blog

The Hidden Costs of a Cyberattack No One Talks About

  • September 28, 2026

When a breach happens, the costs that get counted are the ones with paperwork. Forensics and outside counsel, notification letters and regulatory fees, the incident response retainer. Real money the finance team can model down to the dollar.

That is the number most breach-cost headlines report. Sometimes, it is the smaller half of what happened.

Sometimes, the larger half does not arrive as an invoice. It arrives in the revenue line, quarter after quarter, long after the incident is closed and the press has moved on. For large enterprises above $5 billion in revenue, the part of a breach that rarely shows up on an invoice, reputational loss, comprises 60% of expected breach costs on average (Cye, Hidden Costs of a Cyberattack). That is the number worth talking about.

TL;DR

  • Reputational loss makes up 60% of expected breach costs above $5 billion in revenue.

  • The direct invoice and the revenue damage follow different timelines.

  • Operational downtime alone costs Global 2000 companies $600 billion a year, per Splunk's 2026 research.

What This Means for the Next Breach

The hidden side of a breach keeps billing after the incident closes, and it rarely arrives as an invoice. It shows up as churn, as lost renewals, and as the deals that quietly stop moving.

Cyber insurance pays the invoice but leaves the revenue damage untouched. Coverage replaces the cash, and that is the only part the policy was written for.

What are the hidden costs of a cyberattack?

The hidden costs are the indirect losses that never show up on an invoice. They are reputational damage, customer churn, lost contracts, operational downtime, intellectual property loss, and higher insurance premiums. They are harder to measure than the direct costs. They last longer. And they can add up to more than the incident bill itself.

The direct side is easy to point at because it bills you. The hidden side bills the business slowly. A customer who quietly does not renew. A prospect who picks the competitor after reading the headline. A contract clause that now requires security controls you cannot yet prove.

None of those generate a receipt. All of them cost real money one way or another. Cye's AI-native exposure management platform prices this hidden half by modeling the specific business parameters (industry sector, annual revenue, record counts, system dependencies, and NIST CSF security maturity) that dictate actual financial loss. By attaching an actuarial Cost of Breach (CoB) to each business-critical asset, boards can evaluate emerging threats in financial terms and decide whether to remediate, mitigate, or accept based on residual risk.

Core areas of your organization where costs can be incurred include:

  • Business continuity: Lost revenue from halted operations, unfulfilled transactions, and workforce productivity drops.

  • Reputation: Market share loss, enterprise deal velocity drop-off, and brand devaluation.

  • Customer information: Regulatory penalties, privacy notification costs, litigation, and long-term customer churn.

  • Intellectual property: Permanent erosion of competitive advantage, trade secret theft, and source code exposure.

  • Employee information: Internal liability, payroll/HR overhead, and regulatory fines for compromised workforce data.

Each of those costs lands somewhere other than the incident invoice, which is why the visible total understates the breach.

Why the visible cost is the smaller one

The visible cost is smaller because it captures only the response to the breach, while the damage the breach does to the business afterward goes uncounted.

The 2026 IBM Cost of a Data Breach Report put the global average at USD 4.99 million, a 12% increase over the prior year and a record high, and attributed the rise to higher detection, escalation, and lost-business costs rather than the forensic and legal work.

Reputational loss alone accounts for 60% of expected breach costs at companies above $5 billion in annual revenue (Cye).

A security budget sized against only the insurable invoice could be missing a large portion of the real exposure.

Direct costs vs hidden costs of a breach

The two categories behave differently. Direct costs are large, immediate, and finite. Hidden costs are larger, delayed, and in some cases permanent.

Sizing a breach against the first and ignoring the second is how boards get surprised twice. The first surprise is the incident. The second is the four quarters after it.

This is the split every board and CFO should see before signing off on a security budget.

The hidden costs are what decide whether a breached company merely has a bad quarter or loses its market position. Accurate pricing of open attack paths to business-critical assets means a board can prioritize closing the paths and choke points carrying the most business risk. 

Reputational loss is, sometimes, the largest line item

Reputational damage is, in some cases, the single biggest hidden cost because it converts directly into lost revenue through customer churn and lost deals. It is not a soft, unmeasurable concept. It shows up as a market-cap drop and a renewal rate.

The market reprices a breached company fast. When Okta was breached in October 2023, its valuation fell roughly two billion dollars within days. CrowdStrike's shares fell 39.5% over the month of July 2024, the month of its global outage (Motley Fool).

Customers reprice it too. In sectors where the product is built on trust (such as, but not limited to finance, healthcare, infrastructure) a breach converts directly into churn and lost renewals. 

Then there are the contracts you never see lost. A breached vendor fails the security review on the next enterprise deal. The prospect does not send a rejection explaining why. The revenue simply does not appear.

Why cyber insurance can't cover the hidden side

Cyber insurance is structurally built to pay the invoice, and it leaves the revenue damage uncovered, which is exactly the smaller half of the loss.

Reputational damage is seldom covered by cyber policies because the loss is hard to attribute. Proving that a specific dollar of churn was caused by a specific breach may not meet a policy's causation bar (Cye).

Not to mention that insurers are also enforcing what they sell. After the 2024 ransomware attack on the City of Hamilton, the insurer declined a roughly $5 million claim because the city had not fully implemented multi-factor authentication (CBC News). 

Payout is no longer automatic. The claim can be declined when required controls were not deployed.

This is the argument in 'The Hidden Costs of a Cyberattack: The Impact on Reputation'. Organizations must "mitigate risk first and then transfer the remaining risk to cyber insurance" because insurance is not a replacement for mitigation (Cye). Treating the policy as a substitute for mitigation is how a company ends up insured against the small number and exposed to the large one.

The costs that keep billing after recovery

Some hidden costs do not stop when the systems come back online. Downtime and intellectual property loss are the two that keep charging the business long after the incident response team has gone home.

Downtime

Downtime bills by the minute while it lasts. General IT outage costs average $14,056 per minute as of 2024, rising to $23,750 per minute for large enterprises. These figures cover IT outages from any cause rather than breach-caused downtime (EMA).

Over 90% of mid-size and large enterprises report that a single hour of downtime costs more than $300,000.

Almost half of those (41%) put costs at $1 million to over $5 million (ITIC 2024). In ITIC's 2025 survey, 93% of firms say an hour of unplanned downtime costs at least $300,000 (ITIC 2025). In manufacturing, energy, or healthcare, a short outage means missed transactions, idle production, and contractual penalties stacking up in real time.

Uptime Institute's 8th Annual Outage Analysis, published 13 May 2026, puts thresholds on the same problem. 57% of respondents said their most recent major outage (for an outage of any cause) cost more than $100,000. One in five put it above $1 million (Uptime Institute 2026). 

Unplanned downtime now costs Global 2000 companies $600 billion a year, a 50% increase in two years, Splunk's 2026 downtime research, which calls it a systemic business crisis rather than an IT problem.

Intellectual property

IP loss is the cost with no invoice and no end date. A stolen design, source tree, or customer model is a permanent transfer of advantage to whoever took it. There is no recovery date, no closed ticket, and no number on a breach report. The damage compounds quietly for as long as the stolen asset stays valuable.

These are the costs that separate a breach you survive from one you never fully recover from.

How do you put a number on the hidden costs?

You quantify the hidden costs the same way you quantify the visible ones, by modeling expected loss per asset in dollars, including the reputational and business-impact components most teams leave out.

This is cyber risk quantification (CRQ). Stating risk as the monetary value of the potential loss from a cyber event, asset by asset. Cye's 2026 Global AI and Cyber Maturity Report found regulation rather than budget to be the bigger driver of maturity gains, with Switzerland improving 16% after its regulatory deadlines landed.

A cost-of-breach figure that captures only the invoice is the trap. Cye's breach cost methodology calibrates its number to include reputation loss because that line item can be a large portion of the exposure for large enterprises.

Cye models Exposure as Cost of Breach (CoB) × Likelihood of Breach (LoB). It is an actuarial CoB per business-critical asset, calibrated on 250,000+ real-world events. Multiplying this figure by the likelihood (LoB) that an attacker reaches said business-critical asset enables you to price exposure. 

The Cost of Breach estimate accounts for 93% of the variables that dictate actual loss. Its model takes into account:

  • Company & operational profile: Annual revenue, total salaries, employee count, HQ jurisdiction, company age, and uptime/productivity dependencies.

  • Customer & data profile: Total customer records, sensitive data types (PII, PCI, PHI), and direct competitor density.

  • Cybersecurity maturity: NIST CSF maturity, which applies a statistical discount or premium to your modeled risk.

To facilitate this model, Cye's Org Attack Graph first maps and validates routes to business-critical assets. CoB × LoB can then price the resulting exposure. A model, built in this way, validates real exploitability, live on the organization's actual environment, as it changes.

The result is being able to prioritize the next quarter's budget on the few routes that can reach a business-critical asset rather than thousands of CVSS "high" ratings which may or may not lead to a BCA.

Once the hidden costs carry a monetary figure (the financial exposure), the security budget can finally be argued against the real exposure instead of the insurable fraction of it. The response then settles into a remediate, mitigate, or accept decision.

For each validated, priced path, remediate fixes the root cause, mitigate applies a compensating control when a clean fix is not realistic this cycle, and accept records the risk appetite, owner, rationale, review date, and reassessment trigger.

Before committing budget, Cye's What-If Analysis models each response's expected-loss reduction, the validated paths it closes, and the residual exposure. 

You can re-run the What-If Analysis as your environment changes and compare what different decisions would do, so the CFO or board can defend the expected-loss reduction behind each option before approving spend. Mitigate the risk first, calibrate the breach figure to include the 60% that lives in reputation, and transfer only the residual to insurance. In that order.

The bottom line is that the invoice is the smaller half of the breach

The response bill is real, and it is the smaller half of the loss. Reputational damage, customer churn, and lost contracts keep billing long after the clean-up vendor leaves, and cyber insurance is built to cover the invoice rather than the revenue damage. Count the full expected loss in dollars before the incident, and the hidden side stops being a surprise and starts being a decision input. That separates a business that priced the breach from one that paid it.

Frequently asked questions

Executives and security leaders ask the same questions when they size the true cost of a breach.

What do hidden breach costs include?

Reputational damage, customer churn, regulatory fines, downtime beyond the incident window, IP loss, and higher insurance premiums. What changes the total is how long they keep billing after the systems come back. A breach that is technically resolved in a week can generate churn and premium increases for two years.

Why is the direct cost of a breach the smaller number?

Because the direct cost only captures the response to the incident. What the breach keeps costing after that response is over goes uncounted.

At enterprise scale the gap between what gets invoiced and what gets lost widens, and the hidden side is where the budget argument lives. The invoice is the visible half. The revenue damage is the larger, hidden half.

Does cyber insurance cover reputational damage and lost business?

Rarely. Cyber insurance is built to pay the direct invoice for forensics, legal work, and notification, but reputational loss is seldom covered because proving that a specific dollar of churn was caused by a specific breach almost never meets a policy's causation standard.

How much does downtime cost during a cyberattack?

For a large enterprise, the average cost of an unplanned outage runs to $23,750 per minute, against $14,056 per minute across all company sizes. Those are outage costs from any cause rather than breach-caused downtime specifically (EMA). ITIC's 2025 survey adds the hourly view, with 93% of firms putting an hour of unplanned downtime at $300,000 or more (ITIC 2025).

Unlike forensic costs, downtime bills continuously for as long as systems are unavailable, which is why a breach that takes critical operations offline can cost far more than the incident response itself.

How do you quantify the hidden costs of a cyberattack?

You use cyber risk quantification (CRQ) to model expected loss per asset in dollars, including the reputational and business-impact components most cost estimates leave out. A credible cost-of-breach figure has to be calibrated to include reputation loss, because for large enterprises that is the majority of the exposure.

Modeling the likelihood and dollar cost of a breach for each impacted asset puts the hidden side of the loss on the same page as the visible side, so the security budget can be argued against the real exposure rather than only the insurable fraction of it.

Further Reading

  • Cye, the hidden costs of a cyberattack, the 60% reputation figure: https://cyesec.com/blog/hidden-costs-cyberattack-impact-reputation

  • Cye, mitigation vs. remediation and the mitigate-first principle: https://cyesec.com/blog/mitigation-vs-remediation

  • CNBC, Okta's October 2023 breach and the market-value loss: https://www.cnbc.com/2023/10/23/okta-hack-wipes-out-more-than-2-billion-in-market-cap.html

  • Motley Fool, CrowdStrike's share decline in July 2024: https://www.fool.com/investing/2024/08/02/why-crowdstrike-stock-plunged-40-last-month/

  • Cye, cyber risk quantification vs. optimization, the $100M/20% example: https://cyesec.com/blog/cyber-risk-quantification-vs-cyber-risk-optimization

  • IBM, 2026 Cost of a Data Breach Report, the $4.99M average and 247-day lifecycle: https://www.ibm.com/reports/data-breach

  • SEC, cybersecurity disclosure rules, Form 8-K Item 1.05 (2023-139): https://www.sec.gov/newsroom/press-releases/2023-139

  • Splunk, 2025 CISO Report (with Oxford Economics), board budget scrutiny: https://www.splunk.com/en_us/newsroom/press-releases/2025/splunk-report-cisos-gain-influence-in-the-c-suite-and-boardrooms-worldwide.html

  • CBC News, City of Hamilton cyberattack claim decline (2025): https://www.cbc.ca/news/canada/hamilton/cybersecurity-breach-1.7597713

  • EMA (Enterprise Management Associates) research published by BigPanda, 2024 IT outage costs, $14,056 per minute average and $23,750 for large enterprises: https://www.bigpanda.io/blog/it-outage-costs-2024

  • ITIC, 2024 Hourly Cost of Downtime Report, 90% of enterprises above $300K per hour: https://itic-corp.com/itic-2024-hourly-cost-of-downtime-report/ | ITIC 2024-2025 Global Server Hardware, Server OS Reliability survey (polled February-November 2024, updated April 2025), 93% of firms above $300K per hour: https://itic-corp.com/itic-reports-surveys

  • Uptime Institute, 8th Annual Outage Analysis 2026, 57% above $100,000 and one in five above $1 million: https://uptimeinstitute.com/about-ui/press-releases/uptime-announces-annual-outage-analysis-report-2026

  • Cye, cost of breach estimator, estimate your breach cost in two minutes: https://cyesec.com/cost-of-breach-estimator

Last Updated: 2026-09-30

Request A Demo

Learn how Cye Platform can help you understand the true potential cost of cyber exposure, effectively communicate with executive teams, and prioritize remediation strategy and planning.

Here's what we'll cover:

  • Your objectives and challenges
  • An overview of Cye platform and the right packages for you
  • Your cybersecurity industry benchmark and how you compare
  • Your current exposure management program