When a Canadian small or mid-sized business gets hit by ransomware or a data breach, the sticker-shock number people quote — the ransom demand, or the forensics invoice — is almost never the real total. The true cost of a cyberattack is made up of two very different kinds of expense: direct costs that show up as actual invoices in the weeks after an incident, and indirect costs that bleed out over the following 12 to 24 months in the form of customers who quietly stop calling, insurance renewal quotes that jump, and RFPs your business no longer gets shortlisted for. Most owners plan for the first category and are blindsided by the second, which is usually larger.
This guide breaks down both halves of that bill in Canadian-dollar terms, using patterns IT Cares has observed across SMB clients, published incident-cost research, and the regulatory obligations that apply specifically in Canada under PIPEDA and Quebec's Law 25. It's written for the owner of a 10-, 40-, or 100-person business who wants an honest number to plan around — not an enterprise CISO with a seven-figure security budget.
Who wrote this guide
This article was written and reviewed by IT Cares certified technicians. We work with Canadian SMBs before, during, and after security incidents — deploying protection, and also cleaning up after the fact when a client calls us mid-attack. The dollar ranges here reflect real patterns we've seen, not vendor marketing numbers designed to sell you a bigger security budget than you need.
What "Cost of a Cyberattack" Actually Includes
Ask a small business owner what a cyberattack costs and most will say "the ransom" or "fixing the computers." That's understandable — those are the costs you see first, the ones with an actual invoice attached. But for an SMB, the ransom or the IT remediation bill is frequently the smallest piece of the total cost, not the largest.
A more complete way to think about it is as two separate budgets you're forced to spend, on two different timelines:
- Direct costs — the concrete, invoiced expenses that appear within days to weeks of an incident: ransom payments, forensic investigation fees, IT remediation, legal counsel, regulatory notification, and temporary staffing to keep the business running while systems are down.
- Indirect costs — the slower-moving, harder-to-invoice losses that unfold over the following months and years: customers who leave and don't come back, contracts and RFPs you no longer win, higher cyber insurance premiums (or losing insurability altogether), staff turnover from the stress of the incident, and the marketing spend needed to rebuild trust in the market.
For an SMB specifically, the balance between these two categories tends to skew harder toward indirect costs than most owners expect, precisely because small businesses depend disproportionately on relationships, referrals, and repeat business — the exact things a publicized breach damages most.
Why the True Cost Catches Most Owners Off Guard
There's a specific reason SMB owners consistently underestimate what an incident will cost, and it isn't naivety — it's a planning bias built into how invoices arrive. Direct costs land as concrete numbers with due dates: a forensics firm sends a bill, a law firm sends a bill, an insurer confirms a deductible. Those numbers are easy to plan around because they behave like every other business expense you've ever budgeted for. Indirect costs don't work that way. No one sends an invoice labelled "lost customer, month four" or "declined RFP, month nine." Those losses show up buried inside ordinary-looking revenue reports, months after the incident itself has been resolved and largely forgotten internally — which makes it genuinely difficult to connect cause and effect, even for an owner looking directly at the numbers.
This delay matters because it changes decision-making in the moment. A business owner staring at a $45,000 ransom demand is weighing that number against the cost of downtime this week — not against a customer relationship that quietly erodes over the following year. Every dollar figure in this guide is presented specifically to correct for that bias: not to replace the urgency of the direct costs, but to make sure the slower-moving, larger costs get weighed in the same decision.
Not sure where your business actually stands?
A security audit identifies the gaps that turn a phishing email into a six-figure incident — before it happens, not after.
Direct Costs: The Invoices That Arrive First
Ransom and extortion payments
For businesses hit by ransomware, the ransom demand is usually the first number anyone hears — and it's rarely the number actually paid. Attackers frequently set an initial demand knowing negotiation is expected, and Canadian SMBs that do end up paying commonly settle somewhere between $10,000 and $150,000 CAD, though demands against larger operations can run into the millions. Critically, paying the ransom does not guarantee recovery. A meaningful share of businesses that pay still don't receive a working decryption key, receive one that only partially works, or discover the attacker kept a copy of the stolen data regardless and demands a second payment not to leak it — a pattern known as double extortion that has become close to the industry norm rather than the exception. The Canadian Centre for Cyber Security explicitly advises against paying for exactly these reasons, alongside the fact that payment funds further criminal activity.
There's also a slower cost tied to the payment decision itself that's easy to miss: cryptocurrency has to be acquired, which for a business with no prior exposure to digital currency exchanges can take days and typically requires setting up new accounts under time pressure — days during which the business remains down and the daily downtime cost keeps accruing regardless of how quickly the ransom itself gets sourced.
Incident response and digital forensics fees
Before you can safely restore anything, someone needs to determine how the attacker got in, what they accessed, whether they're still inside your network, and what needs to be rebuilt versus simply cleaned. Professional incident response and forensics engagements for an SMB-scale breach typically run from $8,000 to $60,000 CAD, depending on how many systems are involved and whether the investigation needs to produce a formal report for insurers, regulators, or legal counsel. This is frequently a mandatory step for cyber insurance claims, not an optional add-on — most policies require a panel-approved forensics firm before they'll pay out.
The scope of a forensics engagement also tends to expand once investigators start looking, not shrink. A business that expects a quick confirmation of "yes, ransomware, here's the entry point" often ends up paying for a fuller investigation once the forensics team finds evidence the attacker had access for weeks before deploying the ransomware payload — which changes both the legal notification analysis and the total hours billed.
IT remediation and hardware replacement
Beyond forensics, someone has to actually rebuild: reimaging infected machines, restoring from backup, patching the vulnerability that let the attacker in, replacing hardware that's been compromised at a firmware level, and rebuilding servers from scratch in worse cases. For a small business this commonly runs $5,000 to $40,000 CAD; for a mid-sized business with more servers, more endpoints, and more complex infrastructure, $25,000 to $100,000+ CAD is realistic.
A detail that surprises many owners: remediation frequently costs more than simply restoring a working system, because "working again" and "actually secure" are different bars to clear. Rebuilding correctly means closing the vulnerability that let the attacker in in the first place — patching software, resetting every credential the attacker may have touched, and often replacing rather than simply reformatting hardware that could still contain a persistence mechanism. Skipping that step to save money is exactly how businesses end up hit a second time within the same year.
Legal fees
Legal counsel gets involved early in almost every serious incident — to advise on notification obligations, to review and negotiate with the insurer, to handle any ransom negotiation communications, and increasingly to manage exposure if a lawsuit from an affected customer or business partner follows. Legal fees for an SMB incident typically range from $5,000 for a straightforward, contained matter to $75,000+ CAD if litigation or a regulatory investigation follows.
Counsel experienced in breach response also plays a quieter but valuable role: managing communications so that internal incident notes and preliminary findings are covered appropriately, since poorly worded internal emails written in the panic of the first 48 hours have a way of resurfacing during a later regulatory review or lawsuit.
Regulatory notification costs
If personal information is involved, Canadian businesses have real legal obligations. Under PIPEDA (the federal law), any breach of security safeguards that creates a real risk of significant harm must be reported to the Office of the Privacy Commissioner of Canada and to affected individuals. In Quebec, Law 25 imposes similar but distinct obligations, including notification to the Commission d'accès à l'information (CAI) and a public incident register businesses must maintain. The practical costs — legal review of what happened, drafting notices, mailing or emailing affected individuals, setting up a dedicated phone line or web page for questions, and in more serious cases offering credit monitoring — commonly run from $3,000 for a small, contained incident to $50,000+ CAD for a breach affecting thousands of records.
Businesses operating in more than one province need to account for the fact that these obligations don't perfectly overlap — a Quebec business with customers in Ontario may need to satisfy both PIPEDA and Law 25 requirements simultaneously, on different timelines, with different regulators, which is exactly the kind of complexity that drives up legal review time.
Extortion negotiation and crisis communications
Many businesses that engage with an attacker do so through a specialized ransomware negotiation firm rather than directly, both to protect the business from negotiation mistakes and because insurers frequently require it. These services typically add $5,000 to $25,000 CAD on top of whatever ransom is ultimately paid. Separately, a crisis communications consultant to help manage customer, staff, and sometimes media messaging can add another $3,000 to $15,000 CAD, particularly for a business with any public profile.
Temporary staff and contractor costs
While systems are down, someone still has to answer phones, process orders manually, and keep the business functioning. Businesses frequently bring in temporary staff or pay existing staff overtime to manage manual workarounds during an outage, and separately need contract IT staff or a managed services provider to support the rebuild if internal IT capacity isn't sufficient — together commonly adding $2,000 to $20,000 CAD depending on downtime length.
Owners of businesses without an in-house IT department often underestimate this line item most of all, because it's easy to assume "our regular computer guy will just fix it" without accounting for the fact that incident response is a specialized skill set most general IT support providers don't practice regularly — meaning the rebuild may require a second, more specialized vendor on top of whoever normally handles day-to-day support.
Indirect Costs: The Bill That Arrives Later — and Is Usually Bigger
Customer churn and lost repeat business
This is frequently the single largest cost of a cyberattack for an SMB, and it's the one owners most consistently underestimate because it never arrives as a single invoice — it shows up as a slow decline in repeat orders and renewals over the following year. Based on published breach research and patterns IT Cares has observed across clients, a business that experiences a publicized breach or a lengthy, visible outage typically sees 10% to 40% customer churn within twelve months, with the exact figure depending heavily on how sensitive the exposed data was, how the business communicated during the incident, and how easily customers can switch to a competitor. A consumer-facing retailer with easy alternatives sits at the higher end of that range; a B2B service provider with contracts and switching costs sits at the lower end — but rarely at zero.
How a business communicates during the incident meaningfully changes where it lands in that range. Customers who are notified promptly, given specific and honest information, and offered a clear remediation step (a password reset, credit monitoring, a direct contact for questions) churn noticeably less than customers who find out about a breach from a news report or a competitor before hearing anything from the business itself. Silence, or a notification that reads as vague and legally hedged rather than genuinely informative, tends to push churn toward the higher end of the range.
Reputational damage and lost future contracts
Beyond existing customers leaving, a known breach affects your ability to win new business. Increasingly, mid-size and enterprise clients — and virtually all government contracts — include a vendor security questionnaire or require cyber insurance and specific controls as a condition of doing business. A recent, known incident can disqualify a bidder outright during procurement, or trigger enough additional scrutiny that a smaller competitor without that history wins instead. This effect is genuinely difficult to put a precise number on, but for B2B service providers, contractors, and professional firms, it's frequently the largest single indirect cost over a multi-year horizon.
This cost also compounds in a way direct costs don't: a lost contract this year is also lost referral business and lost renewal revenue in every subsequent year that client relationship would have continued, which is why the multi-year total for a professional services firm can end up dwarfing everything else on this list even though no single year's loss looks dramatic in isolation.
Employee time, morale, and turnover
Incidents consume enormous amounts of staff time — not just IT staff during the technical response, but leadership managing communications, customer service handling angry calls, and finance managing the cash flow disruption. Beyond the direct time cost, the stress of a major incident measurably affects morale, and it's common for businesses to see elevated turnover in the six to twelve months following a serious breach, particularly among staff who felt directly implicated (an employee who clicked a phishing link, for instance) or who bore the brunt of the crisis response. Replacing and retraining even one or two mid-level employees commonly costs $15,000 to $40,000 CAD each when you account for recruiting, onboarding, and lost productivity during the transition.
How leadership handles the employee who "caused" the incident matters more than owners often expect for staff morale broadly. A public blame culture in the aftermath of a phishing-triggered breach tends to make the rest of the team quieter about reporting suspicious emails going forward — the opposite of what a business actually needs after an incident — while a response focused on process rather than individual fault tends to preserve the reporting culture that catches the next attempt earlier.
Higher cyber insurance premiums — or losing insurability
Cyber insurance renewal after a claim rarely comes back at the same price. It's common for premiums to increase 25% to 100%+ at the next renewal following a paid claim, and insurers frequently impose new conditions — mandatory MFA, endpoint detection and response, specific backup requirements — as a condition of continued coverage. In more severe cases, particularly for a business in a higher-risk industry or one with a second incident, insurers decline to renew coverage at all, which itself becomes a business cost: many client contracts and lending agreements now require proof of active cyber insurance.
Insurers underwrite renewal pricing largely off the same signal a forensics report already generated: what specifically failed, and whether the business fixed it. A renewal application that can point to concrete remediation — MFA now enforced everywhere, a new backup architecture, a completed security audit — genuinely does soften the premium increase compared to a business that simply asks to renew "as before" without demonstrating anything changed.
Lost productivity during downtime
Separate from the temporary staffing costs above, there's a pure lost-output cost to downtime itself — revenue that simply doesn't happen while systems are down, projects that slip, and billable work that can't be delivered. For a services business billing by the hour or the project, a week of significant disruption can represent a direct hit to revenue on top of every other cost on this list, distinct from what it costs to fix the underlying problem.
Cost of rebuilding trust and marketing recovery
After the technical rebuild is done, many businesses spend meaningfully on rebuilding market confidence — updated security messaging on their website, a renewed push on customer testimonials and case studies, sometimes a formal PR effort to control the narrative, and in some cases discounted pricing or added service guarantees offered specifically to retain nervous customers. This is real spend that doesn't show up in any incident-response budget line but is a direct consequence of the breach.
For businesses that rely heavily on word of mouth and local reputation — professional services, healthcare-adjacent practices, and retail chief among them — this category can stretch on longer than any other cost on this list, simply because trust rebuilds on a slower timeline than a server does.
Direct vs. Indirect Costs at a Glance
| Cost Type | Examples | Typical Range (CAD) | When It Hits |
|---|---|---|---|
| Ransom / extortion | Ransom payment, negotiation fees, second-extortion demands | $10,000 – $150,000+ | Days 1–14 |
| Forensics / incident response | Root-cause investigation, insurer-mandated forensics report | $8,000 – $60,000 | Days 1–30 |
| IT remediation & hardware | Reimaging, rebuilding servers, replacing compromised hardware | $5,000 – $100,000+ | Weeks 1–6 |
| Legal fees | Notification advice, insurer negotiation, litigation defence | $5,000 – $75,000+ | Weeks 1–52 |
| Regulatory notification | PIPEDA/Law 25 notices, OPC/CAI reporting, credit monitoring | $3,000 – $50,000+ | Weeks 2–8 |
| Temporary staff / contractors | Overtime, manual workarounds, contract IT support | $2,000 – $20,000 | Weeks 1–4 |
| Customer churn | Lost repeat business, cancelled contracts, non-renewals | 10%–40% of affected revenue | Months 1–12 |
| Lost future contracts | Failed vendor security questionnaires, lost RFPs | Highly variable — often largest long-term cost | Months 3–36 |
| Higher insurance premiums | Renewal increase, new mandatory controls, non-renewal | +25%–100%+ at renewal | Months 6–18 |
| Staff turnover | Recruiting, onboarding, lost productivity replacing staff | $15,000 – $40,000 per employee | Months 3–18 |
Three Illustrative Canadian Scenarios
The following are composite scenarios built from patterns IT Cares has observed across SMB engagements — not real, individually identifiable clients — but the numbers and sequence of events reflect realistic outcomes for businesses of these sizes and industries.
Scenario 1: A 25-person Ontario manufacturing firm hit by ransomware
A mid-sized parts manufacturer near Kitchener had an employee open an infected attachment on a Friday afternoon. By Monday, production scheduling software, accounting, and file servers were all encrypted. The attacker demanded $80,000 USD in cryptocurrency. With no tested offline backup for the scheduling system, the company was down for 11 days — losing an estimated $6,000/day in production delays alone. After negotiation, they paid $45,000 CAD for a decryption key that worked on roughly 80% of encrypted files; the remainder had to be rebuilt manually from paper records and supplier re-sends. Total direct cost including forensics, remediation, and the ransom: roughly $140,000 CAD. Two long-standing customers, citing "supply reliability concerns," moved a portion of their orders to a competitor over the following six months — an estimated 15% revenue impact from that account relationship going forward.
Scenario 2: A 12-person Quebec accounting firm hit by business email compromise
An accounting firm in the Montreal area had a partner's email account compromised through a convincing phishing page. The attacker monitored the inbox for three weeks, then intercepted a legitimate client wire transfer instruction and redirected $95,000 CAD to a fraudulent account during a real estate closing. The firm's cyber insurance covered the majority of the loss after a deductible and a lengthy claims investigation, but the policy explicitly excluded coverage for the client's separate financial loss, leading to a difficult conversation and an eventual negotiated partial reimbursement to preserve the relationship. The firm also had to notify affected clients under Law 25 given the email exposure, adding roughly $8,000 CAD in legal and notification costs. The reputational cost proved harder to absorb than the financial one: in a business built entirely on trust with sensitive financial information, the firm lost two clients outright and spent the better part of a year rebuilding confidence with the rest.
Scenario 3: A 40-person BC retailer hit by a customer data breach
A multi-location retailer in the Lower Mainland discovered an unpatched e-commerce plugin had allowed attackers to access a database containing roughly 14,000 customer records, including names, addresses, and partial payment information. Forensics confirmed the exposure met the "real risk of significant harm" threshold under PIPEDA, triggering mandatory notification to the Office of the Privacy Commissioner and to all affected customers. Notification costs (legal review, mailing, a dedicated support line, and one year of credit monitoring offered to affected customers) totalled approximately $62,000 CAD. Roughly 22% of affected customers didn't make another purchase in the following year, a meaningfully larger effect on repeat business than the direct notification cost. At renewal, the retailer's cyber insurance premium increased by 60%, and the insurer required mandatory MFA and a web application firewall as a condition of continued coverage.
The pattern across all three scenarios
In every case, the direct, invoiced costs were significant — but the indirect costs (lost customers, a damaged relationship, a much higher insurance premium) ended up being comparable to or larger than the direct bill within twelve months. Budgeting only for "what the ransom might cost" consistently understates the real exposure.
What these three scenarios also share is a preventable root cause: an unpatched plugin, a phishing page convincing enough to fool an experienced professional, and a missing offline backup. None of these businesses were reckless or unusually careless by industry standards — they looked, on paper, like a typical Canadian SMB with a reasonably competent general IT setup. That's precisely the point: baseline security hygiene that would have cost a few thousand dollars a year would have either prevented the incident outright or dramatically shortened the recovery and reduced the indirect fallout in every one of these cases.
Is Your SMB Financially Exposed? Quick Self-Check
Work through this list honestly. Each unchecked box represents a real gap between what an incident would cost you and what you're currently prepared to absorb.
- ☐ Do you have a written, tested incident response plan, not just an informal understanding of "who to call"?
- ☐ Are your backups stored offline or immutable, so ransomware can't encrypt them along with everything else?
- ☐ Have you actually tested restoring from backup in the last six months, not just confirmed the backup job "ran successfully"?
- ☐ Do you have active cyber insurance, and have you read the ransomware and extortion clauses specifically, not just the coverage summary?
- ☐ Is multi-factor authentication enforced on email, remote access, and financial systems for every employee, no exceptions?
- ☐ Do you know exactly what personal information you hold on customers or employees, and where it's stored?
- ☐ Do you know your specific notification obligations under PIPEDA and, if you operate in Quebec, Law 25?
- ☐ Have you budgeted for indirect costs — customer churn, a higher insurance premium — not just the direct remediation bill?
- ☐ Does your business carry cash reserves or a credit line sufficient to cover several weeks of reduced revenue during a shutdown?
- ☐ Have your employees received phishing and social engineering awareness training in the last twelve months?
If you checked fewer than seven of these, your business is likely more financially exposed to a cyberattack than your current planning accounts for — worth a closer look before an incident forces the conversation.
What Should a Canadian SMB Budget for Cyber Resilience?
These are planning ranges, not quotes — actual cost depends on industry, data sensitivity, and existing infrastructure — but they're a reasonable starting point for budgeting conversations.
| Business Size | Prevention (per employee/year) | Cyber Insurance (annual) | Incident Response Retainer |
|---|---|---|---|
| Under 10 employees | $150 – $400 | $800 – $2,500 | $0 – $2,000 (often skipped at this size) |
| 10–50 employees | $250 – $600 | $2,000 – $8,000 | $2,000 – $6,000/year |
| 50–100 employees | $400 – $900 | $6,000 – $20,000+ | $5,000 – $15,000/year |
The math here is straightforward once you've seen the cost ranges above: spending even $500 per employee per year on prevention is dramatically cheaper than a single incident that costs $30,000 to $250,000 CAD once direct and indirect costs are combined. An incident response retainer in particular — a pre-negotiated agreement with a security firm to respond immediately rather than scrambling to find one during a live attack — is one of the highest-leverage line items on this list, since response speed correlates directly with downtime length, which correlates directly with cost.
It's worth being honest about how these budgets should shift over time rather than staying static. A business in its first year of taking security seriously should expect to spend closer to the top of these ranges, since it's typically starting from a gap-filled baseline — no MFA, no tested backup, no written incident response plan. Once those foundational gaps are closed, ongoing spend can often trend toward the middle or lower end of the range, since maintaining good posture costs less than building it from nothing. The mistake to avoid is treating any single year's spend as a one-time project rather than an ongoing line item, since new employees, new software, and new attacker techniques all continuously reopen gaps that were closed the year before.
Canadian Government Resources for SMB Cyber Resilience
Several Canadian government bodies offer free or subsidized support specifically aimed at small business, and they're underused relative to how genuinely useful they are.
- Business Development Bank of Canada (BDC) — offers cybersecurity advisory services and financing specifically for SMBs looking to invest in protection, including guidance on where limited security budgets have the most impact.
- Canadian Centre for Cyber Security (part of the Communications Security Establishment / ISED) — publishes free, practical guidance built specifically for small business, including baseline control recommendations and ransomware-specific advice. Their guidance is a genuinely useful starting checklist even before engaging a paid provider.
- Office of the Privacy Commissioner of Canada — the federal regulator for PIPEDA breach reporting obligations, with clear guidance on what constitutes a "real risk of significant harm" that triggers mandatory notification, and how to report a breach correctly.
If your business operates in Quebec, Law 25 imposes additional, distinct obligations beyond PIPEDA — our guide on Law 25 vs. PIPEDA for multi-province businesses breaks down exactly where the two frameworks differ and what that means for notification timelines and your incident register.
Want a straight answer on where you actually stand?
IT Cares' managed IT and cybersecurity plans are built specifically for Canadian SMBs — no enterprise-scale pricing, no jargon.
Frequently Asked Questions
The Cheapest Time to Deal With This Is Before It Happens
A security audit costs a fraction of even the smallest incident on this page. Let IT Cares show you exactly where your gaps are — no jargon, no enterprise pricing.
Comments (3)
The customer churn number is what got me. We budgeted for a ransom scenario but never thought about what happens to the client list afterward. Forwarding this to my partners.
The accounting firm scenario hit close to home — we had a near miss with a wire transfer last year. Getting MFA fully enforced across the office next month, no more exceptions for "just this one client system."
Didn't realize insurance premiums jump that much after a claim. Worth reading the actual ransomware clause in our policy instead of just assuming we're covered.
Leave a Comment