CCR Magazine

CCRi banner ad
You are here  :Home arrow News arrow SMEs underestimate the cost of a data breach by 40%
Contact Us Newsletter Signup RSS Feeds

Latest News Headlines


Commercial Credit News


SMEs underestimate the cost of a data breach by 40% PDF Print E-mail
Thursday, 24 March 2016
Half of small businesses in the UK have no plan in place to deal with a data breach and are drastically underestimating the cost of managing one.

Experian’s third annual data breach preparedness study reveals a worrying lack of understanding among SMEs regarding the true cost of a data breach, with estimates falling short by an average of 40%, which could leave the survival of many at stake if a breach were to hit. Government figures indicate that a data breach costs SMEs an average of £310,000; yet the SMEs surveyed estimated the cost to be £179,990 - a shortfall of over £130,000.

While it’s clear SMEs are underestimating these direct costs, the additional indirect costs associated with reputational damage and impacted trust makes the picture for unprepared organisations even more bleak. Two thirds (64%) of consumers say they would be discouraged from using an SME’s services following a data breach, yet just a quarter (23%) of SMEs surveyed acknowledged this as a risk.

Jim Steven at Experian said: “Our study has uncovered an ‘it’ll never happen to us’ attitude among Britain’s most vulnerable businesses. While it’s understandable that smaller businesses may feel they lack the resource or expertise to prepare for a data breach, they are also the most vulnerable. Whether due to sophisticated cybercrime or basic human error, the true cost of a breach is far worse than companies are imagining, and for small companies especially, businesses need to ask themselves whether their business could survive if two thirds of their customer base were to disappear overnight.”

Just 45% of small companies said they had a data breach response plan in place, in spite of three quarters of UK SMEs (74%) having experienced a data breach last year. The research revealed complacency as the main reason for inaction:

· Half (51%) of SMEs without a plan said they did not see it as a priority;
· 40% said they did not think they were at risk;
· A fifth (20%) cited a lack of available budget as the main barrier.

Three quarters (77%) of SMEs are confident they would know what to do in the event of a data breach; yet further investigation found that 60% of plans contained no provisions for customer remediation and around half contained no provision for insurance or communications around the data breach (48% and 49% respectively).

A typical SME response plan:

· 42% No customer notification
· 45% No legal plans
· 48% No insurance plans
· 49% No communication plans
· 60% No remediation for customers
· 75% No forensics

“Our research has uncovered a vast gulf between how ready SMEs think they are for a data breach and the stark reality. With high profile data breaches becoming an almost-monthly occurrence, and European legislation that’s likely to fundamentally change requirements of companies around customer notification, we urge companies of all sizes to expect the unexpected and put solid plans in place. Given the halo effect of financial implications resulting from impacted customer loyalty and longer-term reputational damage, it’s vital that businesses remember that the real people affected here are customers and they’re the ones who will ultimately vote with their feet.” Jim Steven continued.
3 October - Guoman Tower Hotel, Central London 

CCRInteractive, in association with Marston Holdings , is the largest and leading one-day conference from the publishers of CCRMagazine – a truly national and international event for the credit industry.

This landmark event allows delegates to: Learn best practice of how to increase profitable sales in today’s economy. Understand the key compliance issues and how they will impact upon you. Discuss the legislative and regulatory framework and how it will effect you. Consider the potential effects of Brexit on your business. Discover the latest innovations in the market to improve your collections. Motivate your staff to achieve ever improved results.

To book to attend in 2017, contact Stephen Kiely  or Alison Lucas. To find out more about being part of this landmark event, please contact Gary Lucas

 Forums International Ltd

Forums International Ltd

 Attendance at your first meeting is free of charge, and please quote reference 'CCR2016' to receive the special 10% discount off of your first annual subscription.

Find out more here.

latest issue

CCR Cover

The latest edition of CCR Magazine, the leading editorial publication in the UK credit industry, is out.

Read the latest issue online

The Credit Excellence Awards


Tuesday 3 October - Guoman Tower Hotel, Central London

Do not miss your chance to meet and network with the Winners and Finalists at the Credit Excellence Awards, in association with Hoist Finance.

To book your place to attend, please contact Alison Lucas.


CCR is the premier magazine for consumer and credit professionals. It provides an independent voice to the industry, breaking major news stories and running in-depth features.

As a magazine, it works with and campaigns on behalf of the credit industry to promote its importance as a centre of potential profit and business development to the wider business world.

Subscribe to CCR Magazine

CCR World Magazine


Providing information and analysis for thousands of senior credit professionals worldwide, every quarter.

Find out more

GTS Media Ltd
81 Cambridge Road

Registered in England No: 05483197