Back to Blog
Cybersecurity Business Continuity Risk Australian Business

What a $56,600 Breach Actually Buys You

By Ash Ganda | 29 September 2026 | 8 min read

The Australian Signals Directorate’s most recent annual threat report puts the average self-reported cost of cybercrime to a small business at $56,600 per incident, up 14% on the year before. Across all business sizes the average is $80,850, up 50%.

Two things about that number before anything else.

It is self-reported, which means it reflects what businesses that reported an incident said it cost them. And it is an ASD cybercrime figure, not a breach-notification figure — it is a different measurement from the OAIC’s notifiable data breach statistics, and the two get conflated constantly.

With that said, the useful question is not whether $56,600 is the right number for you. It is what a figure of that size is actually made of, because the composition tells you which parts you can remove in advance and which you cannot.

Where the money goes

Very little of it is money taken on the day.

Downtime. The largest component for most small businesses, and the one least likely to be estimated correctly beforehand. Not “the server was down” — staff unable to work, jobs not quoted, orders not taken, appointments not booked. A trades business with six people off tools for three days has spent a substantial share of that average before anyone has touched a keyboard.

Finding out what happened. This is the cost people are most surprised by. Establishing what was accessed is specialist work charged at specialist rates, and it is not optional if you have any obligation to notify — you cannot tell affected people what to do without knowing which information was involved.

Rebuild and clean-up. Rebuilding machines, resetting credentials, restoring data, re-establishing integrations. Mostly labour.

Notification and legal. If the breach is notifiable, preparing the statement, taking advice on whether it is notifiable at all, and handling what comes back.

Customers who leave. Rarely itemised and genuinely material, particularly for businesses holding sensitive information for other people.

Money actually taken. Usually the smallest line, and usually the only one anyone thinks about in advance.

★ Insight ───────────────────────────────────── The composition explains why the average is so much higher than most owners expect. People price a cyber incident as a theft — a number with an upper bound they can imagine. It is actually an outage plus an investigation, and both of those are priced in days of other people’s time. An incident that steals nothing at all can still cost most of that $56,600, which is why “we don’t hold anything worth stealing” is not the protection it sounds like. ─────────────────────────────────────────────────

Which parts you can remove before anything happens

Sort the list above by how much of it is decided in advance, and a clear pattern appears.

Downtime is almost entirely determined by your backups — specifically, by whether you have ever restored one. Not whether backups run. Whether a restore has been performed, timed, and confirmed to produce working data. A business that has rehearsed a restore knows its outage in hours. One that has not, does not know, and will find out during the incident.

Investigation cost is determined by your logs. If sign-in and file-access history exists and covers a useful period, scoping is a day. If it does not exist, or has already rolled off, the investigation becomes an exercise in inference and the bill grows accordingly. Most cloud platforms retain this by default, for a period that depends on your licence tier — and lower tiers often retain less than the 30 days you may have to assess within.

Rebuild cost is determined by documentation. Which systems exist, who has access, what is connected to what. A rebuild against a written list is work. A rebuild against memory is archaeology.

Notification cost is determined by knowing where personal information lives. A list of which systems hold data about other people turns a legal question into a factual one.

Four things, none of which are security products. All four are records that either exist before the incident or do not.

The three controls that change the odds

Reducing the cost of an incident is different from reducing the chance of one. Briefly, on the second, because the reported incidents keep describing the same three gaps:

Multi-factor authentication on email first, then anything holding customer data. Reported incidents attributed to attack are overwhelmingly reached through accounts rather than exotic exploits.

Patching the things that face the internet. Not everything. The router, the VPN, the remote-access tool, the website.

Restricting who can reach what. Most small businesses give everyone access to everything because it is easier, which means one compromised account is a compromised business.

Why the average is rising, and what that does not mean

The small-business figure is up 14%. The all-business average is up 50%, to $80,850.

Two readings of that are tempting and neither is supported by the figures alone.

“Attacks are getting more sophisticated.” Possibly, but a rising average cost per report can equally reflect a change in who reports. The ASD notes that large business accounts for a small share of reports, which makes that segment’s average susceptible to a handful of very expensive outliers. An average moving because of reporting composition looks identical to one moving because incidents got worse.

“This is what it will cost us.” It is a mean across self-reported incidents of wildly differing severity. Most small-business incidents cost far less than $56,600; a few cost very much more. Planning to the mean is planning to a number almost nobody actually experiences.

What the trend does support is narrower and more useful: the cost of an incident is not falling, and the gap between a prepared business and an unprepared one is widening, because the expensive components — downtime and investigation — are precisely the ones that preparation removes.

The insurance question

Worth a paragraph because it comes up immediately after the number does.

Cyber insurance covers some of the list above — usually incident response, notification costs, and business interruption after a waiting period. It does not remove the underlying exposure, and two things about it surprise people.

Policies increasingly require specific controls to be in place, and multi-factor authentication is the most common. A claim on a policy where the required control was not actually enabled is a difficult conversation at a bad time.

And the waiting period matters more than the limit for a small business. A policy with a 12-hour or 24-hour business-interruption waiting period is a different product from one with a 72-hour period, and most small-business outages resolve inside that window — meaning the cover that would have paid is the cover you did not read.

The number worth calculating instead

Rather than debating whether $56,600 applies to you, work out your own downtime figure. It takes ten minutes and it is the one number that makes this conversation concrete.

Take your weekly revenue. Divide by five. Multiply by three.

That is roughly what three days of not operating costs you, before a single specialist invoice. For most small businesses that calculation alone lands somewhere uncomfortably close to the average, and it arrives without anyone having stolen anything.

Then ask the only question that changes it: when did we last restore a backup and confirm it worked?

If the answer is “the backups run every night”, that is not an answer to the question asked.

Source: ASD Annual Cyber Threat Report 2024-25. Figures are self-reported averages and are not a prediction for any individual business.


Cloud Geeks provides cybersecurity, backup and managed IT for Australian small businesses. Websites come from Cosmos Web Tech, apps from Awesome Apps, and the group is Ganda Tech Services.

Ready to upgrade your IT and cloud setup?

Let's talk about cloud, infrastructure, or cybersecurity. We help Sydney SMBs cut hosting costs, harden their stack, and stop firefighting.

Bella Vista, Sydney