Key Takeaways:

  • A report released Wednesday by the Identity Theft Resource Center (ITRC) found that over the past year, 81% of U.S. small businesses experienced a cybersecurity breach, data leak, or both, with more than half of the victims reportingfinancial losses between $250,000 and $1 million.
  • A survey of 662 U.S. small business executives found that nearly four in ten victims said they were forced to raise product prices to cope with the financial impact of the incidents.
  • "In effect, rising cybersecurity costs and financial damage from data breaches are creating a hidden 'cyber tax' that is passed directly to consumers—who are also the very individuals directly victimized by identity criminals stealing their personal information (and financial resources)," the ITRC stated in the report. The ITRC is a nonprofit organization dedicated to helping victims of cybercrime.

Deep Dive:

Cybersecurity has become one of the top challenges keeping CFOs "up at night," second only to profitability and tied with inflationary pressures/economic uncertainty. Global workforce services company ManpowerGroup reached this conclusion in a study released in October.

ManpowerGroup reported that nearly three-quarters of CFOs are now involved in cybersecurity efforts, with half deeply engaged in strategy development and incident response, reflecting the high level of concern among businesses.

The ITRC study found that most surveyed small businesses experienced multiple cybersecurity incidents, with threat actors employing sophisticated methods, including AI-driven attacks.

ITRC President James Lee said in apress release about the studythat "the current situation is not a level playing field; it drags down the economy and threatens national security. The data in the report is alarming and should serve as a wake-up call for everyone."

IBM's annualCost of a Data Breach Reportreleased in July noted that the average cost of a data breach in the U.S. was $10.22 million, up 9% from the previous year, marking the highest record in any region. IBM stated that this surge was driven by stricter regulatory fines in the U.S. and higher detection and escalation costs, while the global average breach cost fell 9% to $4.44 million over the same period.

Among organizations surveyed by IBM, one-third said they would raise prices by more than 15% due to cyberattacks. However, the overall proportion of organizations indicating they would pass breach costs to customers fell by nearly a third, dropping to 45%, down from 63% last year.

IBM noted that while businesses may choose to pass breach costs to customers to offset losses, this strategy could backfire, especially in "price-sensitive markets or periods."