetings, employee password resets, IT overtime, rework, audit preparation, process reconstruction. | Teams stop doing normal growth work and shift into cleanup mode. |
| Insurance and financing impact | Deductibles, premium increases, coverage disputes, underwriting scrutiny, investor questions. | The breach can increase future cost of risk, not just current cost. |
| Security debt repayment | Emergency upgrades, access redesign, segmentation, backup rebuild, SIEM/MDR setup, policy enforcement. | Work that should have been phased becomes urgent and more expensive. |
The first serious cost is proving what happened. A growing company cannot responsibly say, “We think it was only one account,” unless someone has checked the evidence. That means logs, identity activity, endpoint behavior, cloud storage access, privileged account use, email forwarding rules, suspicious API calls, data transfers, and any system changes made around the time of compromise.
Forensics becomes expensive because the company is buying certainty under time pressure. If logs are missing, the work becomes slower. If systems are poorly documented, investigators must spend time mapping the environment before they can judge impact. If SaaS tools are used across departments without central visibility, the company may not even know where sensitive data lives. This is where weak governance becomes a forensic tax.
Downtime is where the breach stops being a security event and becomes an operating event. A ransomware attack that freezes file servers, an email compromise that shuts down finance approvals, or a cloud account compromise that pauses production workloads can hit revenue faster than the company expects.
The direct loss is not only lost sales. It is also delayed invoicing, delayed collections, support backlog, refund pressure, service credits, lost shipping windows, and expensive manual workarounds.
The cost of downtime depends on business model. A SaaS company may lose trust with customers if service availability is hit. A manufacturer may lose production output. A healthcare support company may face severe workflow disruption because patient or insurance processes are time-sensitive.
A professional services firm may lose billable hours and client confidence. For a growing company, downtime is rarely clean. Systems are interconnected, and one broken workflow often pulls three more into the incident.
Ransomware data also shows why downtime matters even when companies do not pay attackers. Sophos’ 2025 ransomware research reports exploited vulnerabilities as the leading root cause and lists a USD 1.0 million average ransom payment, but ransom is only one part of the cost. Recovery time, rebuild work, operational delays, and staff exhaustion can stay with the company long after payment decisions are made.
A breach involving personal data is not just an IT issue. It can trigger privacy review, contractual notification duties, regulator reporting, customer notices, and sometimes credit monitoring or identity protection services. The company must determine what data was accessed, whether it was exfiltrated, who was affected, which jurisdictions apply, and whether notification thresholds have been met.
This is why even smaller companies need to understand their data map. The UK Information Commissioner’s Office security guidance frames security around appropriate technical and organisational measures, and similar logic appears in many privacy regimes. A company cannot assess breach obligations properly if it does not know what personal data it stores, where it sits, who can access it, and which vendors process it.
Legal costs also rise when communication is messy. If a company says too much too early, it may create avoidable liability. If it says too little or waits too long, it may damage trust or breach notification duties. Growing companies often feel this pressure acutely because they have enough customers to create communication scale, but not always enough crisis-communication infrastructure to handle it smoothly.
The least visible breach cost is often the most damaging: the loss of commercial confidence. Customers may not leave immediately. Prospects may not say the breach killed the deal. But the sales process changes. Security questionnaires get longer.
Procurement asks for new evidence. Customers ask whether their data was affected. Legal teams demand stronger clauses. Existing clients ask for credits, audits, or executive calls. Renewal conversations become less about value and more about reassurance.
This is why breach cost should include delayed revenue, not just lost revenue. If a company has a pipeline worth USD 2 million and three large deals slow down by a quarter because the breach raises buyer concern, the company may not record that as a breach cost.
But the cash-flow impact is real. In a growing company, timing matters. Delayed revenue can affect hiring plans, investor updates, vendor payments, expansion plans, and confidence inside the leadership team.
Cyber insurance can reduce financial shock, but it does not erase breach cost. The company may still face deductibles, waiting periods, sublimits, exclusions, forensic-panel requirements, and coverage questions around control failures.
After an incident, renewal can become harder. Insurers may ask for stronger MFA, endpoint detection, patch evidence, backup testing, security awareness, privileged access controls, and incident response documentation before offering acceptable terms.
This creates a second-order cost. The breach does not only cost money during the incident. It can raise the company’s future cost of risk. A company that previously treated security controls as optional may find that customers, insurers, investors, and auditors all start asking for the same missing evidence at once.
During a serious breach, leadership time becomes part of the cost model. The CEO is pulled into customer calls. The CFO is pulled into exposure estimates and insurance. The COO is pulled into business continuity. The CTO or IT head is pulled into containment and restoration.
HR may need to support employee communications. Sales needs talking points. Customer success needs escalation rules. Every one of those hours is an hour not spent on growth, delivery, hiring, product, collections, or strategy.
This is especially costly in founder-led or lean management companies, where a small number of leaders hold too much operational context. A breach exposes that dependency. If only two people understand the infrastructure, only one person can authorize vendor actions, or only one finance manager understands payment controls, recovery becomes slower and more fragile. The company pays for the breach through concentrated human bottlenecks.
A CFO or founder does not need perfect precision to understand breach exposure. They need a working model that separates immediate cash outflow, operational loss, delayed commercial impact, and future security investment. The goal is not to predict the breach perfectly. The goal is to stop pretending the cost is only a ransom, a forensic invoice, or a regulatory fine.
| Cost bucket | How to estimate it internally | Questions leadership should ask |
| Response and investigation | External IR hours + legal hours + internal IT overtime + emergency tool spend. | Do we have an incident response retainer? Do we have logs good enough to investigate quickly? |
| Downtime | Hours of disruption x revenue per operating hour, plus labor cost of idle or manual work. | Which systems would stop revenue, invoicing, delivery, or customer support if unavailable? |
| Data exposure response | Affected records x notification, support, legal, and identity protection costs. | Do we know what personal, financial, client, or regulated data we store and where it lives? |
| Customer impact | At-risk renewals + delayed pipeline + credits + churn + extra account management hours. | Which customers would require immediate notification or security review? |
| Security remediation | MFA hardening, endpoint protection, backup rebuild, MDR/SOC, patching, segmentation, policy enforcement. | Which improvements will be mandatory after the breach anyway, but more expensive under pressure? |
| Future cost of risk | Insurance premium changes + customer audit costs + compliance work + vendor security reviews. | Will this incident affect our cyber insurance, enterprise sales, or investor diligence? |
Growing companies do not usually underestimate breach cost because they are careless. They underestimate it because growth creates complexity faster than governance catches up.
A company adds new people, new tools, new departments, new vendors, new cloud environments, new geographies, new data types, and new customer obligations. Security work then competes with product deadlines, sales targets, hiring, customer delivery, and finance pressure.
The FTC’s small business cybersecurity guidance puts the business reality plainly: companies cannot afford to lose time, information, or money to cyberattacks. That line matters because breach cost is not abstract. It lands in the ordinary places where a growing company is already stretched: cash flow, customer support, staff capacity, compliance, and leadership attention.
Ransomware is expensive because it compresses three problems into one event: operational shutdown, data exposure, and extortion pressure. Older ransomware narratives focused mainly on encryption.
Newer incidents often include data theft, threats to publish information, pressure on customers or partners, and attempts to exploit weak identity controls. The business is not only trying to restore systems. It is trying to make decisions under public, legal, operational, and emotional pressure.
Microsoft’s 2025 Digital Defense Report describes financially motivated attacks, including extortion, ransomware, and data theft, as primary motivations in observed cyberattacks. That matters for growing companies because attackers are not always trying to break complex defenses.
Often, they are trying to monetize the weakest route into a valuable business process: a stolen login, an unpatched internet-facing system, a vulnerable vendor, or a finance workflow that can be manipulated.
| Ransomware cost layer | What leadership sees | What is often missed |
| Encryption | Systems and files become unavailable. | The cost depends on restoration speed, backup quality, and how much work must be rebuilt manually. |
| Data theft | Attackers claim they copied data. | Legal and customer notification may be required even if systems are restored. |
| Extortion pressure | Attackers demand payment and set deadlines. | Payment does not guarantee full recovery, silence, or safety from future targeting. |
| Recovery rebuild | IT restores systems and accounts. | Clean rebuilds take longer when documentation, asset inventory, and identity hygiene are weak. |
| Commercial fallout | Customers ask what happened. | Trust damage can outlast technical recovery by months. |
There is no serious way to make breach cost zero. The better goal is to make the blast radius smaller, the detection faster, the response cleaner, and the recovery less chaotic. The controls that reduce cost are often boring: asset inventory, least privilege, MFA with strong conditional access, endpoint visibility, patch management, tested backups, centralized logging, security monitoring, vendor access review, incident response playbooks, and tabletop exercises.
These controls reduce cost because they reduce uncertainty. If the company knows which assets are critical, it investigates faster. If access is segmented, the attacker moves less easily. If backups are tested, recovery decisions are clearer.
If logs are retained, forensics is cheaper. If legal, IT, finance, and leadership have a response plan, communication is less chaotic. If customers have already seen serious security practices during sales or onboarding, post-incident trust is easier to defend.
That is also why security should be discussed as operating discipline, not just IT spend. The FCC’s small business cyber planner resources and similar public-sector guidance exist because smaller and growing businesses need practical structure before they have enterprise-grade teams.
The companies that control breach cost are not always the companies with the biggest security budget. They are often the companies that know what matters most, monitor it consistently, and rehearse what happens when something breaks.
The following checklist is not a full security program. It is a practical way for leadership to reduce breach cost before a breach happens. Each item either lowers the chance of compromise, reduces attacker movement, shortens investigation time, or improves recovery.
| Control | Why it reduces cost | Minimum practical standard |
| Asset inventory | You cannot protect, investigate, or restore systems you do not know exist. | Maintain current records of critical systems, SaaS tools, cloud assets, data stores, vendors, and owners. |
| Strong identity controls | Many breaches begin with compromised accounts. | Use MFA, conditional access, privileged access review, secure recovery processes, and fast offboarding. |
| Patch discipline | Unpatched vulnerabilities can turn one neglected system into a breach entry point. | Prioritize internet-facing systems, critical vulnerabilities, and vendor appliances with clear ownership. |
| Endpoint and cloud monitoring | Faster detection reduces dwell time and investigation cost. | Monitor endpoints, identity logs, cloud admin activity, data exports, and suspicious access patterns. |
| Tested backups | Recovery depends on backups that actually restore. | Keep offline or immutable backups, test restore procedures, and define recovery time expectations. |
| Incident response playbook | Pre-made decisions reduce panic and delay. | Define who leads, who approves shutdowns, who contacts counsel, who calls insurance, and who communicates externally. |
| Vendor access review | Third-party compromise can become your breach. | Review vendor accounts, integrations, API tokens, shared credentials, and contract notification duties. |
| Security awareness tied to workflows | Generic training misses finance, HR, procurement, and executive attack paths. | Train people around real tasks: payments, invoices, vendor changes, customer data, shared files, and credential prompts. |
When the Breach Is Already Happening, Cost Control Means Discipline
If a breach is suspected, the cheapest response is not the fastest visible action. It is the most disciplined sequence of actions. Pulling plugs without preserving evidence can destroy forensic trails. Sending premature customer emails can create confusion. Paying a ransom without understanding legal, insurance, and recovery implications can create more problems. Waiting too long because no one wants to escalate can make everything worse.
A cybersecurity breach costs whatever the company failed to prepare for. That sounds harsh, but it is usually how economics work. If access ownership is weak, the cost appears in account cleanup. If logs are weak, the cost appears in forensics.
If backups are weak, the cost appears in downtime. If customer communication is weak, the cost appears in trust. If vendor controls are weak, the cost appears in scope uncertainty. If leadership has never rehearsed a response, the cost appears in delay.
For a growing company, the goal is not to copy a Fortune 500 security program. The goal is to remove the expensive unknowns. Know your critical systems. Know where sensitive data sits. Know who owns access. Know which vendors matter. Know how backups restore. Know who makes breach decisions. Know what you would tell customers. Know how to monitor the systems that would hurt most if compromised.
The companies that recover best are not the ones that never believed a breach could happen. They are the ones that treated breach cost as a business risk before attackers forced the conversation.
Yes, but only as a warning signal, not as a budgeting shortcut. A global average like IBM’s USD 4.4 million figure tells leaders that breaches are financially serious, but it does not tell you what your breach would cost. Your actual exposure depends on your business model, type of data, downtime tolerance, customer contracts, regulatory footprint, cyber insurance terms, and response maturity.
A growing company should use averages to start the conversation, then build its own scenario model. What if email is compromised? What if CRM data is exposed? What if ransomware takes down operations for three days? What if finance is tricked into a vendor-payment fraud? These scenarios produce much better planning than asking whether your company is above or below an industry average.
It depends on the incident, but downtime and recovery often become larger than the ransom or initial technical bill. Ransomware gets attention because the demand is visible and dramatic. But the company may spend more on restoration, customer support, legal advice, forensic investigation, delayed projects, manual operations, and lost commercial trust.
Legal cost becomes bigger when sensitive personal data, regulated information, or contractual notification duties are involved. Downtime becomes bigger when systems directly support revenue, production, billing, delivery, or customer support. The safest assumption is that the largest cost will come from the function that the business cannot operate without.
Cyber insurance can help, but it is not a magic reset button. Policies usually have deductibles, sublimits, exclusions, approved vendor requirements, notification duties, and conditions around controls such as MFA, backups, or endpoint protection. If the company misrepresented its controls during underwriting, coverage can become complicated.
Insurance also does not fully cover reputational damage, leadership distraction, lost pipeline momentum, customer anxiety, internal morale, or the operational pain of rebuilding systems. It is useful financial protection, but it works best when paired with real security controls and a practiced incident response plan.
Start with the workflows that stop or slow down when systems are unavailable. Even if revenue is not earned hourly, downtime can delay invoicing, collections, customer support, order processing, production, sales follow-ups, payroll, compliance reporting, or service delivery. Estimate the labor cost of idle or manual work, then add revenue delay and customer-impact costs.
For subscription or service businesses, downtime cost often appears as credits, churn risk, SLA penalties, extra support volume, and delayed renewals. For manufacturing or logistics, it may show up as missed production, shipping delays, overtime, and customer penalties. The point is not perfect math. The point is making business interruption visible before a breach forces the calculation.
There is no universal answer, and no company should make that decision casually. Paying may be illegal in certain sanctions-related situations, may not guarantee recovery, may not prevent data publication, and may encourage further targeting. The decision should involve legal counsel, insurance, incident response specialists, leadership, and, where appropriate, law enforcement.
The better business question is how to avoid making ransom payment feel like the only option. Tested backups, segmented systems, offline recovery, strong identity controls, and clear response playbooks give the company more choices. A company without those options is negotiating from a weaker position.
Technical containment closes one chapter, not the whole incident. After containment, the company still has to complete forensics, restore systems, notify affected parties if required, answer customer questions, support sales teams, review contracts, satisfy insurers, strengthen controls, and prove that the same issue will not happen again.
This second phase can last months. It often includes board updates, customer security reviews, vendor reassessments, password resets, access cleanup, audits, policy changes, employee training, and new tooling. The breach may be over technically, but commercially and operationally the cleanup continues.
There is no single percentage that works for every company. A company handling sensitive customer data, financial data, healthcare workflows, intellectual property, or regulated information should spend more than a company with minimal digital exposure. The better approach is risk-based: protect the systems whose compromise would create the largest business cost.
At minimum, a growing company should fund identity security, endpoint protection, patching, backups, monitoring, incident response planning, security awareness, and vendor access review. The right spend is the amount that reduces the most expensive unknowns, not the amount that buys the most tools.
Founders often miss the cost of attention. During a serious incident, leadership is pulled away from sales, fundraising, customer relationships, hiring, product delivery, and strategy. The company may survive the breach but lose weeks of momentum. That lost momentum rarely appears as a clean invoice, but it is real.
They also miss trust friction. Prospects ask more security questions. Enterprise customers demand evidence. Investors ask about controls. Insurers scrutinize renewals. The company may eventually recover, but every important stakeholder becomes harder to reassure.
No. Some incidents are contained quickly and cost far less than worst-case numbers suggest. A compromised employee account with no data exposure and fast containment is very different from ransomware across production systems or theft of customer records. The size of the breach cost depends on scope, preparation, data sensitivity, and recovery speed.
But even smaller incidents should be treated as signals. They reveal control gaps, training issues, logging weaknesses, vendor risks, or access problems. If the company learns from the incident and fixes root causes, the event can prevent a much larger future cost.
Start with identity, backups, patching, and monitoring. Enforce MFA properly, remove unnecessary admin rights, review dormant accounts, test backups, patch internet-facing systems, centralize key logs, and make sure someone is watching high-risk alerts. These steps reduce the chance that one mistake becomes a company-wide incident.
At the same time, create a simple incident response plan. Define who leads, who approves shutdowns, who calls legal and insurance, who handles customer communication, and which systems must be restored first. A basic, practiced plan can save more money during a breach than an expensive tool nobody knows how to use.
Aug 07, 2026 / 41 min read
Aug 07, 2026 / 33 min read
Aug 07, 2026 / 32 min read