For this 120-person manufacturer, the ransomware attack cost around €1.4 million: lost production, the incident response firm, hardware, recovery work, the insurance deductible and data that never came back. The security recommendations they had declined in the three years before were worth roughly €58,000 a year. Below is how the €1.4 million came together, and what the company changed afterwards.
This is an anonymised, composite case from my own client work; figures are rounded.
This is Part 3 of a case study that started with three years of declined security recommendations and continued through a ransomware attack that started with one email.
The Board Meeting Where Someone Had to Pay
April 2024. Board meeting. The new CFO needed someone to blame for the ransomware attack, and the obvious candidate was the external IT provider: me.
I brought a folder. Three years of emails, recommendations, and quotes, each with a date and a decision attached:
June 2021: M365 Business Premium with MFA, Defender, and Intune, €28,800 a year. Declined. March 2022: a plan to decommission the Windows 7 and Server 2008 R2 machines. "Under consideration," no further reply. May 2022: server room AC replacement, €3,500. Declined. August 2022: a quote for a real backup solution with an offline copy, €12,000 setup plus €800 a month. Declined. January 2024, after the AC failure: an email that read, in part, "This was a €3,500 problem. Next time, it will be a €500,000 problem." No response.
Total value of the declined recommendations: roughly €58,000 a year. Total cost of the ransomware attack (lost production, the incident response firm, hardware, my time, the insurance deductible, the data that never came back) landed around €1.4 million. Nobody in the room said much after that.
What Does It Actually Cost to Recover From a Ransomware Attack?
The incident response retainer alone was €45,000. The cyber insurance deductible, after coverage had been scaled back during the cost-cutting the year before, was €150,000. Recovery took four weeks of eighteen-hour days, rebuilding systems from whatever survived: old emails, paper records, a few employees' personal laptops.
Line by line, as far as this company itemised it (case figures, rounded):
| Cost item | Amount |
|---|---|
| Incident response firm | €45,000 |
| Cyber insurance deductible | €150,000 |
| Lost production, replacement hardware, four weeks of recovery work including my time, and the data that never came back | roughly €1.2 million, not itemised further |
| Total cost of the ransomware attack | around €1.4 million |
The overheated server room two months earlier was its own incident, at close to €228,000.
Some of it never came back. A twenty-year-old payroll database was gone outright. Financial records from 2019 through 2023 were incomplete. Customer order history survived only in fragments. And because the attacker had exfiltrated data before encrypting anything, there was a second cost that doesn't show up on an invoice: explaining to customers why their information had been sitting on someone else's server for three weeks before anyone knew.
What Changed After
By the end of 2024, the company had migrated all 120 users to Microsoft 365 Business Premium, the same plan declined in 2021, with MFA, Conditional Access, Defender for Endpoint, and Intune rolled out fully. The remaining on-prem servers moved to Azure. Backup became an actual 3-2-1 setup with an immutable cloud copy and monthly restore tests, not a Friday USB drive.
They hired an IT team instead of an IT person this time: two people, plus a 24/7 SOC, because the factory runs three shifts and IT problems don't wait for business hours. The full security stack now runs about €95,000 a year, less than what they'd been spending on emergency fixes and my weekend call-outs before the attack.
The CFO resigned in September 2024. The board replaced him with someone who asks questions before cutting things. By December, the company's Secure Score had gone from an estimated 35% to 82%.
The Real Lessons
Fifteen years without a failure is a warning sign
A server that hasn't failed in fifteen years is overdue. The absence of an incident says little about the defenses; often it means someone has been catching problems before they became incidents.
The cheapest option is the most expensive one, eventually
The €3,500 AC repair became a €228,000 weekend. The free antivirus became part of a €1.4 million incident. Every cost-cutting decision in this story ended up costing ten to a hundred times more than the thing it was meant to save.
Invisible IT work is still work
The fired IT veteran's absence cost €2,400 in a single emergency call, on top of the certificate failure that weakened the company's defenses for ten days before the attack, with nobody watching. The best IT people are invisible because everything works, and that invisibility is easy to mistake for being unnecessary.
MFA was only part of what got declined
The link that started this attack dropped a loader on an unpatched Windows 7 laptop, and MFA on its own does not stop that. The package declined in 2021 was more than MFA: Defender checking links and attachments, endpoint protection on managed devices, and Intune, which would have retired that laptop years earlier. I think that package would likely have stopped this attack early; I can't prove it. €28,800 a year against a €1.4 million incident works out to roughly a 48x return, calculated from this company's own numbers and not meant as a benchmark for anyone else's.
Testing a backup is what makes it a backup
The Friday USB drive was theater. The domain-joined backup server turned into a second victim of the same attack, instead of the escape hatch everyone assumed it was. "We have backups" and "we tested restoring from backups last month" are two different sentences, and only one of them means anything during an incident.
A paper trail is what professional survival looks like in writing
Three years of documented recommendations were the only thing standing between me and being blamed for a decision I never got to make.
Companies this size are targets too
Most of the ransomware cases I get called into involve companies of this size, not enterprise targets. "Why would anyone bother hacking us" is not a security posture, and this company found that out the expensive way.
Zero Trust. Zero Drama. Zero Bullshit.
If you put every declined security recommendation from the last three years into one folder, what would the total be, and what would you set it against?
If you want to see what this looks like for your own Microsoft 365 setup: drop me a note. Thirty minutes, I'll show you.
Talk it through with meFrequently Asked Questions
What is the ROI of MFA and Microsoft 365 security for a small business?
In this case, roughly 48x: €28,800 a year in Microsoft 365 security features against a €1.4 million incident that the declined package would likely have stopped early. That is one company's numbers, not a benchmark. Your own ratio depends on what an incident would cost you, but in my experience the gap between prevention and recovery is usually wide.
How long does ransomware recovery take?
For this company, about four weeks of intensive rebuilding, with some records never fully recovered. Recovery time depends heavily on backup quality and how early the attack is caught; untested or compromised backups can extend it considerably.
Should a small business pay the ransom?
Most incident response guidance says no: decryption isn't guaranteed, payment doesn't undo data that was already stolen, and it funds the next attack. This company didn't pay and rebuilt from what survived instead.
Does cyber insurance cover the cost of a ransomware attack?
Partly, and only on the terms of the specific policy. Deductibles, sub-limits, exclusions and the security controls declared when the policy was signed all decide what gets paid. Here, a policy downgraded during cost-cutting left a €150,000 deductible with the company. Read your own policy with your broker before an incident, not after.
What's a realistic annual cybersecurity budget for a 120-person company?
This company landed around €95,000 a year after the incident, covering M365 security licensing, a two-person IT team, and a 24/7 SOC. That was less than they'd been spending reactively before, and a fraction of what this one incident cost.