In brief
- The average cost of a data breach rose in 2024 to 4.88 million dollars, 10% more than the year before (IBM, 2024).
- Organisations took an average of 292 days to find and contain a breach involving stolen credentials (IBM, 2024).
- 70% of affected organisations reported serious disruption, which makes it a business cost and not an IT line item (IBM, 2024).
- Security AI and automation lowered the cost by an average of 2.2 million dollars (IBM, 2024).
- NIS2 brings companies from around 50 employees into scope, with a duty to report within tight deadlines.
On a Tuesday morning, no one can log in. The ERP is slow, then unreachable. By midday there is a message: your files are encrypted. What follows is not a technical problem that IT quickly fixes. It ripples through the whole organisation, and the bill grows every day it lasts.
The question leadership and finance then ask is simple: what does this cost us? And the question behind it, the useful one: what could we have adjusted to make that cost smaller?
A data breach is not a cost for the IT department. It is a cost for the business, and it keeps running as long as no one sees that something is wrong.
The bill behind a data breach
The average cost of a data breach rose in 2024 to 4.88 million dollars, 10 percent higher than the year before (IBM, 2024). That is a global average across all sectors, so do not take it as your bill. Take it as the shape of the bill.
That bill has few lines on the IT side. The largest part sits in downtime, in people who cannot work, in orders that do not go out, in customers who call and get no answer. 70 percent of affected organisations reported serious or very serious disruption (IBM, 2024). That is not a server cost. That is revenue walking out while the fixed costs keep running.
And it lasts. Organisations took an average of 292 days to find and contain a data breach involving stolen credentials (IBM, 2024). Almost ten months in which someone is in your systems before you notice. The cost is not a snapshot on the day of the incident. It is a running total over those months.
For a company of 150 people the amount is lower, but the ratio holds. Take one day of full downtime: wage costs that keep running with no output, orders you miss, customers who call a competitor in the meantime. Multiply that by the days it takes to restart, and the IT bill for the recovery suddenly becomes a footnote.
Reputation is the item no one budgets for beforehand and everyone feels afterwards. A customer who hears that their data has been exposed through you does not wait for your explanation. They wonder whether they will still work with you at the next tender. That loss appears on no recovery invoice, and it is often larger than everything that does.
Why the mid-market is the target
A company of 150 people sits in an awkward zone. Big enough to be worth the effort, because there is money, there is data, there are suppliers and customers to reach through you. Too small for a security team that watches 24 hours a day. That gap is exactly what attackers look for.
Attackers do not need to be clever, they mainly need to be patient. ENISA has named ransomware and social engineering for years as the biggest threats to European organisations. Not an exotic zero-day, but an employee who clicks a link and a password that still works from someone who left last year.
'We are too small, no one targets us' is the most expensive assumption there is. Many attacks are not targeted, they are automated: scanners that sweep the whole internet for a single weak spot and strike wherever they find one. And anyone who serves a larger customer or supplier is interesting precisely because they can be the weakest link to that larger target.
Since NIS2 there is also a legal side. The directive brings companies from around 50 employees into scope, including a duty to report within tight deadlines. A data breach is therefore no longer something you handle internally and keep quiet. You have to be able to see it, prove it and report it on time. Anyone who cannot do that pays twice.
Two levers: less to steal, quicker to see
Two things decide how large the damage becomes. How much there is to steal, and how quickly you see that someone is inside. You can adjust both, and neither needs a security team of ten people.
Less to steal
Most mid-market companies have accumulated tools over ten years. A separate system for invoicing, another for the warehouse, loose folders in the cloud, a CRM that sales once bought themselves. Each of those systems has its own login, its own list of users, its own door to the outside. Every door is one that someone has to guard.
Shadow IT makes it worse. Tools that no one manages centrally, where no one cleans up the user list, where the account of a colleague who has left simply stays alive. These are not edge cases. This is the average state of a company that grew organically.
Fewer systems means fewer doors. One place to log in with SSO and MFA, instead of twelve separate passwords that end up on sticky notes. One user list that you actually manage. Anyone who leaves loses access to everything in a single action, not to the seven systems IT happens to think of at the time.
There is a second bill underneath as well. Twelve systems are twelve contracts, twelve per-user prices that rise with every hire, twelve suppliers each moving in their own direction. Consolidating not only shrinks the attack surface, it also brings that stack of fixed costs down.
Quicker to see
The 292 days from the IBM report are not a law of nature. They are the result of not being able to look. If logs are spread across ten systems, or kept nowhere, then no one notices that an account logs in at three in the morning from abroad and empties the customer database.
On one platform that activity sits in one place. An anomaly stands out because there is something to compare it against. Security AI and automation lowered the average cost of a data breach by 2.2 million dollars (IBM, 2024), and that is almost entirely because they shorten the time to discovery. Every day earlier is a day less damage.
Seeing quickly is half of it. Being able to contain quickly is the other half. That requires that you know which systems connect to each other, where your backups sit and whether they stand far enough apart to survive a ransomware attack. On a scattered landscape that is guesswork. On one platform it is a map you know.
You do not need a team watching screens 24/7 to turn those two levers. You need an environment small enough to oversee, and one that records who did what on its own.
What an audit uncovers
Before you build or buy anything, it pays to know what is really running now. An audit almost always produces the same picture, and it is rarely the picture that was on paper.
- Shadow IT: subscriptions and tools bought outside IT, paid for on a personal card or a department budget, without anyone centrally knowing they exist.
- Dead accounts: logins of people who left months or years ago and still have access. Each one is a key left lying outside.
- No central logging: systems that do not record who did what, or that do record it in a place no one reads. An incident you did not log is one you cannot reconstruct.
- Duplicate data: the same customer records in four systems. Four times as much to leak, four times as much to secure.
None of those things appears in a supplier's quote. They surface during an IT FinOps or security audit, and usually the conclusion is that the problem is not too little security, but too many separate parts to secure.
What ownership changes
The alternative to ten tools is not one large supplier you are locked into. That swaps one problem for another. The alternative is one platform that you own yourself.
Ownership here is literal. The code sits from day one in your own repository, on EU cloud, without a per-user licence that grows with your headcount. SSO and MFA are not an add-on, they are in the foundation. The audit trail sits in one place, ready for the reporting duty that NIS2 imposes. Anyone who leaves loses access to everything at once, because there is no scattered 'everything' anymore.
That is the difference between security as a layer you put over the top, and security as a property of how the system is built. At YK Technologies we build that in waves, with a go/no-go at every transition, so you are never locked into a choice made a year ago.
A data breach costs you the most on the day you can no longer do anything about it. Every choice that lowers the bill, you make beforehand. Less to steal, and quicker to see. Both start with knowing what you run now, not with what the brochure says.
Sources
Want to apply this to your own situation?
Belgian, founder-led and built to hand over. One email is enough.
More reading
