#Cybersécurité

How do you calculate the cost of a cyberattack ?

Article : Le coût d'une cyberattaque

Cyber risk remains a major concern for European companies. According to the latest report from ENISA, the European Union Agency for Cybersecurity, 55% of organizations fear ransomware above all else.

This concern, stemming from the fear of becoming the next victim, does not always translate into the implementation of appropriate preventive measures, however. This disconnect exposes organizations to significant financial and operational consequences.

Intangible and often invisible, a security breach can lead to consequences such as extortion, business disruption, and loss of revenue, as well as causing lasting damage to a company’s reputation.

In this context, how can we assess the true cost of a cyber incident? What direct and indirect consequences must be taken into account?

To learn more, our experts Luc Cottin, Chief Executive Officer (CEO) of Rsecure, and Matthieu Jungers, our Chief Information Security Officer (CISO), provide insights in this article.

Any company can be the target of cyberattacks

Statistics from various European countries show that no type of organization is spared. Small and medium-sized enterprises, large corporations, and associations—whether in the private or public sectors—can all be targeted by cyberattacks.

However, the level of exposure to threats depends less on the size of the organization than on its digital environment, the data it holds, and its ability to detect an intrusion and then respond in the event of an incident.

Cybercriminals thus favor attacks where the cost of preparation and execution is lower than the expected gains. Their choice is based not only on the company’s profile but also on the level of difficulty involved in accessing its digital assets and exploiting its vulnerabilities.

The higher a company’s level of protection, the greater the cost and complexity of the attack, which may lead cyberattackers to choose a different target.

Cybersecurity maturity varies depending on company size and industry

In Luxembourg, the level of preparedness for cyber risks remains highly variable. It depends on the resources available, as well as on the industry sector and the regulatory obligations to which the organization is subject.

Regulated professions, particularly in the financial sector, operate within a framework that requires them to further strengthen their IT security. For example, since January 17, 2025, the European Regulation on Digital Operational Resilience in the Financial Sector (DORA) has strengthened requirements regarding digital risk management, incident reporting, and oversight of technology providers.

Large corporations and the most advanced companies generally have an in-house IT team and a dedicated cybersecurity budget. This structure enables them to better anticipate risks and implement measures to prevent, detect, and respond to incidents.

The situation is often different in smaller organizations. Cybersecurity spending competes with other investments necessary for the company’s operations. As a result, a separate budget is not always allocated.

Protect your business with our experts !

For Matthieu Jungers, this trend is easy to explain: “Very small companies, with between five and ten employees, do not yet view cybersecurity as a priority. It is only when a company has between 100 and 150 employees that a more structured approach is generally adopted. ”

This difference in maturity reflects the ever-increasing regulatory pressure in Europe.

The European Directive on the Security of Network and Information Systems (NIS 2), to be transposed in Luxembourg in 2026, requires affected organizations to strengthen their risk management and incident reporting procedures. However, its application varies depending on the sector, the size of the company, and the nature of its activities.

The General Data Protection Regulation (GDPR) also requires organizations to protect the personal data they process. Failure to comply with these obligations can result in financial penalties, but compliance is not limited to this issue alone. It also helps to better define responsibilities, internal procedures, and the measures to be taken when an incident occurs.

For small businesses, budget constraints remain a reality. However, this does not make them any less vulnerable. On the contrary, more limited resources can slow down the detection of an attack, complicate business recovery, and increase the operational consequences of the incident.

An opportunistic attack can lead to a major incident

Many cybersecurity incidents do not result from an attack targeting a specific company. On the contrary, cybercriminals often launch large-scale automated attacks without knowing in advance which organizations will be compromised.

This method, sometimes referred to as “spray and pray,” relies on volume. Since the cost of launching the malicious campaign remains low, just a few successful attempts are enough to make the operation profitable for the criminals. Companies are therefore compromised primarily when they present an exploitable entry point, regardless of their revenue or industry.

“For small and medium-sized businesses, attacks are often opportunistic. Cybercriminals launch large-scale campaigns, and when an attempt is successful, they continue their intrusion,” notes Matthieu Jungers.

The theft of credentials is one such entry point.

The Rsecure teams were recently contacted following a phishing campaign. “A Microsoft 365 account was compromised. After obtaining an employee’s login credentials, the cybercriminal accessed the employee’s work email and then the SharePoint files that the account was authorized to access.”

A Microsoft 365 subscription alone is not enough to protect an organization. The security level of online collaboration solutions depends on the configuration options enabled, access rights management, and access hardening—for example, by enabling multi-factor authentication (MFA).

Thus, the cost of a cyberattack does not depend on its complexity, but on its impact on the company’s operations. The compromise of a single user account can allow a cybercriminal to expand their access to the company’s resources. A more in-depth analysis of the infrastructure will then be necessary to identify the attacker’s actions, re-secure IT systems, and restore compromised data and resources. These complex actions can prolong business disruptions.

The numerous financial consequences of a cyberattack

The financial consequences of a cyberattack include not only direct, short-term expenses but also indirect costs in the medium to long term.

Direct expenses refer to the resources used to contain the incident, restore backed-up data, and bring the information system back online. These include, in particular, services provided by external vendors and the solutions and tools used during forensic investigations.

Indirect losses encompass various types of hidden costs and expenses. The most obvious are the impact on revenue and the loss of productivity. But damage to reputation also results in lost revenue, leading to the loss of customers and missed business opportunities. Hiring specialists is also costly. Lawyers are often called upon to handle litigation, regulatory obligations, and certain administrative procedures. Finally, crisis management can take a toll on team morale and leave teams vulnerable.

All of these impacts must be taken into account when calculating the cost of a cyberattack.

Teams that remained on the job throughout the crisis

Managing a major IT incident involves three key areas, as explained by Matthieu Jungers, Chief Information Security Officer (CISO) at Rsecure: “Crisis management centers on data and service recovery, analyzing the attack, as well as managing legal obligations, communications, and notifications. ”

Technical teams restore backups, servers, and applications. At the same time, incident response experts reconstruct the sequence of events leading to the attack, while governance teams prepare the necessary notifications and communications, particularly in the event of a personal data breach.

This intense mobilization of employees and service providers over a short period of time results in a direct cost to the company, which must compensate for this additional and unanticipated work.

Carried out urgently and under pressure, these actions can also undermine team stability. This “human cost” has tangible effects, although it is more difficult to quantify.

Do you have a question about protecting your business ?

A cost that depends on the scope of the incident

A cyberattack can sometimes go undetected for days, or even weeks. Post-incident investigation teams will then need to examine a broader range of accounts, files, workstations, and applications to determine the attacker’s actual progress.

For a medium-sized IT environment, “the investigation requires nearly five person-days of analysis, plus one or two person-days dedicated to notifications,” explains Matthieu Jungers. “On a larger scale, such as that of a mid-sized company or a large enterprise, this work will keep teams busy for several weeks.”

The quality of event logs also plays a role in the duration of investigations. These logs track connections, access attempts, and actions performed within the information system. When they are incomplete, altered, or deleted, experts have fewer clues to understand and contain the attack.

Following the incident, expenses related to remediation

Data recovery allows operations to resume, but it does not mark the end of crisis management. After a cyberattack, the company must still fix the vulnerabilities identified and exploited by the attacker, remove any persistent access points (backdoors) the attacker may have installed within the internal network, and strengthen its IT security measures.

If forensic analyses of the compromised equipment and the company’s IT environment fail to secure the system, it may be necessary to start from scratch. In this scenario, rebuilding the information system becomes the primary expense associated with the cyberattack.

Even in the case of a less severe incident, affected companies should implement a process of continuous improvement. That is why Rsecure supports its clients in sustainably strengthening their cybersecurity posture.

Based on the vulnerabilities identified during investigations, our experts can help strengthen user authentication (deployment of MFA, improved password management), review your security configurations, and recommend the cybersecurity solutions best suited to your needs and budget.

Our outsourced CISOs can strengthen your technical teams in these various areas. They monitor the status of your cybersecurity over time, oversee remediation efforts, and, if necessary, offer training tailored to your employees’ roles.

In addition to direct costs, there are long-term losses

Beyond remediation costs, the replacement of equipment, or the need to hire experts, a cyberattack results in a variety of hidden losses and costs.

During the crisis, executives, managers, and technical teams devote a significant portion of their time to coordinating responses and organizing the recovery. “Meanwhile, the company diverts some of its attention away from its core business,” explains Luc Cottin.

During this period, productivity declines, and the processing of orders, invoices, and requests slows considerably. This disruption further erodes trust, especially since customers are often collateral victims of the attack—whether their data is compromised or their business is affected by the ongoing incident. Legal fees are then to be expected for handling litigation and claims.

Finally, the cost of cyber insurance is often reassessed after the incident. The insurer may request an audit and an investigation report before applying a premium surcharge or increasing deductibles.

Rsecure offers you the opportunity to estimate all of these losses using the following calculation :

Cost of the incident = days of downtime × (daily operating loss + salaries and payroll expenses) + equipment costs + expert consultation fees + any fines and penalties

Finally, the impact of crisis management on the teams involved should not be underestimated. Although difficult to quantify, this impact is very real, and it is not uncommon to see higher employee turnover in the months and years following a cyberattack. “Some employees make it clear that they are not prepared to go through another crisis of this magnitude,” notes Matthieu Jungers.

It takes time to return to a stable situation

After a major cyberattack, business operations often resume in a degraded state. Technical teams gradually restore the company’s networks, servers, work environments, and business applications.

The duration of the recovery depends on several factors, including the volume of data to be restored, the difficulty of removing traces left by the attacker, and the effort required to patch the exploited vulnerabilities. When certain compromised servers must be completely rebuilt, the timeline is extended even further.

“Some measures can be implemented quickly, while others take more than a year to become fully operational,” explains Luc Cottin.

Services identified as critical, because they are essential to the company’s operations, are restored as a priority. However, returning to a stable state can take between eighteen months and two years.

Assess and manage risks before a cyberattack occurs

Cyber risk management begins, above all, with mastering IT tools. Before investing in new solutions, we recommend that our clients assess their level of cybersecurity maturity and take stock of the resources and processes at their disposal.

At Rsecure, we structure this approach using the “HOP” method—which stands for People, Tools, and Processes. We believe it is essential to address these three dimensions in order to effectively reduce the impact of a cyberattack within an organization.

Employee training, the deployment of appropriate cybersecurity tools, and the implementation of clear, well-managed processes are therefore at the heart of our IT risk management strategy.

Train employees

The human aspect of the HOP method aims to equip employees with the knowledge needed to recognize an attempted attack and know how to respond to it. Cybercriminals routinely exploit moments of inattention, a sense of urgency, or the element of surprise to get people to comply with an unusual request.

In the face of these manipulation techniques, the training aims to instill the right habits of vigilance and best practices for managing credentials and passwords. When in doubt, the key is to stop what you’re doing and quickly report the incident to the team or the IT service provider.

As Luc Cottin explains: “Raising employee awareness is the first building block we focus on when working with our clients. People need to learn how to better detect attacks and know how to respond. You shouldn’t just shut down your computer and bury your head in the sand. You need to talk about it and communicate.”

Deploy the Right Tools

The second pillar of our approach is based on implementing protection, detection, and remediation measures. Rsecure recommends starting with a comprehensive mapping of the IT environment to identify vulnerabilities within the information system.

This inventory will serve as the basis for assessing the actual impact of risks on business operations. This analysis is necessary to select tools that are appropriate for the company’s situation and budget.

“You need to ensure you have the minimum required for your infrastructure, including outsourced and tested backups, equipment protected by antivirus software or EDR, and properly configured authentication,” explains Matthieu Jungers.

Using a continuous monitoring service, such as Rsecure’s SOC, makes it possible to detect and neutralize a cyberattack from the very earliest stages of the intrusion.

Matthieu Jungers highlights the value of this early intervention. “The SOC allows us to respond more quickly when a threat is suspected and to block an attack immediately before it has a significant impact on the infrastructure. ”

Rsecure offers this service in two packages: R-SOC Tranquility for SMBs looking to secure their workstations and Microsoft 365 environment, and R-SOC for organizations with more extensive infrastructures and advanced monitoring needs.

Standardize the incident response process

Incident response begins long before an incident occurs. Rsecure recommends formalizing a crisis management plan that clearly defines the roles and responsibilities assigned to each individual and department.

This document must clearly list the priority actions to be taken in the event of a cyberattack, as well as the contacts to reach in an emergency.

“We had a case where a client couldn’t find the right number to call,” explains Matthieu Jungers. “He wasted a precious half-hour trying to reach his service provider, when the issue could have been resolved in five minutes if the correct contact information had been shared with everyone internally.”

Rsecure helps companies detect cyberattacks and respond to incidents.

Our teams combine expertise in governance, incident response, and continuous detection of cyberattacks through our SOC.

We work to identify compliance gaps, detect abnormal activity and cyberattacks, and test your company’s defenses.

By combining these three areas of expertise, Rsecure helps you limit the impact of a cyberattack and significantly accelerate your business recovery.

Would you like to assess your level of exposure to cyber threats or prepare your company to manage a cyberattack?

Contact us to schedule an initial consultation with our experts.

How can we help you?

Fill in this form and we will get back to you as soon as possible.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.