Ransomware is no longer confined to large corporations and public institutions. Every week, Danish SMBs are targeted by attacks that encrypt critical data and paralyze entire operations, sometimes for weeks. Yet many businesses underestimate the cost of an attack because they only consider the ransom itself. The reality is far more expensive.

The numbers behind attacks

According to reports from both the Danish Center for Cyber Security and analyses from the Nordic insurance industry, the average downtime after a ransomware attack is 21 days for a medium-sized business. That is three weeks during which production is halted, customers are kept waiting, and employees cannot do their jobs.

The total costs for a Danish SMB with 20–100 employees typically land in the range of 1–3 million DKK. And that is without paying any ransom. Businesses that choose to pay do not necessarily fare better: Sophos' global studies show that fewer than 8% of those who pay recover all of their data, and many are hit again within 12 months.

Did you know? The average cost of recovering from a ransomware attack has more than doubled globally since 2021 and is now approaching 2.7 million USD for medium-sized businesses, and that is excluding any potential ransom (source: Sophos State of Ransomware 2024).

The hidden costs: much more than the ransom

When businesses calculate the consequences of an attack, they typically overlook a long list of costs that quickly accumulate:

  • Lost revenue during downtime: A webshop, a production facility or a law firm that cannot access its systems loses revenue directly for every day that passes.
  • IT cleanup and restoration: Even with a good backup, it can take days to restore servers, validate data and ensure the attacker's access paths are closed. External assistance from an incident response team typically costs 10,000–25,000 DKK per hour.
  • Legal and compliance consequences: If personal data has been compromised, the attack must be reported to the Danish Data Protection Agency (Datatilsynet) within 72 hours. Fines for non-compliance with GDPR can amount to up to 4% of global revenue.
  • Reputational damage: Customers and business partners lose trust when they hear that the company has been hit. That effect is difficult to quantify, but can be the most long-lasting.
  • Increased insurance premiums: Cyber insurance policies rise significantly in price or lapse entirely after a documented attack.

A realistic scenario: The accounting firm that came to a standstill

Imagine a Danish accounting firm with 15 employees. One Monday morning, they discover all files are encrypted: an employee clicked on an attachment Friday afternoon. The attack spread silently over the weekend.

The firm has no offsite backup and no written recovery plan. The result: 14 days of total downtime while an external IT partner attempts to reconstruct data from fragmented local copies. Two clients terminate their agreements. The total bill ends up at 1.4 million DKK, including external IT assistance, lost fee income, legal advice and GDPR notification.

What would prevention have cost? A proper backup solution with offsite replication, endpoint protection, and basic employee awareness training would have cost less than 50,000 DKK per year. That is a 28x difference.

Ransomware attacks are rarely a matter of if. They are a matter of when. Businesses that fare best are those that have invested in solutions and processes before an attack occurs. Feel free to contact us if you would like a free assessment of your current security posture.