US: Cyber attacks on average cost each small business over $8,000 annually
Source: Middle East Insurance Review | Jan 2024
The median cost of cyber attacks has decreased for US small businesses from $10,000 in 2022 to $8,300 in 2023, according to Hiscox Cyber Readiness Report 2023.
The 2023 edition of the annual report by the Bermuda based specialty insurer, which gauges businesses’ preparedness to combat cyber incidents and breaches, is focused on small businesses.
The report is based on a survey of over 5,000 professionals responsible for their company’s cyber security strategy from the US, the UK, France, Germany, Spain, Belgium, Republic of Ireland and The Netherlands.
The major findings specific to the more than 500 US small business professionals include the following:
- Small businesses see cyber as a real threat and 33% of the US small businesses consider cyber risk high or very high, which is ahead of economic issues and competition.
- The median cost of cyber attacks for one business in a year is approximately $8,300, down from about $10,000 last year. Although the cost is down, the median number of attacks has risen from 3 in 2022 to 4 in 2023.
- Small businesses paid over $16,000 in cyber ransoms over the past 12 months. For businesses that paid ransoms, only half (50%) recovered all their data and 27% of the time, hackers made additional demands for money.
- In ransomware attacks, the most common points of entry were phishing (53%), unpatched servers/VPN (38%), and credential theft (29%).
- Despite a 10% increase in median IT budgets and a 24% increase in cyber security spending over the last 12 months, 59% of small businesses don’t use security awareness training. Further, 43% of the businesses surveyed don’t have network-based firewalls.
- 53% of the small businesses in the US have either a standalone cyber insurance policy or have cyber coverage through another policy.
- For all sizes of business, the US ranks second (behind France, 2.98) for cyber maturity with a score of 2.94. When it comes to cyber expertise, 63% of small businesses in the US are intermediates and only 4% are cyber experts.