How can the rise of targeted cyberattacks be explained?
Discover through this article the different costs of a cyberattack
© Ercom-Illustrator
In 2024, ANSSI handled 4,386 security incidents, an increase of 15% compared to the previous year. France is one of the most targeted countries in the world by cybercriminals: it ranks sixth globally in terms of ransomware attack detections and fourth for malware.
The consequences of these attacks are often underestimated. What are the visible and invisible costs of a cyberattack for your organisation?
The visible costs of a cyberattack
A successful cyberattack immediately generates several visible financial costs. First, in the case of ransomware, some organisations choose to pay a ransom to cybercriminals in order to recover their data. This practice is strongly discouraged: not only does it encourage cybercrime, but cybercriminals are likely to demand a second ransom by threatening to publicly release the stolen sensitive data.
Securing compromised data involves costs related to identifying, isolating, and restoring affected systems. In 2024, the average cost of a data breach in France was €4.2 million, according to IBM.
Organisations are legally required to notify customers when their data has been compromised. This involves drafting a clear and legally compliant message, followed by large-scale distribution so that all affected individuals are informed. In many cases, a dedicated hotline is also set up to answer questions and reassure customers.
Depending on the scale of the attack and the nature of the organisation, it may also be necessary to set up a crisis communication unit and involve a public relations agency.
Once the incident is over, technical investigations must be conducted to identify the vulnerabilities exploited by attackers, assess the full extent of the breach, and detect any potential backdoors left in the system.
In the event of cybersecurity failures, heavy fines may be imposed by authorities. For example, the GDPR (General Data Protection Regulation) provides for penalties of up to €20 million or 4% of global annual turnover, whichever is higher. Compliance efforts may also be required to demonstrate corrective action and avoid further sanctions.
Beyond compliance, organisations must strengthen their cybersecurity mechanisms to prevent similar incidents in the future. This requires audits and investment in cybersecurity solutions.
Finally, legal costs must also be considered for two reasons: on one hand to manage potential lawsuits from customers or partners whose data has been compromised, and on the other to initiate legal proceedings against cybercriminals or a failing third-party partner in the case of a supply-chain attack.
The invisible consequences of a cyberattack
A cyberattack can also have less tangible impacts. Very often, ransomware or DDoS attacks can force a shutdown of operations for several hours or even several days. This results in lost revenue for any business relying on digital sales or operations.
The reputational impact of a cyberattack should not be underestimated. In the eyes of the public, an organisation affected by a cyberattack is often seen as having failed to adequately protect itself. As a result, customers lose trust, believing their personal data was not properly secured. The company’s brand image is therefore directly affected, leading to potential drops in customer retention and revenue.
This is also the case in B2B sectors: some business partners may decide to end collaborations, while client companies become concerned about the security of their sensitive data.
If the company is publicly listed, its brand value may decline and its stock price may drop rapidly due to both loss of investor confidence and media coverage of the incident.
In the case of a data breach, cybercriminals may also obtain the company’s intellectual property (patents, trade secrets, development plans, etc.). This may then be resold to competitors, leading to a loss of competitive advantage and undermining years of research and investment.
A cyberattack also affects employee morale. In the event of data deletion or theft, their work may be wiped out. Some employees may feel responsible for the situation, particularly in technical teams. Others may worry about the confidentiality of their personal data. This creates an environment of tension, mistrust, or suspicion, potentially leading to long-term disengagement or resignations.
The combined impact of all these consequences can threaten the very survival of a company. A recent example involves an ERP and e-commerce services company. A ransomware attack managed to reach the environment hosting customer data and fully encrypt it. The company never recovered and was placed into liquidation a few months later.
The consequences of a cyberattack can go far beyond simple data loss. Deploying appropriate cybersecurity solutions is now a matter of survival. End-to-end data encryption is one of the key pillars of this protection, along with securing endpoints and remote access.