How to calculate the cost of a phishing incident for clients

Calculate the real cost of a phishing incident for clients in 2026 - labor hours, downtime, remediation, and notification costs, step by step.

Most MSPs quote a flat number for phishing damage and hope the client doesn't ask how they got it. This guide walks through the actual math: labor hours, downtime, remediation, and the client-specific multipliers that turn a generic scare number into a defensible figure.

Key takeaways

Why this matters

Clients don't argue with a story. They argue with a number that feels made up. If your phishing-cost estimate is a copy-pasted stat from a vendor whitepaper, the first skeptical CFO in the room will ask why their 15-person firm should care about a global average, and you won't have an answer.

A calculation built from the client's own headcount, hourly rates, and systems survives that question. The difference between a credible number and a guessed one is entirely in the inputs. Get those right in 2026 and the same framework works whether you're pricing a 10-seat dental practice or a 200-seat logistics firm.

What you will need

The steps

1. Reconstruct the incident timeline

Start with hours, not dollars. Map out when the phishing email landed, when someone clicked, when IT was notified, and when the account or system was contained. A credential-harvesting click that sits undetected for six hours costs dramatically more than one caught in six minutes.

For clients with no incident history, use a simulated phishing campaign result as the stand-in timeline - most platforms log click-to-report time automatically. This step alone usually surfaces the biggest number in the whole calculation: detection lag.

Common mistake: starting the clock at "when IT found out" instead of "when the email was clicked." That gap is often the most expensive part of the incident and it's the part awareness training directly shortens.

2. Tally direct labor hours

List every role that touched the incident: helpdesk resetting credentials, IT isolating a device, an admin re-issuing MFA tokens, a manager writing the internal notice. Multiply hours by each role's actual loaded hourly rate, not a flat number.

A typical mid-size SMB response involves 3-5 people across 30-50 combined hours once you count triage, containment, and the inevitable follow-up meetings. At a blended rate of $65-90/hour, that's $2,000-$4,500 in labor alone before anything else is added.

Common mistake: forgetting the manager and executive hours spent in status meetings. Those hours count and they're often billed at the highest rate in the building.

3. Price in downtime and lost productivity

If a compromised account triggers a system lockout, quantify the hours that department couldn't work. A finance team locked out of its email for four hours during a payment run isn't just an IT problem - it's four hours of the whole team stalled.

Multiply affected headcount by hours down by their hourly rate. For a 5-person team down for half a day, that's another 20 labor hours added straight to the total, separate from the IT response hours in step 2.

4. Add remediation and forensics costs

This is where numbers jump. If the incident requires a forensic review, password resets across the domain, or a third-party consultant, those invoices land on top of internal labor. Even a modest external remediation engagement runs into four figures for a small client.

This is also the step where you can show the client the return-on-investment case for anti-phishing software - remediation costs are the clearest before/after comparison once training or simulation is in place for a full cycle.

Common mistake: quoting remediation as a flat "worst case" number pulled from a different client's incident. Every environment is different - a client on a modern identity platform recovers faster than one still running legacy on-prem mail.

5. Factor in regulatory and notification costs

If the incident touches personal data, notification obligations kick in depending on the client's sector and the scale of exposure. Even without a formal breach, drafting client communications and a board update takes real hours from someone senior.

For regulated clients - healthcare, financial services, legal - this line item can outweigh the technical remediation cost entirely. Build it as its own row, not folded into "remediation," so the client sees exactly what compliance exposure adds.

6. Turn the total into one client-ready number

Add every row - labor, downtime, remediation, notification - into a single annualized figure if the client has had more than one incident, or a per-incident figure if this is their first. Round to a number that reads as calculated, not rounded for effect: $8,240, not "roughly $8,000."

This is the number that goes into the proposal. It is also the number that makes pricing a cyber security awareness program an easy conversation - a $400/month training program against an $8,240 incident is a math problem, not a sales pitch.

If you can't turn a phishing click into a dollar figure, the client hears 'trust us' instead of 'here is the number.'

Troubleshooting

Client disputes the labor rate you used. Ask for their actual loaded cost per employee, including overhead - most clients underestimate this and the real number is higher than what you assumed, not lower.

No incident history exists for this client. Run a phishing simulation first and use the click-to-report timeline as your baseline. A simulated incident with real click data beats a hypothetical one every time.

The total feels too low to matter. Check whether you've included downtime for affected departments, not just IT hours. Downtime is usually the missing line item that makes a modest incident look expensive enough to justify a program.

The client wants an industry benchmark instead of their own number. Give them both, but lead with their own math. A benchmark is a comparison point; their own number is the one that closes the deal.

Numbers vary widely between similar clients. That's expected - headcount, sector, and existing security maturity all shift the total. A retail chain with 40 POS terminals calculates very differently from a five-person accounting practice.

Tools and resources

What to do next

Build the calculation once per client vertical rather than from scratch every time. Healthcare, legal, and financial services clients carry heavier notification costs; retail and hospitality carry heavier downtime costs from POS or booking system lockouts. Save each version and reuse the structure.

FAQ

What is the average cost of a phishing incident for a small business? There is no single universal figure - the real cost depends on labor hours spent on response, downtime, remediation, and any notification requirements specific to the client. A calculated per-client total is more useful than a national average.

How do you calculate the cost of a phishing incident? Add direct labor hours across IT, ops, and management, downtime for affected staff, remediation or forensics fees, and any regulatory notification costs into one total. Each row uses the client's actual rates and timeline, not industry benchmarks.

Does a phishing simulation count as an incident for cost calculation? Yes, simulated campaigns give you real click-to-report timing you can use as a baseline when no actual incident history exists.

How many labor hours does a typical phishing incident cost an SMB? A mid-size SMB response usually runs 30-50 combined labor hours across IT, helpdesk, and management once triage, containment, and follow-up are counted.

Is downtime included in phishing incident cost calculations? Downtime should be its own line item, calculated as affected headcount multiplied by hours down multiplied by hourly rate. It is frequently the largest single cost in the calculation.

Should regulatory notification costs be included separately? Yes, notification and compliance costs should sit in their own row rather than folded into general remediation. Regulated clients in healthcare, finance, or legal often see this line outweigh the technical cleanup cost.

One last thing

The single line item most MSPs skip entirely is the detection-lag cost from step one - the hours between click and containment. That gap, not the remediation invoice, is usually the largest number in the whole calculation, and it's the one number training programs actually move.

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.