No single number captures the real cost of a cyberattack
When people talk about the cost of a cyberattack, they usually picture one number: the amount of a ransom demand, or the bill for the technical work needed to get systems running again. That picture is misleading. For a Moroccan SME, a cyberattack sets off a chain of costs that unfold over time — some immediate and easy to spot, others more diffuse and sometimes only visible months later. Understanding this cost structure, rather than chasing a single headline figure, makes it easier to judge what a cybersecurity investment can actually prevent. It also reframes the question from "how much does it cost to protect ourselves" to the more accurate one: "how much would it cost not to have done so."
Direct costs: the immediate bill
Direct costs are the ones identified fastest after an attack. First come investigation and recovery expenses: bringing in specialists to understand how the intrusion happened, what was compromised, and rebuilding clean systems from backups or fresh installs. In a ransomware case, attackers sometimes demand a ransom; paying it is generally discouraged, since there's no guarantee the data will actually be recovered, and payment can encourage further attacks without fixing the underlying vulnerability. On top of that come the costs of restoring systems and data, and, if customer or employee personal data was involved, legal and compliance costs may follow, particularly around obligations under Law 09-08 on personal data protection.
Indirect costs: often heavier, and slower to fade
Indirect costs are harder to put a number on, but they often weigh more over time. The first is business interruption: while systems are down, orders can't be processed, sales teams can't reach their tools, and invoicing grinds to a halt. For an SME, even a few days of downtime can mean a meaningful loss of revenue. The second is trust: clients or partners who learn of an incident may hesitate to keep sharing data or placing orders, especially in sectors where confidentiality matters. That erosion of trust can show up as unrenewed contracts or lost tenders, long after the technical systems have been fixed. Finally, the time internal teams spend managing the crisis — instead of doing their normal jobs — is a real cost too, one that rarely shows up on an invoice but is very real nonetheless.
What comes after: insurance and regulatory exposure
A cyberattack doesn't end the day systems come back online. If the company holds cyber insurance, filing a claim can lead to higher premiums at renewal, or stricter terms going forward. Without that kind of coverage, the full cost stays on the company's books. On the regulatory side, if personal data was exposed, the company may face notification obligations and risk scrutiny or sanctions if it hadn't put reasonable protective measures in place under Law 09-08. These consequences, less immediate than the technical outage itself, are still part of the real cost of an incident — and are far better anticipated in advance than discovered afterward.
Reframing cybersecurity as risk management
Seen this way, cybersecurity stops being a line item on the IT budget and becomes a risk-management tool, much like fire insurance or liability coverage. The goal isn't zero risk, which doesn't exist, but reducing the likelihood of a serious incident and limiting its scale if one happens anyway. For a Moroccan SME, that usually means simple, proportionate measures: regularly tested backups, better-controlled access, staff awareness, and a clear plan for what to do if something goes wrong. EBH Security can help businesses assess their current exposure through a free audit, to identify priorities before an incident forces the issue.