What a Cybersecurity Incident Actually Costs a Milwaukee Small Business
What a Cybersecurity Incident Actually Costs a Milwaukee Small Business
The ransom is the small number. What comes after — the downtime, the client calls, the legal work, the insurance negotiation — is where the real cost lives. Here is what a $254,000 incident actually looks like, hour by hour, day by day, all the way through settlement.
Most small business owners we talk to have a mental picture of what a cyberattack looks like. It is fuzzy, dramatic, and involves someone in a hoodie. The reality is almost boring by comparison — a real event unfolds slowly, mostly quietly, and the biggest cost is not the ransom. It is everything the business could not do for the next three and a half weeks.
The story that follows is not a specific real client — that would violate confidentiality. It is a composite drawn from public breach disclosures, the FBI’s Internet Crime Report, IBM’s 2025 Cost of a Data Breach Report, Verizon’s Data Breach Investigations Report, and the specific patterns we see in the Milwaukee area. Every dollar amount is grounded in real 2025 and 2026 data. Every timeline decision reflects what actually happens in incidents like this one.
The composite: a 30-person professional services firm in the greater Milwaukee area — think small law practice, insurance office, medical group, engineering firm. Annual revenue around $6 million. Uses Microsoft 365. Has antivirus. Has a backup vendor. Believes they are protected. Then, one Tuesday morning, they are not.
What the Research Actually Shows About Small Business Incidents
Those numbers matter because they change the conversation from “should we invest in security” to “what does it cost us if we don’t.” IBM’s 2025 report puts the U.S. average data breach cost at $10.22 million across all business sizes — small businesses fall well below that number, but the proportional impact is what makes them close their doors. A $254,000 hit to a $6 million revenue business is not just an expense. It is an existential event.
Here is how the 24 days unfold.
Hour by Hour, Day by Day
The phishing email arrives
Cost so far: $0A junior staff member opens an email that appears to come from a known vendor. The subject line references an invoice the company actually receives every month. The email language is professional, natural, and free of the typos that used to make phishing easy to spot — because it was written by AI. The attachment is a PDF. Opening it triggers a script that installs a small, quiet loader on the workstation. No alarm. No warning. The staff member goes back to work.
Phishing is now the initial access vector in 16 percent of all breaches according to IBM’s 2025 report, and 33.8 percent of breaches specifically targeting small businesses. AI-generated phishing achieves open rates of 54 to 78 percent, compared to about 12 percent for the older, sloppier attempts.
The attacker begins mapping the network
Cost so far: $0Nobody knows anything is wrong. The loader has phoned home and given attackers remote access to the workstation. For the next three hours, the attacker moves quietly through the network — reading the file server structure, identifying who has admin credentials, locating the backup system, and finding the wire transfer instructions and client billing records. They set up silent forwarding rules on the compromised mailbox so every incoming email continues to copy to them, even if the password is later changed.
The average small business does not detect an intrusion at this stage. Detection at Hour 4 requires endpoint detection and response (EDR), which is included in Microsoft 365 Business Premium but rarely turned on. We wrote more about that in our earlier article on what you’re paying for in Microsoft 365 that you’re not using.
The ransomware deploys
Cost so far: $0 — and about to changeThe office is empty. The cleaning crew has come and gone. At 8:47 PM exactly — 12 hours after the initial email opened — the attacker triggers the ransomware payload. Every file on every workstation and every server the attacker has reached is encrypted. Just before the encryption runs, the attacker exfiltrates roughly 40 gigabytes of client files, financial records, and email archives. The backups the company thought were protecting them are targeted too — 96 percent of ransomware attacks now hit backup locations, per VikingCloud research.
By 9:15 PM, screens across the office would display a ransom note if anyone were there to see it. The demand: $85,000 in cryptocurrency within 72 hours, or the exfiltrated data goes public. It stays undiscovered until morning.
The owner finds out
Cost this day: ~$18,000The first person in the office at 7:15 AM cannot log in. Neither can anyone else. By 8:30, the owner has been called. By 9:00, everyone has been sent home. The IT vendor is on the phone and does not know what to do. By noon, an incident response firm has been engaged at emergency rates — typically $400 to $800 per hour, retainer required upfront. By end of day, cyber insurance has been notified, a law firm has been engaged, and forensic imaging has begun on the encrypted machines.
Day one costs: incident response retainer ($10,000), initial legal consultation ($3,500), lost productivity across 30 employees for a full day ($4,500 in fully loaded labor cost, roughly). The company has not yet decided whether to pay the ransom.
The lawyer explains the notification rules
Cost this stage: ~$22,000Wisconsin has a data breach notification law. So do most of the other states where the company has clients. If any exfiltrated data included personally identifiable information — names paired with account numbers, health information, or financial data — the company is legally required to notify affected individuals, usually within 30 to 60 days depending on the state and the type of data. The forensic team is still working to determine what was actually taken.
Legal fees for breach counsel typically run $15,000 to $50,000 for an incident of this size, depending on complexity. The company also engages a notification vendor to handle the outreach to affected clients — that runs $3 to $8 per notified individual, plus credit monitoring services offered to affected clients at $10 to $15 per person per year. For a firm with 800 client records, notification and monitoring alone approaches $15,000 to $20,000.
Some systems come back. Some do not.
Cost this stage: ~$45,000The incident response team confirms that the primary backup was compromised, but a secondary backup at a different vendor was air-gapped and survived. The most recent clean restore point is nine days old. The company can either restore from that point and lose nine days of work, or attempt to pay the ransom and hope for a working decryption key — which even paying customers only receive about 60 percent of the time, per Sophos research. They choose restoration.
Rebuilding takes six days. Each workstation and server has to be wiped, reimaged, patched, and rejoined to the network. The incident response team charges roughly $250 per hour for restoration work, and the process takes approximately 180 person-hours across the environment. Meanwhile, the business is running at maybe 30 percent capacity — email works again by day 5, file access returns by day 7, the accounting system comes back on day 8.
The business is back — mostly
Cost this stage: ~$95,000 in lost revenue and productivityTwenty-four days is the median downtime for a small business ransomware event, per 2025 data. In this case, day 24 is when the accounting system, client portal, secure file exchange, and remote access are all functional again. Some clients have moved to other providers during the disruption. Some client trust has been shaken and will need months of rebuilding. Employee morale has taken a real hit — several team members quietly began interviewing during the outage.
Lost revenue during the incident, for a $6 million-per-year firm, is a straight function of billing days. Twenty-four days of interrupted operations at reduced capacity translates to roughly $95,000 in lost billings, based on partial recovery through the second half of the incident. Some of that comes back in later months. Some does not.
The claim closes and the next renewal arrives
Cost this stage: ~$74,000 net after insuranceCyber insurance covers a portion of the incident cost — typically 60 to 80 percent of documented direct expenses, minus deductible, for policies with proper first-party coverage. In this scenario, the policy has a $25,000 deductible and covers 70 percent of covered costs above that. The insurer pays out roughly $110,000 after the deductible against roughly $180,000 in documented direct costs. Uncovered items include the reputational impact, the lost future business, and any settlement with affected clients who filed complaints.
The renewal notice arrives at day 90 too. Premium for the next year is up 40 percent. Coverage limits have been reduced. Deductible has been raised to $50,000. The insurer requires MFA, EDR, and monthly backup testing as conditions of continued coverage. All of which the company had never fully implemented before the incident.
The ransom is $85,000. The incident is $254,000. The insurance covers $110,000. The business absorbs the rest, along with 24 days of downtime, several lost clients, and a renewal premium 40 percent higher than last year.The full picture, in one paragraph
Where the $254,000 Actually Went
Notice what is not on that list. The lost clients who quietly moved to a competitor during the outage. The team members who took new jobs. The reputation impact on new business development for the next 12 to 18 months. Those costs are real, hard to quantify, and often larger than the direct expenses above. For a firm that closes within six months of an incident — which is 60 percent of small business victims — the total cost is functionally the value of the entire business.
The cyber insurance market has hardened significantly since 2022. Carriers now routinely require multi-factor authentication on all accounts, endpoint detection and response deployed and monitored, tested backups on a documented cadence, and often an annual security assessment. If your renewal is coming up and you have not been asked these questions yet, expect them soon. Businesses that cannot demonstrate these controls are either denied coverage or offered dramatically reduced coverage at higher premiums — sometimes 100 percent higher than the previous year.
The Controls That Stop Almost All Of This
Every stage of the incident above had a specific control that would have caught it, contained it, or made recovery straightforward. None of them are expensive. Most of them are already included in tools the company was already paying for. The reason they were not in place is the same reason we see in most of the incidents we respond to: nobody had ever sat down and configured them properly.
Multi-factor authentication on every email account would have prevented the attacker from maintaining persistent access after the initial compromise. Cost to implement: an afternoon of configuration. Prevention rate against credential-based attacks: greater than 99 percent per Microsoft’s own data.
Endpoint detection and response — the Defender for Business that ships with Microsoft 365 Business Premium — would have flagged the initial loader install within minutes. Cost to implement: included in Business Premium licenses most professional service firms already have.
Tested, air-gapped backups on a documented restoration schedule would have made the ransomware demand irrelevant. The 3-2-1 backup rule (three copies, two media types, one off-site and offline) is not new advice, but the “tested” part is what most SMBs skip. A backup that has never been restored is not a backup. It is a file.
Phishing simulation and awareness training quarterly for staff. Not a one-time video during onboarding. Real, repeated exposure to safe simulated phishing so staff learn what to look for and, more importantly, learn what to do when they think they clicked something they shouldn’t have.
An incident response plan. A written, tested document that says: if this happens, we call these people in this order, we notify these regulators within these deadlines, we say these things to clients. Sixty-six percent of small businesses do not have one. Creating one saves an average of $232,000 in eventual incident cost per IBM’s research. It costs nothing but a few hours of thinking.
Comprehensive small business cybersecurity costs $5,000 to $15,000 per year for a business the size of the one in this article. A single incident like the one described costs $254,000 direct plus insurance and reputational fallout. Prevention costs 50 to 60 times less than recovery. That is not a marketing statistic. That is the actual math on almost every incident we respond to.
Who You Want on the Phone at Hour 12
Incident response is a moment when the relationship with your IT provider matters more than at any other time. The provider who set up your systems, knows your environment, and can be at your building in an hour is a fundamentally different asset than a national call center learning your setup for the first time during the worst day of your business’s history. RedBird has been supporting Milwaukee-area businesses for over 20 years. Every technician is a direct RedBird employee — not a subcontractor dispatched from a staffing pool. When something like this happens, the same people who know your environment show up.
The eight questions we walked through in our earlier article on how to choose a managed IT provider in Milwaukee matter most during an incident. Response time is not marketing — it is a legally required commitment in your service agreement, and it is the difference between containment and full compromise. Backup testing is not a checkbox — it is what determines whether restoration takes eight days or eight weeks. Ownership of documentation is not fine print — it is what lets you actually recover if the provider is not available.
If your last security review was more than a year ago, or if reading through this article surfaced controls you cannot confidently confirm are in place, that is worth a conversation. Not a sales pitch. A straight look at where your setup stands right now, what the exposure actually is, and what closing it would cost — in real numbers, not scare tactics.
Find Out Where Your Exposure Actually Is
Free security assessment. We review your current setup, identify the specific gaps, and give you an honest recommendation — with no obligation and no sales pressure.
Schedule Your Free Consultation Or call us directly: (262) 475-2615 · Hablamos Español