Most discussion of breach cost fixates on the PDPC fine. For a Singapore SME the fine is usually the smaller line. Published penalties against smaller organisations have commonly run S$3,000 to S$50,000, while the investigation, legal advice, notification and remediation that surround a breach routinely cost more than that combined. This page separates what is published research from what is modelled, and shows the working for both.
IBM’s 2026 Cost of a Data Breach Report puts the average across ASEAN at US$4.12 million, about S$5.2 million at the September 2026 rate of roughly 1.27. It is the most quoted number in the region and it is accurate for what it measures.
What it measures is the problem. The ASEAN figure is drawn from 26 organisations across Singapore, Indonesia, the Philippines, Malaysia, Thailand and Vietnam. Studies of this kind recruit large enterprises, because those are the organisations with the incident records, the insurance and the internal accounting to participate. A 30-person company in Singapore is not in that sample and does not have that cost structure.
Cyber insurance claims data is a better guide, because claims come disproportionately from smaller organisations. NetDiligence’s Cyber Claims Study puts average SME crisis services at about US$96,000, roughly S$122,000, with forensics accounting for about 22% of that, or around S$27,000.
Two caveats, because they matter. That is United States claims data, and the US has cost lines Singapore does not, notably state notification laws and the credit-monitoring offers that follow them. A comparable Singapore incident would likely land lower. It is also an average across claims that reached an insurer, which skews toward incidents serious enough to claim on.
Treat it as an order of magnitude, not a forecast: a serious notifiable breach at an SME is a five-figure to low six-figure event, not a four-figure one.
Six lines recur in almost every breach. The table marks which are grounded in published figures and which are modelled, so you can weigh them differently.
| Cost line | What drives it | Basis |
|---|---|---|
| PDPC financial penalty | Seriousness of the lapse, sensitivity of the data, and conduct afterwards | Published decisions: commonly S$3,000 to S$50,000 for smaller organisations |
| Forensic investigation | How much of your estate has to be examined to establish what was accessed | About 22% of crisis services in claims data, roughly S$27,000 at SME average |
| Legal advice | Notification wording, regulator correspondence, contract and customer exposure | Part of the crisis services figure above |
| Notification | Number of affected individuals, and how many then contact you | Part of the crisis services figure above |
| Remediation | Closing the gap: patching, access controls, multifactor authentication, sometimes replacing a system | Varies most widely of any line |
| Internal staff time | Senior people pulled off their actual jobs for two to six weeks | Modelled below |
This one is invisible because it never gets invoiced, so it is worth costing explicitly. Using the same method as our DPO cost comparison: a manager on S$6,000 a month costs about S$42 an hour once employer CPF at 17% is included.
A notifiable breach typically consumes the owner or a director, whoever handles the data protection function, and someone technical, across the first two to six weeks.
| Total internal hours | Roughly equivalent to | Cost of diverted time |
|---|---|---|
| 60 hours | A contained incident handled by two people in a fortnight | about S$2,500 |
| 100 hours | Three people, several weeks, with a regulator exchange | about S$4,200 |
| 150 hours | A contested or complex incident running over a month | about S$6,300 |
These are modelled figures, not survey data, and they exclude the opportunity cost of whatever those people were supposed to be doing instead. For a small company that second number is often the real one.
You must notify the PDPC no later than 3 calendar days after determining a breach is notifiable, weekends and public holidays included. A breach is notifiable if it is likely to cause significant harm, or if it involves 500 or more individuals.
That deadline changes what you pay. Forensic and legal help engaged inside 72 hours is bought at emergency rates from whoever is available, not at rates you negotiated calmly. Companies that already know what data they hold and where it lives can scope the investigation quickly. Companies that do not are paying specialists to discover their own systems, which is the most expensive possible way to learn it.
Everything above can be estimated. Lost business cannot, and for a small company it is often the part that actually hurts.
For a company of thirty people, losing two significant clients can exceed every other line on this page combined.
Preparation, almost entirely, and mostly the unglamorous parts:
For the penalty side of the ledger, see PDPA fines in Singapore for real decisions and amounts. For what to do in the first hours, see our data breach response guidance.
A gap assessment produces the data inventory and response plan that make the expensive parts of a breach cheaper. It is considerably less than one line on the table above.
Get a Gap AssessmentIt depends enormously on size. IBM’s 2026 Cost of a Data Breach Report puts the ASEAN average at US$4.12 million, about S$5.2 million, but that figure comes from 26 large organisations and is not representative of an SME. For a smaller company, insurance claims data from NetDiligence puts average SME crisis services at about US$96,000, roughly S$122,000. The PDPC penalty is usually the smaller line, not the largest.
Usually not. Published PDPC penalties against smaller Singapore organisations have commonly fallen between S$3,000 and S$50,000. Forensic investigation, legal advice, notification, remediation and lost business routinely add up to more than that. Treating the fine as the total cost of a breach understates the exposure substantially.
Six recur: the PDPC financial penalty, forensic investigation to establish what happened, legal advice, notifying affected individuals and the PDPC, remediation to close the gap that caused it, and internal staff time diverted from normal work. Lost business and reputational damage sit on top and are the hardest to bound, because published PDPC decisions name the organisation permanently.
No later than 3 calendar days after determining the breach is notifiable, including weekends and public holidays. A breach is notifiable if it is likely to result in significant harm, or if it involves the personal data of 500 or more individuals. That deadline is also a cost driver: it means engaging forensic and legal help under time pressure, which is the most expensive way to buy anything.
Preparation, almost entirely. Knowing what personal data you hold and where it lives shortens the forensic scoping that drives the largest bill. Having a tested response plan and an appointed DPO means the first day is executed rather than improvised. Prompt voluntary notification, full cooperation and swift remediation are also consistently treated as mitigating factors by the PDPC when it sets a penalty.
Policies differ, and this is worth checking rather than assuming. Cyber policies commonly cover crisis services such as forensics, legal advice and notification, which are the larger lines for an SME. Whether a regulatory financial penalty is covered varies by policy and by whether the penalty is insurable at all. Read the wording, and ask the insurer directly about PDPA penalties specifically.
Disclaimer: This article is for general information only and does not constitute legal, financial or insurance advice. Figures attributed to IBM’s Cost of a Data Breach Report 2026 and NetDiligence’s Cyber Claims Study are as published by those sources; currency conversions use an approximate rate of US$1 to S$1.27 as at September 2026 and will move. Internal staff time figures are modelled illustrations, not survey data, and are labelled as such above. Actual costs vary enormously by incident. For current obligations refer to the Personal Data Protection Commission (PDPC) and seek qualified advice for your specific situation.