跳到主体内容

Kaspersky Lab survey shows real business loss from cyberattacks now $861K per security incident

2016年9月13日

On average a single cybersecurity incident now costs large businesses $861,000. Meanwhile, small and medium businesses (SMB) end up paying $86,500. Most alarmingly, the cost of recovery significantly increases depending on the time of discovery.

On average a single cybersecurity incident now costs large businesses $861,000. Meanwhile, small and medium businesses (SMB) end up paying $86,500. Most alarmingly, the cost of recovery significantly increases depending on the time of discovery. SMBs tend to pay 44% more to recover from an attack discovered a week or more after the initial breach, compared to attacks spotted within one day. Enterprises pay a 27% premium in the same circumstances. These are the main findings of Kaspersky Lab’s report “Measuring the Financial Impact of IT Security on Businesses” based on the 2016 Corporate IT Security Risks survey1.

Budget increases address complexity

In the 2016 survey, Kaspersky Lab for the first time compared an organization’s security budget to losses incurred from serious incidents. Overall, businesses expect IT Security budgets to grow at least 14% over the next three years, due to the increased complexity of IT infrastructure. A typical small businesses currently spends 18% of their total IT budget on security, whereas enterprises allocate 21%. The research shows a significant disparity between businesses of differing sizes, with annual security budget varying from just $1,000 for very small businesses to more than one million US dollars for large companies.

Cost of recovery: employee overtime and more

To estimate the total cost of recovery, Kaspersky Lab and B2B International asked businesses to report their losses from the most serious security incident in different categories. Although the most frequent cost is for additional staff wages, businesses reported significant spending due to lost business opportunities, improvement in IT security, employing external specialists and hiring new staff. Enterprises spend $79K on training and $85K on requesting help from external experts –19% of the total loss.

Talking about ROI

“Based on our worldwide survey, the average IT Security budget is ‘worth’ just 2.5 cyberattacks once all direct and indirect losses are taking into account. With thousands of threats attacking corporate world every day, an efficient cybersecurity definitely pays off. Businesses understand the threat clearly; 59% of SMBs and 62% of enterprises say they will improve their security regardless of an ability to measure return,” comments Vladimir Zapolyansky, Head of SMB Marketing, Kaspersky Lab.
“However, the survey proves that reaction time post-breach has a direct impact on financial losses. This is something that cannot be remedied via budget increases. It requires talent, intelligence and an agile attitude towards protecting one’s business. As a security vendor, our goal is to provide tools and intelligence for businesses of all sizes, keeping in mind the difference in ability to allocate security budgets,” adds Zapolyansky.
The full report titled “Measuring the Financial Impact of IT Security on Businesses” is available at Kaspersky Lab’s website here.  


1 Corporate IT Security Risks is the annual survey conducted by Kaspersky Lab in cooperation with B2B International. In 2016 we have asked more than 4000 representatives of small, medium and large businesses from 25 countries on their views on IT Security and real incidents they had to deal with.

Kaspersky Lab survey shows real business loss from cyberattacks now $861K per security incident

On average a single cybersecurity incident now costs large businesses $861,000. Meanwhile, small and medium businesses (SMB) end up paying $86,500. Most alarmingly, the cost of recovery significantly increases depending on the time of discovery.
Kaspersky logo

关于卡巴斯基

卡巴斯基是一家成立于1997年的全球网络安全和数字隐私公司。卡巴斯基不断将深度威胁情报和安全技术转化成创新的安全解决方案和服务,为全球的企业、关键基础设施、政府和消费者提供安全保护。公司提供全面的安全产品组合,包括领先的端点保护解决方案以及多种针对性的安全解决方案和服务,以及用于应对复杂和不断变化的数字威胁的网络免疫解决方案。全球有超过4亿用户使用卡巴斯基技术保护自己,我们还帮助全球200,000家企业客户保护最重要的东西。要了解更多详情,请访问www.kaspersky.com.cn.

相关文章 企业新闻