HomeBlogProtecting Your Firm: The Real Cost of Data Collection and Security
All PostsSmall Business Cybersecurity Basics

Protecting Your Firm: The Real Cost of Data Collection and Security

Kevin MabryAugust 18, 2026
CybersecurityData ProtectionSmall BusinessRisk Management
Protecting Your Firm: The Real Cost of Data Collection and Security

Discover why data is a liability for small firms and learn practical steps to protect your business from the rising $4.88 million average cost of a breach.

In my 26 years of helping small professional service firms, I have noticed a dangerous trend: business owners have become digital hoarders. We have been told for a decade that "data is the new oil," which has led firms to believe that more information is always better. However, from where I sit, data is often less like oil and more like gunpowder. If you store it without proper care, it doesn't take much of a spark to level the building. According to the 2024 IBM Cost of a Data Breach Report, the average cost of a data breach has climbed to a staggering $4.88 million. For a firm with 15 or 20 employees, a fraction of that cost is enough to trigger a permanent shutdown.

Every time you onboard a new client, process a payment, or save a tax return, you are engaging in data collection and storage activities that carry significant legal and financial weight. Most small business owners I talk to assume they are "too small to be targeted." I’ve spent my career since 1999 disproving that myth. The reality is that criminals love small firms because they usually have "enterprise-grade" data but "home-office" security. You aren't invisible; you are a low-hanging fruit. I've watched firms lose decades of reputation in a single afternoon because they treated their security like a generic IT task rather than a core business risk.

Cybersecurity is not about buying the flashiest software or hiring a "tech guy" who checks your backups once a quarter. It is about making smart, informed decisions about how you handle information. In this guide, I want to strip away the technical noise and look at the reality of data collection and protection for the modern small firm. We will look at why your current approach might be leaving you exposed, the real-world costs of getting it wrong, and the practical steps you can take to secure your firm without needing a Fortune 500 budget.

Key Takeaways

  • Data is a Liability: Treat every piece of client information you collect as a potential financial risk, not just a business asset.
  • The "Human Element" is Number One: 68% of breaches involve a human element, including social engineering attacks or simple errors, according to the 2024 Verizon Data Breach Investigations Report (DBIR).
  • Small Firms are Prime Targets: 43% of all cyberattacks are aimed at small businesses because they often lack the robust defenses of larger corporations.
  • Antivirus is Not Enough: Traditional "set and forget" IT support is no longer sufficient to stop modern threats like ransomware and account takeovers.
  • Minimize to Protect: The most effective way to secure data is to stop collecting information you don't strictly need for daily operations.
  • Compliance is Not Security: Meeting regulatory requirements (like HIPAA or FTC Safeguards) is the bare minimum; it does not mean your business is actually safe from an attack.

The Real Cost of Data Collection and Storage Failures

In my experience, business owners often view cybersecurity as a "sunk cost"—money going out the door that doesn't help the business grow. I challenge that perspective by showing them what the alternative looks like. When we talk about the risks associated with data collection and management, we aren't just talking about a tech glitch. We are talking about operational paralysis.

Last year, I sat down with the managing partner of a 12-person accounting firm. They had been hit by a "business email compromise" (BEC). A criminal had gained access to a junior staffer's mailbox and sat there silently for three weeks, watching how the firm communicated. Eventually, the attacker sent a fake invoice to a high-value client during tax season. The client paid $45,000 into a fraudulent account. The firm wasn't just out the $45,000; they had to pay for a forensic investigation, legal fees to notify their entire client base, and they suffered a massive blow to their reputation that resulted in three long-term clients leaving within a month. This is the reality of modern cybercrime: it's not a movie plot; it's a sophisticated business model designed to drain yours.

The Financial Breakdown

When you look at the numbers, the "cost" of proactive security suddenly looks like a bargain. The FTC reports that small businesses are increasingly targeted because they are the "entry point" into larger supply chains or possess high-value personal data like Social Security numbers and bank details.

  • Forensic Investigation
  • Expense Category Proactive Security (Per Year) Post-Breach Recovery (One-Time)
    Monitoring & Protection $5,000 - $15,000 $0
    $0 $20,000 - $50,000
    Legal Fees & Notifications $0 $10,000 - $30,000
    Ransom Payment (If applicable) $0 $100,000+ (Not Recommended)
    Lost Revenue/Reputation $0 $50,000 - $250,000+
    Total Estimated Impact $5,000 - $15,000 $180,000 - $380,000+

    When I present these numbers to CEOs, the conversation shifts. We stop talking about "buying software" and start talking about "business continuity." If you spend $10,000 a year to avoid a $200,000 disaster, that is a 2,000% return on investment. In my 26 years of doing this, I’ve never seen a better deal in business.

    Understanding the Lifecycle of Data Collection and Protection

    Most small firms have a "catch-all" mentality. They collect everything they can and keep it forever. I once worked with a small medical billing office that still had digital records from 2005. When I asked why, the owner said, "I thought we might need them someday." That "someday" never came, but the risk remained every single day those files sat on their server. Modern data collection and protection strategies require you to be intentional about what you keep.

    Step 1: The Inventory

    I always tell my clients: You cannot protect what you don't know you have. Start by identifying every place client data lives. It's not just your main server or your cloud storage. It's in your employees' email attachments, it's on their personal smartphones, and it's in the "Downloads" folder of every computer in the office. In my experience, most firms are surprised to find that 30-40% of their sensitive data is stored in unmanaged, "invisible" locations.

    Step 2: The "Need to Know" Rule

    A major mistake I see in firms under 50 employees is giving every staff member access to every folder. They do it for "convenience," but it’s a security nightmare. If a receptionist's account is compromised and they have access to the firm's entire financial history, the attacker has it too. I advocate for the "Principle of Least Privilege." Employees should only have access to the data they need to do their jobs today. Nothing more.

    Step 3: Secure Disposal

    Data has an expiration date. If you are a CPA and a client hasn't been with you for seven years, why are you still holding onto their old tax returns? Every record you delete is one less record a hacker can steal. I recommend setting a clear "Data Retention Policy" that dictates exactly when files are purged. This simple step reduces your liability significantly without costing a dime in software fees.

    Why Small Firms are Targets for Account Takeovers

    The most common threat I see today isn't a complex hack of your firewall. It is a simple account takeover. An employee gets a phishing email that looks like a Microsoft 365 login request, they enter their credentials, and just like that, the "keys to the kingdom" are handed over. According to KnowBe4’s 2024 Phishing by Industry Benchmarking Report, nearly 1 in 3 untrained employees will click on a malicious link.

    I remember a 6 AM call I got a few years ago from a distraught business owner. Their controller had received an email that appeared to be from the CEO (my client), asking for an urgent wire transfer to a new vendor. Because the controller wanted to be helpful and the email looked legitimate, the money was sent. It was $28,000. By the time they called me, the money was long gone, moved through three different international banks in minutes. This wasn't a "tech failure"; it was a failure of process and training. The criminals understood the firm's data collection and communication patterns better than the employees did.

    The Myth of "My IT Guy Has It Handled"

    I often hear, "Kevin, I pay an IT company $150 a month to manage my computers. Aren't they doing this?" My answer is usually "No." Standard IT support is like a mechanic—they keep the car running. Cybersecurity is like a specialized security team—they make sure no one steals the car or the cargo inside. Most IT providers focus on uptime and "fixing things when they break." They are not typically monitoring for silent account intrusions or conducting deep-risk assessments. If you haven't had a specific conversation about security layers with your provider, you likely have a massive gap in your defenses.

    Implementation Best Practices: Securing Your Firm Today

    You don't need to be a tech expert to secure your firm. In my 26 years, I’ve found that the most effective security measures are often the simplest ones. Here are the five steps I recommend every professional service firm take immediately:

    1. Implement Mandatory Multi-Factor Authentication (MFA): I cannot stress this enough. If you do nothing else, turn on MFA for your email and your financial accounts. It stops 99% of automated account takeover attempts. If a system doesn't offer MFA, stop using it.
    2. Conduct a "Data Audit": Spend one hour this week looking for data you don't need. Look at old client files, former employee accounts that are still active, and redundant backups. If you don't need it for legal or operational reasons, delete it.
    3. Invest in Continuous Awareness Training: Don't just do a one-hour seminar once a year. Your employees need short, monthly reminders of what a phishing email looks like. Security is a muscle; if you don't train it, it weakens.
    4. Encrypt Everything: Whether it's the hard drive on a laptop or the email you send to a client, encryption should be the default. If a laptop is stolen but the drive is encrypted, you have a hardware loss, not a data breach.
    5. Develop an Incident Response Plan: I once asked a client, "Who do you call if you're locked out of your server at 2 PM on a Friday?" They didn't have an answer. You need a simple one-page document that tells your staff exactly who to call and what NOT to do (like turning off the server, which can destroy evidence) during a breach.

    FAQ

    Does my small business insurance cover data breaches?

    Don't assume your general liability policy covers cyber incidents. Most don't. You usually need a specific "Cyber Liability" rider or standalone policy. Even then, read the fine print—many insurers will deny a claim if you didn't have basic safeguards like MFA in place at the time of the breach.

    Is the cloud safer for data collection and storage than an on-site server?

    Generally, yes—but only if configured correctly. Microsoft and Google have better physical security than your office closet, but they follow a "Shared Responsibility Model." They secure the infrastructure; you are responsible for securing the data and the access to it. If your password is "Password123," the cloud won't save you.

    How often should we change our passwords?

    The old advice of changing passwords every 90 days is actually outdated. It leads to people choosing weak, predictable passwords (like "Spring2024!"). Instead, I recommend using long, unique passphrases (16+ characters) stored in a secure Password Manager, and only changing them if you suspect a compromise.

    What is the biggest mistake you see small firms make?

    Thinking that cybersecurity is a "product" you buy once. It's not. It's a continuous process of assessing risk and making adjustments. The firms that get hit the hardest are the ones that set up a firewall in 2018 and haven't looked at it since.

    Are Macs safer than PCs for sensitive data?

    This is a common myth. While there used to be fewer viruses for Macs, that has changed as Macs have gained market share in the business world. More importantly, most modern attacks (phishing and account takeovers) happen in the browser, meaning the operating system you use doesn't matter to the attacker.

    Do I really need to worry about the FTC Safeguards Rule?

    If you handle non-public financial information—which includes many accountants, tax preparers, and even some law firms—the answer is a resounding yes. The FTC has significantly ramped up requirements for data protection, and the fines for non-compliance are steep.

    Conclusion

    Protecting your firm’s data collection and daily operations doesn't have to be an overwhelming technical nightmare. It starts with a shift in mindset: moving from seeing data as a trophy to seeing it as a responsibility. In my 26 years at Sentree Systems, I've seen that the firms that thrive are not the ones with the most expensive software, but the ones with the best decision-making processes. They understand that security is a core business function, just like accounting or legal counsel.

    The cost of doing nothing is no longer zero. Between rising insurance premiums, the increasing sophistication of ransomware, and the high price of client notification, the financial "ROI" of cybersecurity has never been clearer. Don't wait for a 6 AM phone call to start taking this seriously. Start by identifying your risks, protecting your accounts, and training your team. Cybersecurity should give you the confidence to grow your business, not leave you wondering if you'll be in business next month.

    Get a Risk Assessment

    Watch: Stop Ignoring These Costly Cyber Threats 🚨

    12 viewsJul 29, 2025Watch on YouTube →
    KM

    Kevin Mabry

    Founder & CEO, Sentree Systems

    Kevin Mabry is the founder and CEO of Sentree Systems, a cybersecurity company serving small professional service firms with under 100 employees. Since starting his business in 1999, Kevin has spent more than 26 years helping organizations protect sensitive information and make smarter technology and security decisions.

    His work focuses on helping business owners protect client data, reduce cyber risk, and avoid the operational disruption caused by ransomware, account takeovers, phishing, and other preventable threats. Kevin is known for explaining cybersecurity in plain English without vendor hype, unnecessary jargon, or treating cybersecurity like generic IT support.

    Take Action

    Is your business protected?

    Get a free security assessment. We'll identify your biggest risks and give you a clear, plain-English action plan — no obligation.

    Schedule Your Free Assessment