The 4 hidden costs of a cyberattack: from system rehabilitation to legal consequences
Whether it's a hacked email box, a ransomware attack, an unavailable computer system or information sent by mistake, the first reflex is to assess the financial impact of the cyber incident based on the amount stolen or the systems affected. However, as soon as critical processes for the company freeze, fixed costs continue to accumulate. Stef Vermeulen, cyber insurance expert and Country Manager of Stoïk, deciphers the 4 hidden costs that make up the overall bill of an attack.
Belgium recorded 635 incident reports in 2025, nearly 70% more than the previous year, according to the latest figures from the Belgian Cybersecurity Center. The issue of cyberattacks now concerns all organizations without distinction. Suffice it to say that good preparation can make all the difference.
Stef Vermeulen, cyberinsurance expert and Country Manager of Stoïk Belgium highlights this reality based on an international study conducted by IBM on data leaks. "Organizations with a trained intervention team and a regularly tested response plan report lower costs as a result of a data leak." But, the expert points out, "the exact composition of this final invoice is often less obvious than we think". Based on an internal report from Stoïk, Stef Vermeulen reviews four hidden costs related to cyber incidents for SMEs.

The 4 hidden costs making up the overall bill of an attack
1-Stops and delays
A cyber incident can disrupt the day-to-day operation of a business in a very short time. Following the attack, employees can no longer access essential systems, resulting in a temporary stoppage of activities, delays in service delivery or a stoppage of production and deliveries. Meanwhile, the fixed costs continue to run normally. The financial impact can therefore quickly increase, even if the direct loss remains limited. The longer the critical processes for the company are disrupted, the heavier the incident weighs on business continuity.
Rapid intervention can limit the impact of a cyber incident, but does not eliminate the financial consequences. Stoïk estimates the average loss for companies with an annual turnover of €25 million between €58,000 and €92,000, depending on the sector, even when the response to the incident is launched within an hour after the attack.
2. Investigation and system restoration
The resolution of a cyber incident is not limited to the return of systems. Cybersecurity experts must first determine how attackers were able to get into the system, which systems were affected, and whether it is safe to restart them. It takes time and staff. In the case of ransomware incidents handled by Stoik in 2025, investigations lasted an average of 10.3 days and 18 days for system reconstruction.
Hidden costs also lie in the overtime to get the systems back in order. In 2025, the workload related to the reconstruction of information systems increased by 23.4%, while cybersecurity experts spent 49.5% more time on the survey. This effort is in addition to the daily work of internal IT teams and possible external specialists.

3. Damage to the reputation and trust of customers
During ransomware attacks, the impact is often not limited to the systems themselves. Cybercriminals steal data, threaten to disclose it or even go so far as to contact customers, suppliers or employees directly to increase the pressure. As a result, an incident can continue to have repercussions even after the technical restoration. Companies must answer questions, reassure their customers and clearly explain how they manage future risks. This requires additional communication time and effort, while reputational damage can also have business consequences if customers or partners lose trust.
4. Legal consequences
A cyber incident can also have legal consequences. When personal data is concerned, the GDPR applies and the company must check its obligations. In Belgium, the Data Protection Authority ensures compliance with data protection rules.
For organizations covered, for example, by the NIS2 Act, additional requirements may apply to the management and reporting of incidents. Legal and privacy experts must therefore help determine which data is concerned, what action is needed, and whether the incident should be reported. This follow-up also requires time and expertise, often while the technical refurbishment is still in full swing.
Good preparation saves precious time
For Stef Vermeulen, it goes without saying that "cyber risk management is an essential element of the day-to-day management of any company, regardless of the size of the organization. Companies have every interest in identifying their critical processes, defining responsibilities and determining the internal and external skills they need." This also includes regular testing of backups and emergency plans. "Thus, in the event of an incident, no valuable time is lost in discussions and distribution of roles, and the company can focus more quickly on the essentials: stopping the attack, restoring key processes and limiting additional damage," concludes the specialist.

