MalwareRansomwareDigital Transformation
Hiscox: cyber attacks cost small firms USD $52,000
Thu, 17th Sep 2026 (Today)
JOSEPH GABRIEL LAGONSINNews Editor
Hiscox’s 10th Cyber Readiness Report found that 29% of organisations suffered at least one successful cyber attack in the past year. The study drew on responses from 6,800 cyber security decision-makers, including 1,000 in the UK.
The findings highlight a steady financial and operational burden for smaller businesses. On average, cyber incidents cost organisations USD $52,000 a year and caused about 32 hours of disruption, based on the insurer’s research into companies with fewer than 250 employees across the UK, mainland Europe and the US.
Beyond the immediate cost, businesses reported wider effects on growth and staffing. Nearly a third said cyber incidents had delayed growth and expansion plans, while 31% cited increased staffing costs, 30% reported financial damage and 29% said they had lost opportunities.
Reputational harm emerged as the leading concern after an incident. Almost half of respondents, 48%, ranked damage to reputation and customer trust as the most significant risk, ahead of operational downtime or business interruption at 46% and supply chain or third-party disruption at 44%.
Among businesses that had been hit, 28% said they had faced financial penalties and 26% had experienced bad publicity. The findings suggest the effects of an attack can continue after systems are restored, especially for smaller firms with limited capacity to absorb extra costs or customer losses.
The survey also found that cyber incidents are shaping management decisions and workplace policy. Nearly a third of firms, 32%, said they now link executive compensation or performance to cyber security outcomes after a hack, while 24% said they had reduced remote or hybrid work access following an incident.
This suggests cyber security is becoming more closely tied to governance and operational oversight, rather than sitting solely within technology teams. For smaller employers, attacks are driving changes not only in software budgets, but also in how senior leaders are assessed and how staff are allowed to work.
Companies are also increasing spending in response. Average investment in cyber resilience measures stood at USD $51,000, almost matching the average annual cost of incidents.
That spending is spread across technology, recruitment and workforce preparation. More than half of respondents said they were investing in new technology, 55% said they were hiring specialist staff and 62% said they were updating employee training.
The report presents cyber risk as an increasingly routine part of business operations rather than a rare shock event. While the released material does not break out all findings by individual market, the inclusion of 1,000 UK respondents provides a substantial sample of British small and medium-sized businesses within the wider data set.
Eddie Lamb, Global Head of Cyber at Hiscox, said the results reflected a broader change in how companies view online threats. “During our 20+ years of insuring cyber risks and our decade of Cyber Readiness research, we’ve seen a clear shift in the cyber threat and how businesses respond to it. Cyber risk has become a recurring cost, not an exceptional event, so the investment we’re seeing in cyber resilience is good news as businesses start to take back control,” Lamb said.
The research was conducted among cyber security decision-makers in organisations with fewer than 250 employees. That focus places the report squarely on the small and medium-sized business segment, where resources are often tighter and the effects of downtime can quickly be felt across sales, staffing and customer service.
For insurers and business advisers, the results add to evidence that many smaller companies no longer see cyber attacks as a remote or specialist concern. Instead, they are factoring them into budgets, operating models and executive accountability, with average resilience spending now almost level with the average annual losses reported from incidents.
ChatGPT
Key takeawaysExplain why it mattersCreate action planFuture watch
Claude
Key takeawaysExplain why it mattersCreate action planFuture watch
Perplexity
Key takeawaysExplain why it mattersCreate action planFuture watch
Grok
Key takeawaysExplain why it mattersCreate action planFuture watchShareShareAdd us as a preferred source on Google
Related stories
AI-driven cybercrime surges at scale, Flashpoint warnsCheck Point warns of rising cyber attacks & AI riskCheck Point warns of rising attacks & AI data leak riskAutomotive firms face crisis after 24 hours’ outageiStorage warns firms to secure data beyond networks
Top stories
Cloudways launches Velocity managed Node.js hostingInsight backs Scotland’s AI scaling adoption programmeTMX Transform appoints Frances Farren as UK directorFIOR names Gemma Ungoed-Thomas as sovereign AI adviserHES FinTech expands UK payments deal with Acquired
