One Monday morning, Daniel A. walks into his workshop and finds the machines at a standstill. The supervision screens show a message he doesn't understand, and Marc K., his part-time IT lead, is already on the phone, white as a sheet. That morning, nobody yet knows what the cyberattack will really cost — and it's precisely that uncertainty that hurts the most.
The cost of a cyberattack is far more than the ransom
When people talk about a cyberattack, they picture a ransom to pay: a sum demanded by attackers to restore access to your files. That's the image of ransomware (a program that encrypts your data, makes it unreadable, then demands a payment in exchange for the key). But in a manufacturing SME like Daniel A.'s, the ransom is almost never the heaviest cost item.
In a machining company, part of the system doesn't look like office computers: it's the machines themselves, their controllers and the workstation that drives them — what we call OT ("operational technology", as opposed to office IT). That supervision workstation often runs on an old system that's no longer updated, "because the machine software won't support anything newer". And very often, the workshop and the offices share the same flat network. The result: a booby-trapped email opened in accounting can, step by step, reach the machine that does the cutting. That's what turns an ordinary IT incident into a production stoppage.
Once the workshop is at a standstill, the bill builds up quietly, across several items you never see coming. This is what makes the cost of a cyberattack so deceptive: the figure that makes the headlines — the ransom — is almost always the smallest slice of the total. The rest doesn't show up anywhere on Monday morning; it reveals itself day after day, as the company tries to get back to normal. For Marc K., who "puts out fires" on his own, it's also an invisible burden: every hour spent rebuilding is an hour not spent on the rest of the business.
The first item is production downtime. A machining line that isn't running means orders falling behind, deadlines promised to a client that won't be met, staff paid to wait. That cost isn't measured in hours but often in days: the time to understand, to clean up, then to get everything running again. For a workshop, it's almost always the dominant item — well ahead of the ransom.
The second is technical recovery. Getting the servers back up, reinstalling the workstations, rebuilding the data from backups — when they exist and actually work. Many SMEs discover at that very moment that their backups had never been tested, or that they were plugged into the same network as everything else, and were therefore encrypted too. All the while, the external provider's bill keeps ticking.
The third item is the quietest and the most lasting: trust. A client who learns that its subcontractor was paralysed starts to wonder whether its technical drawings — its intellectual property — are still confidential. It may demand guarantees, push back an order, or simply look elsewhere. That cost appears on no invoice, but it is paid over the months that follow.
Finally there's the regulatory dimension. If personal data is affected — a customer list, HR records — the nFADP (Switzerland's data protection act) expects the controller to take appropriate security measures and, where a breach is likely to result in a high risk to individuals, to notify the Federal Data Protection and Information Commissioner (FDPIC). Handling that in the middle of a crisis, without having thought about it beforehand, adds time and stress at a moment when both are already scarce.
None of these items can be priced precisely in advance, and that's exactly why it's better to think in orders of magnitude than in promises. What we can say without being wrong is the ranking: in an SME that produces, the stoppage weighs the most, recovery comes next, and lost trust takes the longest to rebuild. Knowing that ranking already tells you where to focus your efforts before an incident, rather than discovering everything at once on the day it hits.
In plain terms (Camille). The right question isn't "how much is the ransom", but "how much does a day when nothing runs cost me, multiplied by the number of days I need to get going again". That single sentence puts the risk back in its proper place — and it takes no technical skill to answer.
Key takeaways
- The real cost of a cyberattack is the sum of several invisible items: production downtime, getting back on your feet, customer trust, legal obligations. The ransom, when there is one, is often just the tip of the iceberg.
- A manufacturing SME is especially exposed because its workshop and its office IT often share the same network: an infection that starts on an email in accounting can end up on the machine that does the cutting.
- This cost isn't inevitable. You never bring it down to zero, but you make it far more bearable by preparing, in calm conditions, for what plays out under pressure.
Steps to put in place this week
1. Put a figure on a day of downtime
Take ten minutes with your production manager. How many orders does a day without the workshop push back? How many people end up waiting? That amount, even a rough one, in francs, is your real exposure. It turns an abstract risk into a business decision — and it needs no IT tool.
2. Ask to see a restore, not a backup
"We have backups" means nothing until you've checked that you can actually rebuild from them. As a manager, you don't have to do it yourself: simply ask your IT lead or your provider to show you a file that has genuinely been restored, and how long it took. The answer — or the lack of one — will tell you where you stand.
3. Write your crisis contact list before the crisis
On a single page: who to call if everything stops. Your IT provider, your insurer (with the policy number), the Federal Office for Cybersecurity (NCSC), which receives incident reports, and the FDPIC if personal data is involved. Hunting for these numbers during the incident means losing the hours that cost the most.
Where do you really stand?
These three steps don't remove the risk — nothing does — but they move the cost of a cyberattack from the unknown to the manageable. One honest question remains: beyond these first steps, where is your organisation genuinely solid, and where does it rest on the hope that "it won't happen here"?
That's exactly what the Cyber Passport self-assessment lays out, question by question, without jargon. It certifies nothing and doesn't declare you "protected": it shows you in black and white your strengths and your blind spots, in a report you can share with a client or an auditor. Enough to decide, calmly, what you prepare before the next difficult Monday morning.



