Sentry
Most business owners picture a cyberattack as a single bad day. A ransom note. A frozen screen. A frantic call to IT.

In reality, the cost of a cyberattack tells a different story. For Australian small and medium businesses, a single breach can trigger weeks of disruption, thousands of dollars in unplanned spending, and damage that lingers long after the systems are back online.

According to the Australian Signals Directorate, the average small business now loses $56,600 to a single cybercrime incident, a 14% jump on the year before. That figure covers a lot of ground: downtime, recovery, lost customers and, in some cases, regulatory scrutiny.

So what actually happens after a breach, and what does it really cost? Here’s the breakdown, including a real case from one of our own clients.

What Happens in the Hours and Days After a Breach

A cyberattack rarely announces itself clearly. Most businesses notice a symptom first, not a warning label. Bounced emails, a locked file, a strange login alert, or a worried call from a client are usually the first signs.

Here’s the typical sequence once an incident is confirmed:

  1. Detection. Someone notices unusual activity, or a security tool flags it. The longer this takes, the more expensive the incident becomes.
  2. Containment. Affected systems are isolated to stop the attack spreading further.
  3. Investigation. A forensic review works out what happened, what was accessed, and how the attacker got in.
  4. Notification. If personal information was compromised, the business may need to notify the OAIC and affected individuals under the Notifiable Data Breaches scheme.
  5. Recovery. Systems get rebuilt, passwords get reset, and normal operations slowly resume.
  6. Review. A proper response includes a plan to stop the same thing happening again.

If you’re in the middle of a suspected breach right now, don’t wait to work out the next step. Our incident response team can help you contain it fast.

The Real Cost of a Cyberattack, Broken Down

When people ask about the cost of a cyberattack, they usually mean the ransom or the IT bill. In reality, that’s only part of the picture.

Direct costs

These are the expenses tied directly to the incident:

  • Emergency IT and forensic investigation fees
  • System repairs, rebuilds and new security tools
  • Legal advice and regulatory notification costs
  • Staff overtime to manage the response
  • Ransom payments, in the rare cases businesses choose to pay (most experts advise against it)

That $56,600 average for small businesses, mentioned earlier, mostly falls into this direct-cost bucket. Medium businesses fared worse in the same Annual Cyber Threat Report, losing $97,200 on average. That’s a 55% jump on the year before.

Indirect costs

These costs build up more slowly, and they’re often bigger:

  • Lost revenue while systems are down
  • Clients who quietly move to a competitor
  • Higher insurance premiums at renewal
  • Staff time diverted away from paying work
  • Reputational damage that outlasts the headline

IBM’s 2026 Cost of a Data Breach Report puts the average Australian breach at $4.22 million once every cost is added up. That figure includes large enterprise incidents, so it sits well above what most small businesses actually experience. Even so, a small fraction of that total can hurt a small business for months.

When a Website Breach Took Down a Client’s Email

Not every cyberattack targets data directly. Sometimes the damage is more indirect, and just as disruptive.

One of our clients, Enviroscope, a commercial and industrial maintenance business, found their website had been compromised with hidden malicious code. The malware was built to hide from admins and scanners, so it went unnoticed for a while.

The knock-on effect was serious. Their domain reputation dropped, and their emails started being blocked or flagged as spam, particularly on Microsoft platforms. For several days, invoices, client updates and day-to-day communications simply weren’t landing in inboxes.

Sentry Cyber’s team responded within hours, working outside business hours to speed up recovery. We removed the malicious code and verified the site was clean. Then we worked through the DNS and email authentication settings needed to rebuild domain trust. A full remediation report was delivered within a week, and email deliverability was restored.

Read the full Enviroscope case study for the technical breakdown of what happened and how it was fixed.

The lesson here is simple: a breach doesn’t have to touch your inbox directly to break your inbox.

The Trust Cost of a Cyberattack

Some of the worst damage from a breach has nothing to do with your systems. It happens in your clients’ inboxes, and in their heads.

When Your Data Ends Up on the Dark Web

If an attacker gets into your systems, they’re often not just looking to lock you out. They’re looking for data they can sell. Names, addresses, dates of birth, driver’s licence numbers, tax file numbers. This is exactly the kind of personally identifiable information (PII) that ends up for sale on dark web marketplaces, sometimes within days of a breach.

Once that data is out, you can’t get it back. It doesn’t disappear when you pay a ransom or patch a vulnerability. It sits there, ready to be used against your clients for identity theft, months or years later.

Under the Notifiable Data Breaches (NDB) scheme, this kind of exposure usually triggers a legal obligation. If it’s likely to cause serious harm, you have to tell every affected client. That’s the right thing to do. Telling a client their data may be on the dark web is also one of the hardest emails you’ll send. It’s not a conversation that builds trust.

When Your Own Account Starts Attacking Your Clients

Over 90% of cyberattacks start with a phishing email landing in someone’s inbox. Once an attacker is inside a mailbox, business email compromise is one of the most common next steps we see.

Here’s what that typically looks like. The attacker doesn’t announce themselves. They sit quietly, reading your emails, searching Google Drive or other cloud file systems and learning how you write and details about your identity. Then they use your actual account to send more phishing emails to your entire client list. Because these emails come from a real, trusted address, people click. That’s the whole point.

We saw exactly this play out for one Melbourne business owner. A compromised Google Workspace account went unnoticed for six months. During that time, the attacker used it to attempt a fraudulent $50,000 tax return in her name. Her accountant caught it just in time.

Read the full account compromise case study to see exactly how it happened, and how it was caught.

This is why business email compromise is so damaging to trust. It’s not a stranger emailing your clients. It’s you, or what looks exactly like you.

Bad News Travels Fast

Every day, another Australian business ends up in a headline about a data breach. If that business is yours, current clients start asking questions. Prospective clients researching you online may find the story before they find your services page.

Trust, once lost this way, is expensive to rebuild. It shows up as slower sales cycles, harder renewals, and clients who quietly choose a competitor instead of asking why.

Why Small Businesses Feel It the Hardest

Large enterprises can usually absorb a big breach. They have dedicated security teams, cyber insurance, and cash reserves built for exactly this kind of disruption.

Small and medium businesses rarely have that buffer. A single cyberattack can mean weeks of lost productivity, a scramble to notify clients, and a hit to cash flow that a bigger company would barely notice.

It also explains why attackers increasingly target smaller businesses. Weaker defences, combined with valuable client data, make SMBs an attractive target rather than an afterthought.

The Office of the Australian Information Commissioner recorded 1,205 data breach notifications in 2025. That’s the highest number since mandatory reporting began in 2018, and an 8% rise on the year before. Every one of those started as somebody’s ordinary Tuesday.

How to Lower Your Risk (and Your Potential Costs)

The good news is that most of the cost of a cyberattack is preventable. Businesses that invest in the basics consistently pay less, recover faster, and notify fewer people when something does go wrong.

A few places to start:

  • Know your weak points. A vulnerability assessment shows you exactly where an attacker would get in first.
  • Test your defences properly. Penetration testing simulates a real attack, so you can fix the gaps before someone else finds them.
  • Train your people. Most breaches still start with someone clicking the wrong link. Cyber awareness training turns your team into a line of defence instead of the weakest one.
  • Watch your systems around the clock. Security monitoring catches unusual activity early, well before it becomes a 200-day breach.
  • Build on a proper framework. The Essential Eight is the government’s baseline standard for good cyber hygiene, and our compliance and certification support can take you further.
  • Lock down your cloud tools. If your business runs on Google Workspace, our Google Workspace security services close some of the most common gaps we see attackers exploit.
  • Close the AI gap. IBM’s research found that businesses without AI-assisted security tools face notably higher breach costs. Our AI Security & Risk Assessment service helps you catch up.

Want a simple starting point? Our free Google Workspace Security Playbook is a practical download, with no cost and no obligation.

Frequently Asked Questions

How much does a cyberattack cost an Australian small business?

The Australian Signals Directorate reports an average of $56,600 per incident for small businesses, up 14% on the previous year. The real number depends heavily on how quickly the breach is caught and contained.

What’s the biggest hidden cost after a breach?

Lost time and lost trust. Staff hours spent on recovery instead of paying work, and clients who quietly stop doing business with you, often outweigh the direct IT costs.

Do I have to tell customers if my business is breached?

If personal information is involved and the breach is likely to cause serious harm, you’re required to notify the OAIC and affected individuals under the Notifiable Data Breaches scheme.

How long does it typically take to recover from a cyberattack?

It varies widely. Straightforward incidents can be resolved within a week, as in our Enviroscope case study. More complex breaches, especially those involving customer data, can take months.

What’s the single best way to reduce the cost of a cyberattack?

Catch it early. Breaches identified and contained quickly cost significantly less than those that go unnoticed for months. Regular monitoring, staff training and a tested response plan make the biggest difference.

The Bottom Line

The cost of a cyberattack isn’t just the ransom note or the IT invoice. It’s the days of lost productivity, the clients who don’t come back, and the trust that takes years to rebuild.

The businesses that come through a breach in the best shape are usually the ones that prepared before it happened, not after.

If you’re not sure where your business stands, a security assessment is the fastest way to find out. Our team can show you exactly where the gaps are, and what to do about them, before they turn into a very expensive Tuesday.

Get in touch with Sentry Cyber to book a no-obligation chat about your business’s cyber security.