← Back to Insights
Risk explainer5 Min Read

What Does a Data Breach Cost a Small Business? The Downtime Math

A five-day outage costs a $10M company roughly $200,000 before any recovery invoice arrives, and IBM measured a $670,000 premium on breaches traced to AI tools nobody inventoried. Here is the math, and the three things that shrink it.

AZ InnovationsMay 25, 2026

The diagnostic behind this article

Microsoft Estate Risk Ledger

$3,500

Review the full scope →

A company generating $10M a year produces roughly $40,000 a business day, so five days offline costs about $200,000 in stalled work, wasted salary, and missed revenue before a single recovery invoice arrives. That number does not appear on the ransom note. For most small and mid-market companies, the ransom is the least of the worries. The expensive part is what stops while you recover, and what it costs to have never closed the doors in the first place.

The bill starts on day one, when email goes off

The moment you suspect a breach, your business stops.

  • Day 1: Email is turned off. Nobody can invoice. Nobody can sell.
  • Day 3: You are still scrubbing servers. Clients are asking why you are not responding.
  • Day 7: You are back online, but every password has been reset, sessions are revoked, and half the week went to explaining instead of working.

Five days offline costs a $10M company about $200,000

Run the same arithmetic on your own numbers. Divide annual revenue by roughly 250 business days, multiply by the number of days you would realistically be down, then add the recovery invoice on top. The figure above is an illustration at $10M; the shape of the problem holds at any revenue.

What the research says the gaps cost

The IBM Cost of a Data Breach Report 2025 put numbers on the pattern behind most incidents: ungoverned gaps compound the bill. One in five organizations reported a breach traced to shadow AI, unsanctioned tools nobody inventoried, and those breaches cost an average of $670,000 more than at organizations with little or none. Among breached organizations, 63% had no governance policy for the gap that hurt them, or were still writing one.

The lesson generalizes past AI: breaches are most expensive where nobody could say what existed, who had access, or what to restore first. The inventory you did not have becomes the invoice you did not expect.

What actually shrinks the bill

Common questions about what a breach costs

How much does a data breach cost a small business?

There is no single figure, so work it from your own revenue. A company generating $10M a year produces roughly $40,000 a business day, which puts five days offline at about $200,000 in stalled work and missed revenue before the recovery invoice arrives. Divide your annual revenue by roughly 250 business days and multiply by the number of days you would realistically be down.

Is the ransom the largest cost of a breach?

For most small and mid-market companies it is not. The ransom is a single invoice, while the outage around it stops invoicing and selling for days, and the cleanup carries on after the systems come back: every password reset, every session revoked, and days spent explaining the incident instead of working.

How long is a business offline after a breach?

Assume days. The illustration in this article runs a week: email switched off on day one so nobody can invoice, servers still being scrubbed on day three while clients wait for an answer, and back online by day seven. How long you are actually down turns on how fast you can restore, which nobody knows until someone has performed a restore and timed it.

What makes one breach cost more than another?

Gaps nobody governed. The IBM Cost of a Data Breach Report 2025 found that one in five organizations reported a breach traced to shadow AI, unsanctioned tools nobody inventoried, and that those breaches cost an average of $670,000 more than at organizations with little or none. Among breached organizations, 63% had no governance policy for the gap that hurt them, or were still writing one.

What actually reduces the cost of a breach?

Three things, in order: an inventory of identities, admin roles, devices, and data exposure ranked by risk; closing the standing gaps, meaning legacy authentication, permanent admin roles, and files shared wider than intended; and a restore path someone has actually performed and timed.

Compare all of that to the cost of finding the gaps on purpose: the $3,500 Microsoft Estate Risk Ledger inventories the risk, the waste, and the missing ownership across your environment and prices the fix, before an incident runs the math for you.

About the author

Written by the founder of AZ Innovations: a Microsoft-certified solutions architect, Top Rated on Upwork with a 100% Job Success score, who personally scopes and delivers every engagement. Name shared on the first call. See the delivered work or read a representative sample report.

Want this proven in your tenant?

The Microsoft Estate Risk Ledger turns this into scored findings and a fixed remediation plan for your environment.

$3,500

Talk through the problem Browse the diagnostics