Cyber attacks costing SMEs full working week in operational disruption
Successful cyberattacks cost affected SMEs an average of almost a full working week in operational disruption, with an average of 34 hours lost, a new report published on Tuesday said. Picture: Alamy
Successful cyberattacks cost affected SMEs an average of almost a full working week in operational disruption, with an average of 34 hours lost, a new report published on Tuesday said.
The Hiscox Cyber Readiness Report 2026 said 36% of SMEs who suffered a cyber attack over the past year lost business opportunities or partnerships following the outage, while 34% delayed growth, expansion or new business initiatives. The research carried out among cybersecurity decision-makers in 300 Irish businesses with fewer than 250 employees, found that businesses experiencing a successful attack reported an average of 34 hours of operational disruption across the previous 12 months.
Read More
“Cybersecurity is no longer simply a technology issue. For an SME, losing almost a full working week to disruption can mean delayed orders, missed opportunities, pressure on cash flow, and valuable management time being diverted away from customers and growth," said Hiscox Ireland senior developent underwriter Ciara Weldon.
Some of the best known companies operating in Ireland have suffered cyber attacks over the past year. Stryker, which employs over 4,000 employees in Cork alone, suffered a major attacktarget="_blank" rel="noopener noreferrer"> earlier this year, while Boston Scientific, which employs more than 7,000 people in Ireland, was hit by a cyber outage just last month.
But an attack on an SME can be catastrophic to a business, said Ms Weldon. “Smaller businesses often face many of the same sophisticated threats as larger organisations, but without the same depth of in-house cybersecurity, fraud-prevention, or compliance resources. That makes preparation, clear responsibilities, and access to the right support particularly important.”
The Cyber Readiness Report 2026 was conducted by Wakefield Research for specialist insurer Hiscox, taking responses from 6,800 cybersecurity decision-makers and subject-matter experts in businesses with fewer than 250 employees across Ireland, the UK, the US, France, Germany, Spain, Portugal, Italy, the Netherlands, and Belgium.
Across the sample of 300 Irish companies surveyed for the report, 48% of SMEs ranked reputational damage or loss of customer trust among their greatest business risks from a cyber attack. Operational downtime or business interruption and supply-chain or third-party disruption from a cyber attack were each identified as further key concerns, along with regulatory compliance.
“The wider impact of an attack can continue long after systems are restored. A cyber incident can affect financial performance, business relationships, customer confidence and the ability to move forward with new investment or expansion," said Ms Weldon.
“That is why cyber resilience needs to be treated as a core business discipline rather than an issue owned solely by the IT department.”
The report found that 64% of respondents now have cyber insurance to deal with the financial implications of an attack, compared to 40% when the report was first compiled in 2017.
"Ten years ago the question was how to stop cyber attacks. Today the question is how organisations continue to operate and grow despite them," the report said.
"From our experience insuring cyber risk, the strongest organisations are not necessarily those that suffer the fewest incidents. They are the ones that are prepared, respond decisively, and learn from disruption when it happens."




