What is data breach cost?
Data breach cost is the total financial loss an organization suffers because of a data breach. It adds direct spending, such as investigation, legal advice, notification and fines, to indirect losses, such as downtime, lost customers and higher insurance premiums, some of which keep arriving for years after the incident.
Line items on a breach bill
Backup is normally budgeted as an IT running cost, while breach cost lands on the whole business. The two meet in downtime and recovery, which are often the largest items after ransomware. Each line below responds to the state of the backups differently.
- Investigation: forensic firm, internal staff time, crisis management. It shrinks when storage logs answer scope questions quickly.
- Downtime and lost business: revenue lost during the outage and customers who leave afterwards. It falls in step with restore speed.
- Recovery: rebuilding systems, replacing hardware, overtime. It is far smaller when data does not have to be recreated.
- Notification: identifying affected people, letters, call centers, regulator filings. Backups do not change it.
- Legal and regulatory: defense, settlements, fines, credit monitoring. Backups rarely move it.
Fines sit at the far end. GDPR Article 83 sets two ceilings: €10 million or 2% of worldwide annual turnover, and, for more serious infringements, €20 million or 4%, whichever is higher in each case. Supervisory authorities set the actual figure by weighing the nature, gravity and duration of the infringement and the steps taken to limit the damage, which includes how the data was protected and recovered.
Twenty-four hours versus seventy-two of downtime
Downtime is billed by the hour. A business losing $20,000 of revenue an hour pays $480,000 for a 24-hour outage and $1.44 million for a 72-hour one. Most of the gap between those figures is decided inside the backup environment: whether clean restore points survived, and how fast the repository can deliver them. A recovery that rebuilds data from scratch, or waits days on a slow restore, moves the bill into a different order of magnitude.
Backup storage is usually compared on price per terabyte. Measured against breach cost, the comparison that counts sets the price of keeping enough protected restore points, on storage with enough restore throughput, against the price of each extra day offline when they are missing. Cyber liability insurance absorbs part of both, after its waiting period and within its sublimits.
Data breach impact on people, records and trust
Data breach impact is the wider set of consequences behind the invoice, for the people whose information was exposed and for the organization that held it. Some of it can be undone and some cannot. Exposed passwords are reset and payment cards reissued; government identifiers are rarely replaceable, health records never are, and a published home address changes only when the person moves. Stolen records are resold and merged with data from other breaches, so harm to individuals can surface years later.
Inside the organization, altered records create a quieter loss. Until the team can show which entries an attacker changed, every decision based on them is in doubt, and the only way to show it is a comparison with an earlier copy the attacker could not modify. Lost customer and partner trust tends to outlast the outage itself.
Encryption narrows impact in one specific way. Under GDPR Article 34, notifying affected individuals is not required when measures such as encryption left the data unintelligible to whoever took it, which is why backup encryption matters for lost disks and offsite media. Managed service providers see impact multiply: one set of credentials reaching every client's backups turns a single breach into separate notifications, separate contract claims and separate restores competing for the same platform.
ARTESCA and data breach cost
ARTESCA bears on the recovery lines of a breach bill and leaves the disclosure lines alone. Backup data written to it under S3 Object Lock in compliance mode stays in place until its retain-until date whichever account the attacker has taken over, so an encrypted or wiped production estate still has an intact source to restore from instead of a rebuild from nothing. Governance mode, which any holder of the bypass permission can lift, offers weaker assurance. Capacity scales to a validated 8.5 PB on standard servers or a hardware appliance, the price-per-terabyte side of the comparison above.
Notification letters, legal defense, regulator inquiries and credit monitoring follow stolen data, and no storage setting reduces them.
Related terms
- Data breach: unauthorized access to, disclosure, alteration or loss of data.
- Cyber liability insurance: cover that transfers part of a cyber loss to an insurer.
- Restore throughput: the sustained rate at which backup data comes back.
- Backup encryption: ciphering backup data so a stolen copy is unreadable.
