What a cyberattack really costs an SME

When a business owner imagines the cost of a cyberattack, they usually think of a ransom. That is the visible part, the one that appears in press articles. In the accounts of an SME that has been hit, it is rarely the heaviest line, and sometimes it does not even exist.

The real bill is made up of several items, some of which never appear on any invoice. The first is business interruption: while the systems are blocked, the company invoices nothing, or far less. The second is technical recovery: a provider steps in, analyses what happened, cleans up the workstations, rebuilds the servers, restores the data and verifies that the attacker no longer has access. This work is counted in billed days of work.

The third item is invisible and often the most underestimated: the time of your own teams. Re-entering orders, reconstructing files from e-mails, calling customers back one by one, catching up on the backlog built up during the downtime. These hours are not billed to anyone, but they are paid, and they produce nothing new.

Then come costs that vary case by case: notifying the people concerned if personal data has leaked, legal advice, a possible criminal complaint, the late-delivery penalties set out in your contracts, and the technical hardening decided after the fact, which would have been far cheaper to undertake beforehand. The ransom, when it is paid, adds to all of this without replacing anything: it only partly speeds up recovery, and erases none of the other items.

The scale of the phenomenon is anything but theoretical. The National Cyber Security Centre (NCSC) received 64,733 voluntary incident reports in 2025, up from 62,954 the previous year, according to its 2025/II half-year report published on 30 March 2026. Among them, 57 ransomware incidents were reported in the second half of 2025. These figures say nothing about cost, but they show that the subject is no longer a textbook hypothesis.

Why business interruption weighs more than the ransom

A ransom is a single, known, negotiable amount. Business interruption is a meter that keeps running. That is the essential difference, and it is what explains why two companies of comparable size, hit by the same attack, can end up with bills that differ by a factor of ten.

Take a services company with two million francs in revenue. Over about two hundred and fifty working days, that comes to eight thousand francs a day. If most of its activity runs through its files and software, every day of standstill costs several thousand francs before an IT technician has even sent a first invoice. Three days of downtime and ten days of downtime are not the same event.

What determines this duration is not the sophistication of the attack, but the quality of preparation. A company that has a copy of its data off the network, and has already verified that this copy restores, is back up in a few days. A company whose backups have never been tested discovers at the worst possible moment that the restore file is incomplete, corrupted, or that it too was encrypted because the disk stayed permanently plugged in. It then enters a long reconstruction, and it is precisely at that moment that paying a ransom becomes tempting.

This is why the question of tested backups weighs more, in the simulator above, than the sector of activity or the size of the company. It is also why the 3-2-1 backup rule is the measure with the best effort-to-protection ratio for an SME. It costs almost nothing, and it divides the length of the downtime, and therefore the cost, by proportions no other measure achieves.

A worrying signal comes, moreover, from the perception of the owners themselves. According to the 2025 SME Cybersecurity study, 42% of Swiss SMEs consider their protection sufficient, down from 55% a year earlier. Confidence is declining, which is rather healthy, but it is declining without the basic measures becoming widespread.

What cyber insurance does and does not cover

Cyber insurance is a useful tool, provided you know what you are buying. The policies offered in Switzerland generally cover two things well: emergency response costs, often through a provider imposed by the insurer, and business interruption during the outage, up to a limit and over a period set out in the contract.

Most policies also include legal assistance, the cost of notifying the people concerned in the event of a data leak, and third-party liability cover if a third party holds you responsible for the damage. Some cover the ransom, often with strict conditions and the insurer's prior agreement.

What is less well covered deserves a careful reading of your general terms and conditions. A time-based deductible almost always applies: the first hours or first days of interruption remain at your expense, which is enough to absorb a good share of small claims. The time spent by your own teams is almost never compensated. Loss of customers and reputational harm are not compensated either. Technical improvements decided after the incident remain at your expense, even though they are often the condition for renewing the contract.

Finally, several contracts make compensation conditional on complying with security measures declared when the policy is taken out: regular backups, two-factor authentication, applied updates. An inaccurate declaration weakens the cover at the very moment you need it. Insurance transfers part of the financial risk. It replaces neither backups nor basic measures, and it does not reimburse lost time.

The limits of any estimate

It must be said clearly what this simulator cannot do. It knows neither your activity's margin, nor your cash position, nor your contractual commitments, nor the season in which the incident would occur. A five-day standstill in the middle of a quiet period and the same standstill on the eve of a major deadline have nothing in common.

The model reasons on revenue, not on margin. Part of that revenue is sometimes recovered after resuming, when orders are simply postponed; another part is permanently lost, when the customer has gone elsewhere. We account for this by applying a recovery in the lower bound and none in the upper bound, but this split remains an assumption, not a measurement.

The downtime durations used are, likewise, deliberate working assumptions. They reflect a simple, observable reality: a prepared company recovers quickly, an unprepared company rebuilds. They do not claim to describe your case. If you have reason to think your recovery would be faster or slower, mentally replace the number of days in the breakdown shown and recompute the product: that is precisely why every line of the calculation is visible.

What this tool does, on the other hand, it does honestly. It turns a vague worry into a debatable order of magnitude, based on your figures and on assumptions you can challenge one by one. That is enough to settle the only question that matters at the outset: is the stake a few thousand francs, or several hundred thousand. The answer determines the effort it is rational to devote to prevention.

To go further, the cyber check-up gauges your level of protection in twelve questions, and the Tools page brings together the site's other free resources.