A data breach at a Tri-State small business almost never costs the millions that national headlines quote. Reported cybercrime losses average roughly $27,100 per complaint in New York and about $32,000 in New Jersey. Notification duties, downtime, and stolen funds drive that bill, not fines.
Every year a report lands carrying a number so large it stops being useful.
IBM’s 2025 Cost of a Data Breach study put the United States average at $10.22 million, an all-time high, while the global average actually fell to $4.44 million. Both figures are real. Both are also drawn from a sample where one breached hospital network or regional bank pulls the mean somewhere a 25-person business in Rockland or Bergen will never go.
Owners read $10.22 million, decide the number is absurd, and quietly file the whole subject under things that happen to other people.
Bad statistic. Worse lesson.
The useful question is narrower. What does an incident actually cost a business with 5 to 60 employees, operating in New York or New Jersey, with real customers who legally have to be told? That number exists. It sits far below $10.22 million and well above what most owners guess. The preventive side of this math lives on our cybersecurity services page. This piece is about the invoice.
The Number Everyone Quotes Is Not Your Number
Enterprise breach studies survey enterprises. That sounds obvious written down, and it gets forgotten constantly. Check the sample.
A study built from organizations with compliance departments, breach counsel on retainer, and tens of millions of records will produce a mean shaped by those organizations. Regulatory penalties, class-action exposure, and brand damage across a national customer base are genuine costs at that scale, and they are most of why the American figure runs more than double the global one. A 30-person accounting practice in Westchester carries none of that structure, which cuts both ways. Smaller exposure. Also no in-house team, no legal budget, and nobody whose job is to answer the questions that arrive in week one.
So the enterprise number overstates the damage and understates the disruption. What you want instead is data counted per incident, at the size incidents actually happen.
What the FBI’s Own Numbers Say About New York and New Jersey
The FBI’s Internet Crime Complaint Center publishes exactly that. Its 2025 Internet Crime Report logged 1,008,597 complaints and $20.877 billion in losses nationally, a 26% jump in dollars over the prior year, at an average loss of $20,699 per complaint. Every complaint is one victim reporting one incident. No weighting toward the Fortune 500.
Break it out by state and the Tri-State picture gets specific.
| Reported to the FBI in 2025 | Complaints | Total losses | Average per complaint |
|---|---|---|---|
| United States | 1,008,597 | $20.877 billion | $20,699 |
| New York | 45,255 | $1,226,307,877 | about $27,100 |
| New Jersey | 20,648 | $660,411,901 | about $32,000 |
The averages are simple division on the FBI’s own published tables, so check the arithmetic yourself if you like.
Two caveats worth stating plainly, and they cut in opposite directions. IC3 counts only what victims actually reported, so the real totals run higher than these, and its complaint pool mixes individuals in with businesses, so neither state average is a clean business-only figure. Directionally, still useful.
Now look at New Jersey again.
It files fewer than half as many complaints as New York and still ranks fifth in the country for total dollars lost, sitting one place above Arizona and well above states that report far more incidents. New Jersey is sixteenth nationally by complaint volume and fifth by money. On losses per 100,000 residents it ranks sixth, ahead of New York at tenth. Fewer reported incidents, bigger ones.
Both states run above the national average per complaint. New York by roughly 31%, New Jersey by roughly 55%. If you operate here, the national average is the floor of your expectations rather than the middle.
New York Gives You Thirty Days. New Jersey Wants a Call First.
Here is the part that genuinely separates a Tri-State breach from a breach anywhere else, and almost nobody prices it in advance.
New York changed its breach law. Under General Business Law section 899-aa, notification to affected residents “shall be made within thirty days after the breach has been discovered.” That fixed deadline took effect on December 21, 2024, replacing the older and much softer standard of acting without unreasonable delay. A second change followed on March 21, 2025, folding medical information and health insurance information into the definition of private information, which pulls in a lot of businesses that assumed the statute never touched them. Separately, you notify the State Attorney General, the Department of State, and the Division of State Police, plus the Department of Financial Services if you are regulated by it.
Thirty days is not long. It starts at discovery. Discovered by whom? By the business, which in practice means whoever first realizes something is wrong, not a security team watching alerts.
New Jersey works differently. Under N.J.S.A. 56:8-163 there is no fixed day count for customers; disclosure happens “in the most expedient time possible and without unreasonable delay.” The catch sits elsewhere in the statute. A business must, “in advance of the disclosure to the customer,” report the breach to the Division of State Police in the Department of Law and Public Safety. Law enforcement hears about it before your customers do, and the New Jersey Cybersecurity and Communications Integration Cell handles that intake.
Now put a business in Paramus with clients in White Plains into that picture. Both obligations fire simultaneously. Two states, one mailing list. One clock, one sequencing rule, two sets of regulators, and that list has to be split by state before a single letter goes out. Nobody budgets for the lawyer hours that sorting takes, and that is usually the first surprise invoice.
We covered what New York expects of your security program before anything goes wrong in the piece on what the NY SHIELD Act actually requires of a 20-person business. Worth reading alongside this one, because the SHIELD obligations are what a regulator measures you against after the notification letters land.
Where the Money Actually Goes
Strip out the enterprise line items and a small business breach bills in roughly six places. Six, not one.
- Forensics. Somebody has to establish what was reached and whose records were in it. You cannot write an accurate notification letter without this, and you cannot legally skip the letter.
- Notification itself. Printing, postage, and credit monitoring for affected people. It scales with your customer list, not your revenue, which is why a small firm holding a lot of records gets hit disproportionately.
- Downtime. The quiet one. Days when nothing bills, staff sit idle, and the phones still get answered by people who cannot access anything.
- Money that simply leaves. Business email compromise accounted for $3.05 billion across 24,768 complaints in the FBI’s 2025 data. That works out near $123,000 per reported case, and it is the single most expensive way a small business loses money to a keyboard. Our walkthrough of how a fake CEO email costs real money covers the mechanics.
- Legal review of the two state playbooks above.
- Insurance. The deductible now, the premium later.
Ransom demands sit slightly apart from that list. Verizon’s 2026 Data Breach Investigations Report, built from more than 22,000 confirmed breaches, found ransomware present in 48% of them, up from 44%. The encouraging part is that 69% of victims did not pay at all, and the median payment among those who did fell to $139,875 from $150,000. Refusal is becoming normal. What changed is not attacker behavior but preparation, because an organization that can restore from a clean, recent, tested copy has already removed the only pressure the encryption ever created, and the negotiation stops being a negotiation. It only works if the restore works, which is the entire argument for treating tested backup and recovery as a financial control rather than an IT chore.
Verizon also notes small organizations are disproportionately hit by ransomware while working with fewer resources than the enterprises in the same dataset. Same threats. Smaller bench.
What This Looks Like Across Rockland, Westchester, and Bergen
A few patterns hold across the businesses in this market, and they are about the shape of the business rather than the county line.
Most sit under sixty people. Professional practices, medical and dental offices, contractors, accounting firms, small manufacturers. Very few have anyone internal running IT, which means the person who can answer a forensic question works somewhere else and has other clients. That is a scheduling problem on a normal Tuesday. Inside a thirty-day statutory window it becomes a cost.
The second pattern is the state line, and it catches people. Plenty of businesses here bill across it without thinking about it, because the Tri-State area functions as one market even though it is not one legal jurisdiction. A Bergen firm with Westchester clients holds New York residents’ private information. The thirty-day clock applies to those records regardless of where the office sits. Same in reverse, and the trigger is the residency of the person whose data was exposed rather than the location of the server it sat on, which is why one incident can put a single business under two different notification regimes simultaneously. That surprises people.
Third, and this is the one worth acting on now, the expensive part of a breach is decided long before the breach. Whether logs exist. Whether a restore has been tested this year. Whether anyone can produce a list of who had access to what. Those three answers set the forensics bill and the notification scope, and they are cheap to fix in advance and brutally expensive to reconstruct afterward. In over 20 years working these three markets, that ordering has not changed.
What Owners Ask After the First Scare
What should a business our size actually budget for this?
We’re a 20-person shop. Are we really a target?
Doesn’t our cyber insurance just cover all of this?
We have customers in both New York and New Jersey. Which law applies?
When exactly does the thirty-day clock start?
Is any of this cost avoidable once it has already happened?
A free security risk assessment shows which records you hold, who can reach them, and whether a restore works today. No obligation, and the findings are yours either way.
