Ransomware is not confined to large corporations and public institutions. Danish SMBs can also be affected by attacks that encrypt data, steal information, and disrupt operations. The ransom demand is only one possible cost; recovery, downtime, external assistance, and follow-up work can weigh more heavily.
The numbers behind attacks
There is no single public, documented average cost or downtime that applies specifically to Danish SMBs. The outcome depends on the scope of the attack, the organization's dependencies, its incident response plan, the quality of its backups, and how quickly systems can be safely validated and restored.
As an international benchmark, Sophos' State of Ransomware 2026 measured an average recovery cost of USD 1.7 million. The survey was conducted from January to March 2026 among 2,158 IT and cybersecurity leaders in organizations with 100–5,000 employees across 17 countries and concerned experiences from the previous 12 months. It is therefore a global survey benchmark, not a price estimate for a Danish business with 20–100 employees.
In the Verizon 2026 Data Breach Investigations Report, about 96% of ransomware victims in cases where organization size was known were SMBs. That finding documents the relevance of the threat to smaller organizations, but it does not state what an attack costs a Danish SMB.
Should you pay? The official ransomware guidance, now published by the Danish Resilience Agency, recommends not paying a ransom. Payment does not guarantee that the organization receives working decryption keys or that the attacker actually leaves the systems. Read the official guidance.
The hidden costs: much more than the ransom
When businesses calculate the consequences of an attack, they typically overlook a long list of costs that quickly accumulate:
- Lost revenue during downtime: A webshop, a production facility or a law firm that cannot access its systems loses revenue directly for every day that passes.
- IT investigation and restoration: Systems must be examined, rebuilt, validated, and monitored, and the attacker's access paths must be closed. The price depends on the scope, specialist hours, and required replacement equipment.
- Legal and compliance consequences: If the incident is a personal data breach, the controller must notify the Danish Data Protection Agency without undue delay and, where feasible, within 72 hours, unless it is unlikely to pose a risk to individuals' rights or freedoms. See the Danish Data Protection Agency's guidance.
- Reputational damage: Customers and business partners lose trust when they hear that the company has been hit. That effect is difficult to quantify, but can be the most long-lasting.
- Changed insurance terms: An incident can affect the insurer's risk assessment, premium, coverage, or security requirements at renewal.
An illustrative calculation, not a market statistic
Consider an accounting firm whose client files, accounting data, and email archives become unavailable. A useful calculation starts with the firm's own figures: lost contribution margin during the actual downtime, internal staff time, incident response and legal assistance, replacement equipment, customer communication, and subsequent security work.
The calculation should test several scenarios rather than assume one universal duration: how much does one hour, one day, or several days without each critical system cost? Which services can continue manually, and which customers or contractual deadlines are affected? This produces a business-specific estimate instead of an unsupported industry average.
The same applies to prevention: its price depends on the number of users and devices, data volume, recovery requirements, existing licenses, and service level. A concrete risk assessment and quotation are needed before prevention and expected loss can be compared fairly.
Ransomware risk should be included in the organization's contingency planning. Tested backups, clear roles, incident procedures, endpoint protection, patching, and employee awareness reduce both the likelihood and the consequences. Contact us if you would like a no-obligation assessment of your current security posture.