Fortellar
Blog

The Real Cost of a Data Breach

Client Exposure, Insurance Gaps, and What Comes Next

When most organizations think about the cost of a data breach, they think about fines. That's understandable. Regulatory penalties make headlines. GDPR fines run into the tens of millions. HIPAA settlements are public record. And there's something clarifying about a number in that it gives leadership something concrete to point to when making the case for security investment.

But fines are rarely the most expensive part of a breach. And for most organizations, they're not even the most likely consequence. The real cost of a data breach is harder to quantify, takes longer to materialize, and is considerably more difficult to recover from.

Here's what actually happens.

The First 72 Hours

The immediate aftermath of a breach is a logistics problem…and most organizations aren't ready for it.

Before you can notify anyone, you need to know what happened. That requires forensic investigation: determining when the breach occurred, which systems were affected, what data was accessed or exfiltrated, and how the attacker got in. If you don't have an incident response plan and a relationship with a forensic firm already in place, you're building that capability under pressure, on the clock.

Why does the clock matter? Because notification timelines are not suggestions. Under most US state breach notification laws, affected individuals must be notified within 30 to 72 hours of discovering a breach involving personal information. GDPR requires notification to supervisory authorities within 72 hours of becoming aware of a breach. HIPAA requires notification to affected individuals within 60 days, but your business partners and covered entity clients may contractually require faster notification.

The organizations that handle breaches well are the ones who did the work before the breach happened: incident response plans that have been tested, forensic retainers in place, a notification protocol that's been reviewed by legal, and communication templates that don't have to be written from scratch at 2 a.m.

“Fines are rarely the most expensive part of a breach. The real cost is harder to quantify, takes longer to materialize, and is considerably more difficult to recover from.”

The Client Conversation

For organizations that sell to enterprise clients or hold sensitive data on behalf of other businesses, the most consequential call after a breach is often not to a regulator. It's to a client.

Enterprise clients have their own regulatory obligations, their own boards, and their own customers to protect. When a vendor breach exposes their data, they need answers quickly: What was accessed? Whose data is affected? What was your security program supposed to prevent this? What are you doing now?

A vendor who can answer those questions clearly, promptly, and honestly, with documentation to back it up, is in a fundamentally different position than one who can't. The former has a difficult conversation. The latter has a crisis.

And the documentation matters. Enterprise clients will ask what your security program looked like before the breach. If the answer is a collection of policies that haven't been reviewed in three years and a SOC 2 audit that lapsed eighteen months ago, that becomes part of the record. If the answer is a current Type II report, documented controls, and evidence of continuous monitoring, it becomes context that supports the argument that you were operating a reasonable program and something still went wrong, which happens.

The Insurance Gap

Cyber insurance was supposed to be the backstop. For many organizations, it is, but not always in the ways they expected.

Cyber policies have gotten more complex as claims have gotten more expensive. Coverage that seemed comprehensive at renewal often turns out to have meaningful exclusions when something actually goes wrong. Common gaps include:

Incident type exclusions. Some policies exclude specific attack vectors, such as ransomware from state-sponsored actors, social engineering losses, or breaches originating from a vendor's vendor rather than the vendor directly. The fine print matters.

Scope mismatches. If your policy covers your primary environment but the breach originated in a third-party system you rely on, coverage may be disputed. Supply chain compromises create exactly this kind of ambiguity.

Underreporting of risk. Premiums are based on the risk profile you disclosed at the time of application. If your environment has changed materially with new systems, more users, AI tools with access to sensitive data, etc. and you haven't updated your policy, you may find that the insurer disputes the claim on the basis of changed risk.

Sublimits on specific costs. Forensic investigation, notification costs, and business interruption losses are sometimes subject to sublimits well below the overall policy limit. Organizations that haven't walked through their policy with coverage counsel often discover this after the fact.

None of this means cyber insurance isn't worth having. It is. But treating it as a substitute for a security program rather than a complement to one is a costly misunderstanding.

The Malpractice and Liability Question

For professional services organizations, such as law firms, accounting firms, consultancies, and others who hold sensitive client information as part of delivering their services, breach exposure extends into professional liability territory.

The ABA has been explicit: competent representation includes cybersecurity competence. When confidential client information is exposed because a firm failed to maintain adequate security controls, the question of professional liability follows quickly. That's not hypothetical anymore. It's the basis of claims that have been litigated.

More broadly, any organization that holds sensitive data on behalf of clients under a service agreement should understand what that agreement says about data security obligations. The contractual baseline for what constitutes "reasonable" security is moving steadily upward, driven by enterprise clients who are inserting more specific security requirements into vendor contracts every year.

“The organizations that handle breaches well aren't the ones with perfect security programs. They're the ones with honest, documented, operational ones.”

The Long Tail

The costs that get underestimated most consistently are the ones that don't appear on the invoice.

Client attrition. Enterprise clients who experience a breach through a vendor don't always terminate the relationship immediately. Sometimes they wait until the contract renewal. Sometimes they shift work elsewhere while keeping the relationship nominally in place. The revenue loss is real and significant, but it materializes slowly and is hard to attribute directly in the moment.

Reputational effect on new business. Breaches become part of the public record. Prospect security reviews include questions about past incidents. How you handled it matters, but so does the fact that it happened.

Internal cost of remediation. After a breach, you have to fix the thing that went wrong. In most cases, that means significant investment in the security program that should have prevented the breach in the first place — at a moment when the organization is already absorbing investigation costs, legal fees, and potentially regulatory penalties. It's the most expensive time to build a security program.

Leadership distraction. The executive bandwidth consumed by breach response is substantial and difficult to quantify. Months of leadership attention that would otherwise go toward the business go toward managing the fallout.

What Changes the Math

Organizations that experience breaches but manage them well by containing costs, preserving client relationships, and emerging with their reputation intact tend to have a few things in common.

  • They had a documented security program with real operational controls, not just policy documents. When clients asked what their security looked like before the breach, they had something credible to show.
  • They had incident response plans that had actually been tested. They knew who was responsible for what before anyone had to figure it out under pressure.
  • They were honest and prompt in their communications. With clients, with affected individuals, and with regulators. Organizations that slow-walk notification or communicate vaguely tend to compound their exposure significantly.
  • And critically, they had already built the relationships that made those conversations possible. Enterprise clients who know a vendor, trust their team, and have confidence in their program give significantly more benefit of the doubt than clients who are evaluating the vendor for the first time in the middle of an incident.

The Bottom Line

A breach is expensive. The fine, if there is one, is often not the most expensive part.

The real cost is in the client conversations you have to have, the insurance coverage that doesn't quite fit, the revenue that doesn't renew, and the internal work of rebuilding credibility. And the most reliable way to change that math is to do the security work before the breach happens, not after.

The organizations that handle breaches well aren't the ones with perfect security programs. They're the ones with honest, documented, operational ones.

Fortellar works with organizations to build compliance programs that hold up before, during, and after the moments that matter. Get in touch to talk through where your program stands.

Incident Response & Resilience

Talk to the team that does the work.

Fortellar builds and runs security and compliance programs for regulated organizations. Bring us the gap you are trying to close.

Talk to Us