Cyber security Cyberattack
10.03 2026

For a small business, a cyber incident can cost nearly €13,000 per day

Friday evenings, weekends, and holiday periods are the most attractive times to carry out cyberattacks, as vigilance and organizational readiness are at their lowest. Even on a day off, a company must respond quickly to a cyber incident, because a “mañana-style” delay can deal a serious financial blow, notes Mihkel Kukk, Head of Cybersecurity at KPMG Baltics.

According to Kukk, the following scenario is very common. It’s a Friday evening, the office is empty, the weekend is ahead, and you finally feel like you can switch off from work. Then suddenly, a message arrives—not necessarily on your phone, but on a colleague’s. A business partner has sent updated payment details. The message is marked “urgent.” You start wondering: is this notification real? At first glance, everything seems logical—the tone is correct, the signature is right, even the previous conversation is there. Only one detail is different—the bank account number.

“This is exactly where the biggest vulnerability lies for small and medium-sized businesses. Attacks don’t come when everyone is at their desks, calmly analyzing the situation. You’ve probably noticed that phishing emails about ‘updating bank details’ often arrive during holidays. Attacks come when things are quiet—on Friday evenings, weekends, and during vacations. Not because it’s romantic, but because it’s effective. Two questions determine how big this story becomes: does someone notice the alert immediately, and does someone act immediately—or only on Monday?” says Kukk.

Often, such incidents begin in a very ordinary way: someone enters login credentials into what appears to be a legitimate page. Sometimes it’s a fake login page, sometimes a third-party integration, sometimes just one wrong click caused by fatigue. An attacker doesn’t need to break down a “thick door” if they can simply get the key from the user.

Once access is gained, the next steps are not taken loudly but quietly. Email forwarding rules are set up, alerts are hidden, communication is monitored. The attacker waits for the right moment—one that fits naturally into the company’s workflow—and then sends “updated payment details” or a “payment requiring urgent confirmation” to a partner or customer. Very often, it doesn’t look like a technical or business crisis—just a normal workday.

Is your incident response plan actually thought through?

According to Kukk, this leads to the first important realization: “having tools” does not mean “having protection.” Many small and medium-sized companies rely on the Microsoft ecosystem as the backbone of their operations—identity, email, devices, cloud. Security features are often available as well. But a tool alone is like a smoke detector with a battery installed—if nobody is there to hear it, it doesn’t help. The tool may raise an alert.

“What happens next determines whether this is a real attack, how critical it is, and whether immediate action is taken to stop the threat. Do we lock the account, terminate sessions, remove malicious rules, restore access in a controlled way, and limit damage before money leaves the bank account?” Kukk explains.

If you want to understand as a leader whether such an incident is just an inconvenience or a serious financial hit, a simple exercise can help: assign a price tag to potential downtime—not to create fear, but to make decisions proportional to real risk.

What does downtime cost?

Let’s start with a formula:
Downtime cost €/day ≈ (annual revenue ÷ 12 ÷ 22) + [critical employees × (gross salary × 1.35 ÷ 22)]
If the impact is customer-critical (sales/payments/deliveries halted), add a conservative buffer: ×1.5.

Based on this, consider a simple example. A company has annual revenue of €2 million. Think about how many employees are critical but unable to work during downtime. With an average gross salary of €2,500, the revenue loss component is €2,000,000 ÷ 12 ÷ 22 ≈ €7,576 per day. Salary costs are roughly: 6 × (€2,500 × 1.35 ÷ 22) ≈ €920 per day.

“Even this simple calculation shows that one day of downtime costs about €8,500, and if there is direct customer impact, it can conservatively rise to nearly €13,000 per day. This is why ‘let’s look at it on Monday’ is not a neutral decision—it has a very specific price tag,” Kukk emphasizes.

In public discussions, SOCs (Security Operations Centers) and 24/7 monitoring are increasingly highlighted—and rightly so. Many cybersecurity service descriptions stress the same principles: continuous monitoring, early detection, and immediate response. However, for small and medium-sized companies, the question is usually not whether someone is “watching a screen.” The question is whether you have the team, processes, and automation to quickly answer three key questions: is it real, what is the impact, and what do we do immediately?

Managed cybersecurity services help defend against complex attacks

The logic of MDR (Managed Detection and Response) is built precisely to go beyond simply “passing on alerts.” It combines 24/7 threat detection and rapid response with clear roles and escalation processes, ensuring incidents move from identification to containment, recovery, and lessons learned.

Instead of just “collecting logs,” the approach is methodical: mapping business-critical services, analyzing architecture and attack paths, and aligning detection with real risks in your environment. Based on KPMG’s experience, this helps avoid two common extremes: “silence” (no detection) or “noise” (too many false positives).

It’s also important that detection is not a one-off project. Managed cybersecurity treats detection like product development: rules, playbooks, and procedures evolve, expand, and become automated over time. Scalability matters too—covering hundreds of rules and leveraging automation ensures fast response even at inconvenient times. While the default focus is often the Microsoft ecosystem, the same operational capability can be applied to other XDR/SIEM solutions if needed.

Returning to that Friday evening scenario, the real question is not whether such incidents can happen—yes, they can. The real question is whether your organization has a clear, tested, and 24/7 operational capability to respond before the damage reaches your bank account, customers, or production. If you don’t have that capability today, the good news is that you don’t need to build it from scratch or place a 24/7 burden on your internal team.

Mihkel Kukk

Cybersecurity Strategic Advisor

Neglecting cybersecurity can cause forced downtime and give competitors an advantage

Organizations can no longer view cyber risk as a separate issue; it is an integral part of the b..

Cyber security

KPMG: A properly selected information security standard serves as a quality mark for partners

Companies that rely on external service providers for data processing increasingly face a key que..

Cyber security

A threefold increase in cyber incidents creates a pressing need for a Chief Information Security Officer

Over the past few years, the number of cyber incidents in Estonia has tripled, and this worrying..

Cyberattack Cyber security

Why Purple Teaming is the Missing Link in Modern Cybersecurity

In today’s cybersecurity landscape, most organizations are caught between two realities: they kn..

Cyber security

Reflections from the Field - A Red Team’s Perspective on Cybersecurity in Estonia

Over the past several years, our red team has conducted extensive offensive security assessments..

Provide a safe and sustainable business environment for your company. We help build a resilient and reliable digital landscape, even in the face of changing threats.

KPMG Baltics OÜ

+372 626 8700
cyber@kpmg.ee
Ahtri 4, 10151 Tallinn, Estonia
${item.title}
KPMG Baltics KPMG Global Privacy KPMG IT Audit
Email again:

Analysis of employee awareness

Analysis of employee awareness focuses on mapping the skills and increasing the competencies of the weakest link in cyber security: the users, the employees.

Email again:

Threat assessment

Threat assessment is a tactical and technical service that allows a company to get a quick overview of external threats.

Email again:

Maturity assessment

Maturity assessment helps plan IT investments and design further steps to mitigate vulnerabilities and ensure better security.

Email again: