How do you measure the cost of not being able to be trusted?
Cyberinsurance can’t fix reputation damage
Smaller organizations underestimate how much a breach damages their reputation
Before you look to cyberinsurance to save the day, there’s another reason to prioritize security controls first — and it has nothing to do with premiums or policy limits. As Michael Murphy of Murphy Insurance Agency puts it: “insurance cannot fix reputation.”
That may sound like something only an insurance or cybersecurity professional would say. But the business case for taking reputation seriously is well-documented, and the risks are more concrete than many leaders realize.
Cost of a Data Breach
That title is borrowed from the major annual survey by IBM. To illustrate trends, the report gives breakdowns of the frequency of breaches, how they happen and the industries affected and the dollars spent on things like ransomware payments and remediation efforts. One thing it cannot fully quantify is the short-, mid- and longterm effects of a breach on a business. But just because these are hard to track doesn’t mean they’re any less real, just more insidious.
There are some businesses for which Google Reviews are a major factor. Harvard Business Review found that a single one-star drop in reviews costs a business between five and nine percent of annual revenue.
But a confirmed data breach, in which for example confidential records are stolen, can damage your fundraising prospects, hurt your ability to recruit top talent and erode the trust of clients and partners you’ve spent years building.
In Michael Murphy’s memorable phrase: trust … takes forever to earn and takes an instant to lose.
Last year defense contractor MorseCorp agreed to pay $4.6 million dollars in fines to the US DoD for fraudulently representing its compliance with the NIST framework. Reputation damage from that kind of settlement is part of the public record – very difficult and costly to come back from.
Ripple effects
Have you experienced a breach? If so, you may know the unfortunate human toll on an organization.
The effects of a breach move through a workforce in ways that are easy to underestimate. The first questions employees tend to ask are: ‘Did I do something wrong? Am I going to get fired?’ What often follows is a period of paralysis, rumor-making and finger-pointing, especially if the organization hasn’t stress-tested its Incident Response Plan.
This is part of why post-breach, large organizations frequently fire the CIO – not necessarily because that person caused the breach, but to signal a clean break and restore confidence. It’s a costly, disruptive move that rarely addresses root causes. (How do they hire the next CIO? I wonder.)
Post-breach employee morale is its own quiet crisis and one that rarely shows up in a breach-cost report.
In recovery
IBM’s report this year does put numbers on how long the effects of damage actually lasts. Among organizations that fully recovered, 76% said it took more than 100 days – fielding client questions, managing staff anxiety and trying to close new business while the incident is still a live topic. And only 2% of respondents reported a recovery time of less than 50 days.
And then the kicker – 65% of organizations surveyed said they had not fully recovered at the time of the report. IBM explicitly defines full recovery as the restoration of customer confidence and employee trust, not just containment of the breach itself. A good IT team can remediate in days. Winning back the trust of a client who got a breach notification letter from you takes considerably longer and it’s a much murkier road.
I’ve seen numbers circulating from 20% to 60% of smaller businesses that would fail because of the effects of a breach. Those stats can vary as much as the types and severity of cyberattacks. And those numbers don’t matter nearly as much as asking yourself the amount of theft and/or closure and/or operational damage your organization could realistically sustain and still function.
Is this your golden opportunity?
Consider the organization that we met with and still passed on security controls. They were hit with a ransomware attack less than a year later and told me they regretted that they dragged their feet.
A discovery call doesn’t commit you to anything. But it can give you a better picture of where you stand, what’s actually at risk, and what closing gaps would involve for an organization in your industry.
So if the data in this post gave you pause, consider contacting Bryley’s Roy Pacitto at rpacitto@Bryley.com or reach him by phone at 978.562.6077 x217.
The following quiz is provided as a tool for learning modeled on cybersecurity certification tests. The quiz collects no data.
by Lawrence Strauss, July 27, 2026
Lawrence has written for Bryley since 2015. His coverage of cyber-scams appears on moneywise.com