“Don’t Do Security, It Pays Off” – What the Risk Calculator Says vs. What the Post-Attack Invoices Say

There is a formula you learn for the CISSP exam that nobody then dares to apply literally: a safeguard should not cost more than the losses it prevents. Sounds reasonable. The problem is that if you plug in real numbers from Poland, the answer very often comes out as: security is not worth doing. 💥

And before anyone throws a slipper at me: I didn’t invent this formula. It was invented by people who wanted security to be rational rather than religious. Today I want to take it seriously, do the math honestly, and find out where it breaks.

⚡ TL;DR (for the busy):

  • The CISSP formula: annualized loss expectancy (ALE) = the loss from a single incident × how often it happens per year. A safeguard that costs more than ALE is “irrational”.
  • Reality: the average breach now costs $4.99 million (IBM 2026). Equifax paid about $1.4 billion for one missing patch. Change Healthcare about $2.9 billion for missing MFA on a single Citrix server.
  • But: Equifax’s share price recovered within a year and hit all-time highs in 2021; Żabka, three days after a €7.56 billion takeover offer, lost source code that a hacker priced at €5,000 – and the stock didn’t flinch. In eight years of GDPR, Polish companies were fined a total of about €25 million, and after a breach only about 11% of customers actually leave, though 78% say they would.
  • Except averages don’t die: KNP Logistics (158 years old, 730 jobs) ended with one guessed password; Travelex, Vastaamo, Lincoln College and National Public Data never got back up either, and in Poland the bike maker 7Anna (Rondo, NS Bikes) filed for bankruptcy after a single redirected bank transfer.
  • Conclusion: the formula is fine; companies just feed it lowballed numbers. And the only variable that really changes the result is an aware customer and a regulator who is catching up.

Let’s start with heresy: security is a cost, not a value

The short version for non-technical readers. Risk management counts like this:

  • SLE (Single Loss Expectancy) – how much you lose if something happens once. In plain terms: the price of one slip-up.
  • ARO (Annualized Rate of Occurrence) – how many times a year it happens. In plain terms: probability.
  • ALE (Annualized Loss Expectancy) = SLE × ARO. In plain terms: what this risk costs you per year on average if you do nothing about it.

And now the rule every CISSP knows by heart: the annual cost of a safeguard should not exceed the ALE that the safeguard reduces. If the safe costs more than what you keep in it – don’t buy the safe.

Let’s run an example (made-up numbers, real mechanics). An online shop with 200,000 customers. The owner estimates: a breach means a fine, lawyers, a few customers leaving – say PLN 1.5 million. Probability? “Well, maybe once in ten years” – so ARO = 0.1.

The textbook calculator (hypothetical data)

PLN 1.5M
SLE – the price of one incident
×
0.1
ARO – “once in 10 years”
=
PLN 150K
ALE – annual expected loss
PLN 300K
annual cost of a “sensible” security programme
300K > 150K → by the formula: NOT WORTH IT ❌

Result: by the formula, it’s not worth it. It’s cheaper to pay for the slip-up once it happens.

Lesson #1: The formula isn’t stupid. The numbers we feed it often are. And you’re about to see just how much.

Reality check: the invoices after an attack

Instead of “gut feel” estimates, let’s take real invoices.

What does a data breach cost in 2026?

According to the IBM Cost of a Data Breach 2026 report (602 organizations, incidents from March 2025 to February 2026), the average cost of a breach is $4.99 million – a record, and 12% more than a year earlier. In the US – $11.5 million. Average time from intrusion to containment: 247 days. And the most important part for our formula: almost two-thirds of that cost is not the ransom or the fine, but detection, escalation and lost business – downtime, customers who bought elsewhere in the meantime.

Average global cost of a data breach (USD millions)

2020
3.86
2021
4.24
2022
4.35
2023
4.45
2024
4.88
2025
4.44
2026
4.99 – record

Source: IBM / Ponemon Institute, Cost of a Data Breach Report 2020-2026. US average in 2026: $11.5 million.

39% of surveyed companies had at least one ransomware attack in the past year. Plug that in as ARO instead of “once in 10 years” and your ALE just quadrupled.

Equifax: $1.4 billion for one patch

In 2017, the US credit bureau Equifax leaked the data of about 148 million people. The entry point: a known Apache Struts vulnerability (CVE-2017-5638) for which a patch had been available for two months. The cost according to the company’s own filings: over $1.4 billion – settlements, regulators, lawyers, credit monitoring for victims, plus an obligation to spend at least $1 billion on security. The insurer covered $125 million. A drop in the ocean.

Change Healthcare: $22 million ransom, nearly $3 billion bill

February 2024, the largest medical claims processor in the US. The attackers came in through Citrix remote access with no MFA enabled (multi-factor authentication – that second code from your phone). Parent company UnitedHealth paid a $22 million ransom to ALPHV/BlackCat, which then vanished with the money. Total cost of the incident in 2024: nearly $2.9 billion – downtime, rebuilding, interest-free loans to hospitals that stopped getting paid. The ransom was less than 1% of the bill.

What was missing, and what it cost

EQUIFAX, 2017
Missing: 1 patch (available for 2 months)
Leaked: 148 million people
~$1.4B
Covered by insurance: $125M
CHANGE HEALTHCARE, 2024
Missing: MFA on 1 Citrix server
Ransom: $22M (<1% of the bill)
~$2.9B
Cost in 2024 alone, per the parent company

Lesson #2: When you calculate SLE, don’t put the statutory fine in there. Put in downtime, people, lawyers, lost contracts and 247 days of clean-up. That is the price of one incident.

The stock market has the memory of a goldfish 🐟

Here it gets interesting, because the “not worth it” argument has strong support in the data. Comparitech has been analysing share prices after breach disclosures for years. The 2024 edition (118 NYSE-listed companies, incidents 2007-2023) found:

  • share prices fall by a mere 1.4% on average and bottom out 41 trading days later;
  • they return to pre-breach levels after 53 days;
  • over six months, breached companies trail the NASDAQ by 3.2% on average – noticeable, not tragic.

Share price after a breach disclosure – average across 118 companies (Comparitech 2024)

DAY 0
Breach disclosed
DAY 41
-1.4%
the bottom
DAY 53
0%
back to pre-breach level
6 MONTHS
-3.2%
vs. NASDAQ

Trading days. Averages smooth everything out – which is why I show specific companies below.

Equifax: from panic to all-time high

Averages are one thing; a specific company is another. Let’s trace Equifax step by step, using figures from the financial press. On 7 September 2017 the shares cost $142.72. The day after the disclosure: -13.7%, the biggest single-day drop since 1999. A week later the price broke below $100, bottoming around $93 – more than a third down.

Equifax (EFX) – share price at key moments, USD

142.72
7 Sep 2017
day before
123.23
8 Sep 2017
-13.7%
98.99
13 Sep 2017
below $100
~93
mid Sep 2017
the bottom
135.91
7 Sep 2018
one year later
221.41
Apr 2021
record
~182
Sep 2026
today

Closing prices and levels as reported by CNBC, Fortune, AJC (2017), The Daily Swig (2018), Zacks (2021), Trading Economics (2026). Illustrative chart, excluding dividends.

One year on, on 7 September 2018, the shares cost $135.91 – almost back to where they were. An analyst quoted by The Daily Swig put it bluntly: investors have simply forgotten. In December 2020 the stock hit all-time highs, and in April 2021, after quarterly results, it jumped 14.9% to $221.41. A company that lost the data of nearly half of American adults and paid $1.4 billion was worth more than ever. 🤷

The day after: from panic to a shrug

So nobody accuses me of cherry-picking – here is the first trading session after disclosure for several companies, including three from the Warsaw Stock Exchange (GPW):

Share price reaction in the first session after the incident was disclosed

Okta, Oct 2023
-20%
SolarWinds, Dec 2020
-17%
Equifax, Sep 2017
-13.7%
CD Projekt (GPW), Feb 2021
approx. -5%
Monnari (GPW), Aug 2021
-2%
Żabka (GPW), Aug 2026
no significant reaction
UnitedHealth, Apr 2024*
+7.5%

* UnitedHealth: pre-market reaction to quarterly results in which the company reported $872 million in Change Healthcare attack costs – the rest of the business buried the incident. Sources: MarketBeat, CNBC, AJC, money.pl, Stockwatch, Interia, FXMAG, The Register.

A few observations from this list:

  • SolarWinds and Okta took the hardest hit because security is their product. SolarWinds sells network management software through which, in 2020, attackers walked into US government departments; the stock fell 17% on the Monday, 23% over the week, and more than a third overall. The company later paid $26 million to settle with shareholders. Okta, which sells login and MFA, lost about 20% in a single day after its October 2023 breach. If you sell trust, the market prices your breach differently.
  • CD Projekt is a textbook example of how to cut SLE. In February 2021 a ransomware group encrypted part of its systems and stole game source code. The company had intact backups, refused to negotiate or pay, and the stock dropped about 5-6% on heavy volume. A side note: investors weren’t happy that the news went out on Twitter rather than via an official exchange filing – communication is part of the bill too.
  • Żabka showed something even more interesting. More on that below, because it’s fresh, Polish and unusually instructive.

Lesson #3: If you’re a big company with a solid business, the market will forgive your breach faster than you can close the regulator’s proceedings. That is the real reason boards don’t panic. Two caveats: when security is your product, the market counts differently (SolarWinds, Okta), and when you have backups and know how to say “no” (CD Projekt), you don’t need anyone’s forgiveness. And one warning: if you’re not listed, you don’t even have that cushion – you just have the bill.

The ones that never got back up ⚰️

Everything above is about companies that survived. Now for the ones that aren’t in Comparitech’s statistics, because they no longer have a share price. It’s not a long list – and that matters, I’ll explain why in a moment – but every entry on it follows the same pattern.

Companies closed or bankrupt after an attack

DigiNotarNL, 2011
Certificate authority. Forged certificates, weak admin passwords, no antivirus.
Bankrupt in under a month
Code SpacesUK, 2014
Code hosting. Attacker got into the AWS console and deleted data along with the backups.
Shut down within days
TravelexUK, 2020
Currency exchange. REvil ransomware on New Year’s Eve, systems down in 30 countries, $2.3M ransom paid.
Administration, 1,300 jobs
VastaamoFIN, 2021
Psychotherapy chain. Therapy notes leaked, patients blackmailed directly.
Bankruptcy, CEO convicted
Lincoln CollegeUSA, 2022
College. Ransomware, 3 months without admissions and fundraising systems.
Closed after 157 years
KNP LogisticsUK, 2023
Haulage, 500 trucks. One guessed password, no MFA, backups destroyed.
Bankrupt after 158 years, 730 jobs
National Public DataUSA, 2024
Data broker. Data of hundreds of millions of people leaked, wave of lawsuits.
Bankrupt within months
7Anna (Rondo, NS Bikes, Creme)PL, 2025
Premium bikes. A customer’s payment redirected to a fraudulent account in Portugal.
Bankruptcy filing
ZEGODE, 2026
Textile finisher, 60 staff. Ransomware, 6 weeks without production while fixed costs kept running.
Insolvency filing

Sources: BBC/Panorama, Infosecurity Magazine, Tom’s Hardware, TechRadar, Malwarebytes, Assured, rp.pl, gdpr.pl (links at the end of the post).

KNP: 158 years, 500 trucks, one password

A story BBC Panorama told in 2025, and one worth retelling at every board meeting. KNP Logistics Group (trading as Knights of Old, founded 1865) had cyber insurance, backups and procedures. In June 2023 the Akira gang guessed one employee’s password – there was no MFA. When the insurer’s crisis team arrived the next morning, everything was encrypted: servers, backups, disaster recovery, endpoints. The demand was estimated at around £5 million; the company didn’t have it. Without financial records there was no way to get a bridging loan or sell the business. In September 2023: administration, 730 redundancies. The former co-owner now tells the media that one password ended 158 years of history.

Travelex, Vastaamo, Lincoln College: three industries, the same ending

Travelex got hit by ransomware on New Year’s Eve 2019, took systems offline in 30 countries and, according to reports, negotiated with REvil, ultimately paying about $2.3 million. Eight months later the company went into administration; the pandemic finished it off, but it was the attack that drained the reserves. Vastaamo, a Finnish psychotherapy chain, lost the therapy notes of about 33,000 patients; the attacker blackmailed them directly. The company went bankrupt in 2021 and its former CEO was convicted for data protection negligence – probably the best illustration of personal liability in Europe. Lincoln College in Illinois survived the Spanish flu, the Great Depression and two world wars, but did not survive three months without an admissions system after a ransomware attack in December 2021. It closed in May 2022, after 157 years.

Poland: 7Anna and a list that keeps growing

Our case isn’t “ransomware” – it’s something even more mundane. 7Anna, a Gdańsk-based maker of premium bikes (Rondo, NS Bikes and Creme brands), filed for bankruptcy in August 2025. Management said it outright: the key blow was an attack in which hackers redirected a customer’s payment to a fraudulent account in Portugal. Classic BEC (Business Email Compromise) – a swapped account number on an invoice after a mailbox takeover. The company already had problems with customers and financing, and “they stole a huge amount” was enough to tip it over. No encryption, no ransom, no data leak – and bankruptcy.

Rzeczpospolita, in the same article, goes on: Herbapol Lublin faced a $900,000 ransom demand (the company didn’t pay and rebuilt its systems on its own – proof that survival is possible), furniture maker Kler took costs of around PLN 800,000, and Polada had 250 GB of data stolen. And beneath that, a whole layer of companies no portal will ever write about, because they have no press office. CERT Polska logged a record 260,783 incidents in 2025; in Sophos’s “Ransomware in Poland 2024” survey, 6% of attacked companies lost all their data and only 14% got everything back. Just across our western border: ZEGO, a German textile finisher from Aschaffenburg, 60 people, 35 years in business – ransomware in March 2026, six weeks without production while fixed costs kept running, and an insolvency filing in July.

Honest about the statistics: the internet is full of “60% of small businesses close within six months of an attack”. Nobody can point to a source for that number and I treat it as an urban legend. The hard data says otherwise: according to Sophos’s State of Ransomware 2026, only about 2% of organizations whose data was encrypted got nothing back at all. Total corporate death is rare. But “rare” is not “impossible” – and it is never random.

Because look at what every company on this list has in common. Not the sophistication of the attack. Backups the attacker could reach (Code Spaces, KNP). One password without MFA (KNP, DigiNotar). Downtime longer than the financial cushion (ZEGO, Lincoln College, Travelex). One hijacked mailbox (7Anna). None of these things costs PLN 300,000 a year to fix. And none of them fits in the “ALE” row of a spreadsheet, because the spreadsheet assumes the company still exists after the incident and can pay the bill.

Lesson #4: The CISSP formula has a hidden assumption: that you survive to bear the loss. For Equifax that’s true. For a company with two weeks of liquidity and backups on the same network as production, ALE isn’t an annual cost – it’s an expiry date.

Poland: fines that don’t hurt (yet)

Now for our own backyard. Because in Poland, the “not worth it” argument sounded exceptionally convincing for years.

  • In eight years of GDPR, Polish companies received 106 fines totalling about €24.9 million. In words: the entire country, every company, eight years – less than one average US breach according to IBM.
  • In 2025 something shifted: UODO, the Polish data protection authority, imposed 32 fines totalling nearly PLN 64.5 million, versus PLN 13.9 million a year earlier. The record is PLN 27 million for Poczta Polska (the national postal service), the highest fine for a private company is PLN 18.4 million for ING Bank Śląski, and McDonald’s Poland got almost PLN 17 million for a leak of employee data at a subcontractor nobody had vetted.

UODO fines – total value per year (PLN millions)

2024
13.9
2025
64.5 (32 fines, +363%)

Largest single GDPR fines in Poland (PLN millions)

Poczta Polska
27
ING Bank Śląski
18.4
McDonald’s PL
~17
Morele.net
3.8

Sources: UODO/PAP (2025 summary), LexDigital, Forsal. For comparison: the average US breach per IBM 2026 is $11.5 million – more than all GDPR fines in Poland over eight years (about €24.9 million).

My favourite Polish case, though, is Morele.net, an online electronics retailer. November 2018: data of 2.2 million customers leaked. September 2019: UODO imposes a PLN 2.8 million fine (partial lack of encryption, no two-factor login, no risk analysis). February 2023: the Supreme Administrative Court overturns the decision on procedural grounds. February 2024: UODO imposes the fine again, this time PLN 3.8 million. The company announces another appeal. It’s 2026, the shop is trading, customers are buying, and the case is in its eighth year.

Morele.net: one fine, eighth year of litigation

Nov 2018
Data of 2.2 million customers leaked
Sep 2019
UODO: PLN 2.8M fine
Feb 2023
Supreme Administrative Court overturns the decision
Feb 2024
UODO again: PLN 3.8M
2026
Another appeal. The shop is trading.

From a spreadsheet’s point of view: a fine spread over eight years, with the option of never paying at all. Hard to find a better argument for “not doing it”.

Likewise ALAB Laboratoria – until 2026 the largest medical data leak in Poland (November 2023, test results, national ID numbers). The company didn’t pay the ransom; UODO opened an inspection in December 2023, has completed it and, according to the latest reports, is still analysing the evidence – no fine yet. Three years after the country’s biggest medical data leak.

August 2026: Żabka and MyDr, a live lesson

Poland recently got two fresh cases that perfectly illustrate both sides of the equation.

Poland, August 2026: two incidents, two scales

PLN 32.6B
Żabka’s valuation in the Couche-Tard takeover offer (31 Jul 2026)
€5,000
the price a hacker asked for code from 89 repositories and 541,000 Jira tickets
18,814,422
national ID numbers in the database stolen from MyDr (over 2 TB, medical data)
~PLN 1,500
what Polish courts have typically awarded one person for a leak of their data

Sources: Niebezpiecznik, Sekurak, CRN, TVN24 Biznes, money.pl, Zaufana Trzecia Strona, Antyweb.

Żabka. On 31 July 2026, Canada’s Couche-Tard announces an offer to acquire Żabka Group, Poland’s biggest convenience store chain, for €7.56 billion. On 2 August a listing appears on a hacker forum: source code from 89 GitLab repositories, 541,000 Jira tickets, 229,000 IT service desk tickets, documentation and production credentials – all for €5,000. In the samples, the same access token appears in every repository dump. The company confirmed unauthorized access to systems used to exchange information with franchisees. And the share price? According to market reports, investors took the news calmly – the takeover offer anchored the valuation. The entire IT estate of a company valued at PLN 32.6 billion, on offer for €5,000, and the spreadsheet says: nothing happened. That is exactly how our equation works in practice.

MyDr. Two weeks later: a software provider for more than 12,000 medical practices (part of the ZnanyLekarz / DocPlanner group). The attackers claim to have data on nearly 19 million Poles – national ID numbers, appointments, prescriptions; the government confirmed the scale and launched a lookup service at bezpiecznedane.gov.pl. The kicker: the hackers contacted the media themselves because MyDr staff weren’t responding to their emails and texts, and they called their proposal “an offer to purchase the results of a security audit”. MyDr isn’t listed, so no share price fell. The UODO inspection will take months. And the victims? The head of UODO reminds them about compensation claims, but courts have so far awarded around PLN 1,500 per person. Now imagine that just 1% of 19 million sue. That’s not a forecast, that’s arithmetic – and it’s the one number in this post at which a board should stop reading and start counting.

There is a “but”, and I wrote about it recently: NIS2 and Poland’s new KSC Act introduce fines of up to €10 million or 2% of turnover, and the head of the organization is personally liable – up to 300% of their salary. It’s the first regulation that writes the CEO’s name into the formula, not just the company’s tax ID.

Lesson #5: The regulator is catching up slowly, but catching up. UODO’s fines more than quadrupled in a year, NIS2 adds personal liability, and after MyDr civil claims stop being theoretical. Companies that “rationally” postponed the topic for years were using a 2019 ARO. It’s no longer that year.

Customers: 78% say they’ll leave, 11% do

And here we get to the heart of it. If neither the market nor the regulator punishes enough, one factor remains: the customer.

In a Ping Identity survey (2018, over 3,000 people in the US, UK, France and Germany), 78% of respondents said they would stop engaging with a brand online after a breach. Sounds like the end of the world for any company.

Except RAND Corporation asked people not “what would you do” but “what did you do”. The result: among people who actually received a breach notification, only 11% stopped dealing with the company, 65% changed nothing, and 77% were satisfied with how the company responded. They got free credit monitoring and moved on.

Customers after a breach: words versus actions

“I would stop engaging with the brand after a breach” (Ping Identity 2018, stated intention)
78%
Actually stopped dealing with the company after a breach notification (RAND 2016, actual behaviour)
11%
Changed nothing (RAND 2016)
65%

Sources: Ping Identity Consumer Survey 2018; RAND Corporation, RR-1187 (2016).

I see it at home too. How many people stopped shopping at Morele after the leak? How many switched labs after ALAB? How many Żabka customers went to a competitor in August? I have no hard data, but I have eyes – and I see the same companies with the same customers.

Lesson #6: As long as customers don’t vote with their wallets, ARO × SLE comes out low in the corporate spreadsheet and the formula works against security. This isn’t a technology problem. It’s a demand problem: security will start paying off exactly when customers start demanding it. Regulation is just a prosthesis for that demand.

So… don’t do security? Three things the formula can’t see 😈

If I stopped here, this text could be attached to a budget-cut justification. So, honestly: here’s where the formula breaks.

1. Averages don’t die. You can.

ALE calculates an average. But the loss distribution has a fat tail – most incidents are a few hundred thousand, but every so often one comes in at $2.9 billion. Equifax and UnitedHealth survived because they had the means. KNP, ZEGO and 7Anna didn’t. For a 50-person company, one three-week outage and one fine isn’t “a loss above average” – it’s the end of the business. Chainalysis, in its report on 2025, shows that attackers have shifted precisely to small and medium businesses.

Ransomware 2025: fewer payers, pricier and more frequent

+50%
attacks year on year (about 8,000 victims on leak sites)
28%
of victims paid – a record low
$12.7K → $59.6K
median ransom paid (+368%)
$1,427 → $439
black-market price of access to a company network (2023 → 2026)

Source: Chainalysis, 2026 Crypto Crime Report; Darkweb IQ.

Your ARO isn’t “once a decade”. Someone just bought a way into your network for the price of a tank of fuel. And as Żabka showed, they’ll sell your entire technical documentation for the price of a used laptop.

2. The cost of safeguards is falling faster than the cost of incidents

Look at the causes again: Equifax – one patch. Change Healthcare – MFA on one server. Morele – no 2FA and no encryption. KNP – one guessed password and backups within the attacker’s reach. 7Anna – one hijacked mailbox. Żabka – one access token repeated across every repository dump. These weren’t sophisticated operations. They were hygiene. Today MFA, offline backups, patching and one test a year cost a fraction of what they did a decade ago, and they cut out most of the realistic scenarios. CD Projekt didn’t pay the ransom because it had backups – and that is the whole difference between “-5% in one session” and KNP. In the opening equation I put PLN 300,000 for a “sensible programme”. The truth is that 80% of the effect comes from the first 20% of that money. The CISSP formula doesn’t tell you to buy everything – it tells you to buy whatever lowers ALE most cheaply.

3. The formula counts the company. The law counts you.

The share price recovers, the fine expires, customers forget. But personal liability of management under the KSC Act isn’t a line in the company’s balance sheet – it’s a line in your household budget. In Finland, Vastaamo’s former CEO was convicted for negligence in protecting patient data. In October 2023 the US SEC charged SolarWinds and, personally, its CISO with misleading investors about the state of its security. A court later dismissed most of the charges, but the signal went out: the name of the head of security in an indictment. The first Polish CEO to pay out of their own pocket will change spreadsheets in a thousand companies faster than ten IBM reports.

Summary: how to count it honestly ✔️

Same formula, honest data

❌ The 2019 spreadsheet
SLE = the statutory fine
ARO = “once in 10 years”
Safeguards = “all or nothing”
Customer = won’t notice
CEO = not liable
Company = still exists after the incident
✔️ The 2026 spreadsheet
SLE = downtime + people + lawyers + lost business + 247 days + lawsuits
ARO = 39% of companies hit by ransomware per year
Safeguards = MFA, backups, patches, testing
Customer = starting to ask
CEO = up to 300% of salary out of their own pocket
Company = only if the backups are out of reach
  1. Keep the formula, fix the data. SLE isn’t the statutory fine but downtime + people + lawyers + lost business + 247 days of clean-up. ARO isn’t “once in 10 years” but 39% of companies hit by ransomware per year. And add the row “can we afford it if it happens this quarter”.
  2. Buy cheap controls with big effect. MFA everywhere, backups the attacker can’t reach from the production network, patches in weeks not months, access tokens with expiry dates, a phone call to verify any change of bank account on an invoice. These are the fixes that were missing in every story in this post.
  3. Check that it really works. Paper accepts anything. KNP had insurance, backups and procedures. A penetration test – a controlled attack on your own systems – is the cheapest way to find out what your ALE really is, and to get the “audit results” from yourself rather than from hackers with a price list.
  4. And as a customer – ask. Do you have MFA? Do you test your security? What happened after your last breach? Every such question is a raise in SLE in someone else’s spreadsheet. Security will start paying off when we start demanding it.

The title of this post isn’t my opinion. It’s the result the calculator gives when you feed it numbers from five years ago. Recalculate with today’s.

Frequently asked questions (FAQ)

Does investing in cybersecurity pay off?

It depends on how you calculate the loss. According to IBM, the average cost of a breach in 2026 is $4.99 million, of which almost two-thirds is downtime, detection and lost business rather than fines. If you plug the full cost of an incident and a realistic probability (39% of companies experienced ransomware within a year) into ALE = SLE × ARO, basic safeguards such as MFA, backups and regular testing pay for themselves many times over.

What are ALE, SLE and ARO?

They’re risk management concepts (from the CISSP curriculum, among others). SLE is the cost of a single incident, ARO is the expected number of incidents per year, and ALE (= SLE × ARO) is the annual expected loss. The rule says the annual cost of a safeguard should not exceed the ALE it reduces.

Does a company’s share price fall after a data breach?

Yes, but usually slightly and briefly. According to Comparitech’s analysis (118 NYSE companies, 2007-2023), shares fall 1.4% on average, bottom out after 41 days and return to pre-breach levels after 53 days. Equifax fell by more than a third after its 2017 breach but was almost back to pre-breach levels a year later and hit record highs in 2021. Companies whose product is security lose more (SolarWinds -17% in a day, Okta -20%). On the Warsaw exchange, CD Projekt lost about 5% after its 2021 ransomware attack, and Żabka in 2026 barely reacted.

Can a company go under because of a cyberattack?

Yes, though it’s rare – according to Sophos only about 2% of organizations with encrypted data get nothing back. Documented failures after attacks include DigiNotar (2011), Code Spaces (2014), Travelex (2020), Vastaamo (2021), Lincoln College (2022), KNP Logistics (2023, 730 jobs after one guessed password), National Public Data (2024), Germany’s ZEGO (2026) and, in Poland, bike maker 7Anna (2025, after a redirected payment). The common denominator: backups within the attacker’s reach, no MFA and downtime longer than the company’s liquidity.

What are the penalties for a data breach in Poland?

Under GDPR: up to €20 million or 4% of global turnover. In practice, in 2025 UODO imposed 32 fines totalling about PLN 64.5 million; the record is PLN 27 million (Poczta Polska) and, for a private company, PLN 18.4 million (ING Bank Śląski). In addition, since April 2026 the amended KSC Act (Poland’s NIS2 implementation) applies: fines of up to €10 million or 2% of turnover and personal liability of the head of the organization up to 300% of their salary. Victims can also pursue civil claims – court awards so far have typically been around PLN 1,500 per person.

How many customers leave after a data breach?

Fewer than say they will. In surveys, as many as 78% say they would stop engaging with a brand after a breach (Ping Identity, 2018), but RAND’s study of people who actually received breach notifications found that only 11% cut ties, and 65% changed nothing.

Sources 📚


Want to know what your ALE really is, rather than what a 2019 spreadsheet says? A penetration test is a controlled attack on your systems, after which you get a concrete list: what’s broken, how badly, and what to close first – often for a fraction of the cost of a single day of downtime. Get a quote in 2 minutes with the calculator or drop me a line, before someone else offers you the “audit results” – for €5,000. 🔓

Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *