Source Code Conversations Ep. 11 - Impact of Breach
00:00
Hi everyone and welcome to Volume 11 of Source Code Conversations.
This episode we’re delighted to welcome two of our cloud consultants, Ana Stefanovic and Arek Panfil to discuss the costs of a cyber breach, the risks, how it works and introduction to our Impact of Breach Assessment.
Thanks for giving us your time, let’s get into the conversation.
Guest Introduction
Zoe Hawkins: Welcome to Source Code Conversations Ana and Arek, first time here.
Ana Stefanovic: Thanks for having us, great to be here.
Zoe: Good to have you both here as today we’re tackling a question that almost every organisation knows is important, but very few can actually answer:
What would a cyber breach really cost your business?
Both Ana and Arek are cyber security experts, both of which work with organisations across CEMA, and they’re here with me to tackle the question.
Let’s get to it.
The Reality of Cyber Risk
Zoe: Let’s start with the basics. I think some people still hear cyber breach and assume it’s something that happens to big enterprises, banks, hospital, not them.
Arek Panfil: Yeah, and honestly, that’s one of the biggest misconceptions out there.
The reality is, attacks today are largely automated. Attackers aren’t picking targets manually, they’re scanning thousands of organisations at once, looking for any weak point.
Zoe: So this really is more of a when than an if?
Arek: For most organisations, yes. Around 43% of UK businesses experienced a breach or attack in the last year.
And we see very similar patterns across the CEMA region.
Zoe: Oh wow that’s nearly half. What does that actually translate to in cost?
Arek: The global average cost of a data breach is now over €4 million and rising.
But what’s often overlooked is how long breaches go undetected. On average, it can take months to identify and contain one, meaning damage builds quietly in the background.
Zoe: So by the time you notice, it’s already expensive.
Arek: Exactly, financially, operationally, and reputationally. And in regions like CEMA, you also have regulatory exposure layered on top, GDPR, NIS2, financial regulations, all of which can significantly increase the total impact.
Why Security Conversations Fall Short
Zoe: So here’s the thing, none of this is exactly new. People have been talking about cyber risk for years. Why aren’t organisations doing more?
Ana: Because the conversation is happening in the wrong language.
Security teams talk about vulnerabilities, threats, controls, which is important, but boards and CFOs don’t make decisions based on that.
They make decisions based on financial impact.
Zoe: So it’s not a lack of awareness, it’s a translation problem?
Ana: Exactly.
If you say: “We have a vulnerability issue,” it’s hard to act on.
But if you say: “This specific risk could cost us €2 million, and €200k reduces it by half,”. Then suddenly it’s a business decision.
Zoe: And that’s when budgets get approved?
Ana: Every time. Because now you’re speaking in a language that leadership understands.
Introducing the Impact of Breach Assessment
Zoe: So this is where our Impact of Breach Assessment comes in. What exactly is it?
Arek: At its core, it answers that original question:
👉 What would a breach actually cost us?
And it does it with a defensible, organisation-specific financial figure, not a generic estimate.
Zoe: I see so it’s a tailored assessment?
Arek: Completely. It models:
your organisation
your sector
your existing controls
and a realistic breach scenario
So, the output reflects your situation, not an industry average.
Zoe: I like how you framed it earlier, more like a financial stress test than a risk assessment
Arek: That’s exactly what it is.
It’s the same principle businesses use for major investments, understanding downside risk in real financial terms.
How It Works
Zoe: Alright, so walk me through it. What does someone actually have to do?
Ana It’s designed to be very simple:
You complete a short questionnaire — takes about 10 minutes
It covers your environment, risks, and controls
Then our consultants validate and model the data
And within 48 hours, you get a full report.
Zoe: That’s quick.
Ana: That’s the idea, remove friction. No long consulting engagement, no heavy lift internally.
Zoe: And what exactly does the report give you?
Ana: A clear financial breakdown of potential breach impact across:
operational disruption
recovery costs
regulatory fines
reputational damage
Plus, prioritised recommendations on where investment makes the biggest difference.
Why It Matters
Zoe: So once an organisation has that report, what changes?
Arek: The conversation changes immediately. Instead of: “We should improve security,” You can say: “Here’s our financial exposure, and here’s how we reduce it.”
That helps with:
budget approval
board-level decision making
compliance evidence
cyber insurance discussions
Zoe: And I imagine it helps internally as well?
Arek: Massively. When everyone, the CFO, board, and security team is working from the same financial figure, you get alignment. And alignment speeds up decisions.
Final Takeaway
Zoe: To finish off, what’s the one thing you want people to take away from this?
Ana: That you can’t manage what you can’t quantify. Cyber security isn’t just a technical issue anymore, it’s a business risk. And the organisations that handle it best are the ones that can:
measure it
communicate it
and act on it
Zoe: I like that, simple, but powerful.
Closing
Zoe: If you want to understand what a cyber breach could really look like for your organisation, the Impact of Breach Assessment is designed to give you that clarity, quickly and practically.
Thanks for listening, and we’ll see you in the next episode.
If you enjoyed this episode, don’t forget to share it with your colleagues and follow us on LinkedIn at ‘Cloud Services by Source Code Control’ to know when the next Volume drops. Thanks for listening, and we’ll see you next time on Source Code Conversations.
Ana Stefanovic
Interviewee
Arek Panfil
Interviewee
Zoe Hawkins
Interviewer & Editor
Related
Discover more from Source Code Control
Subscribe now to keep reading and get access to the full archive.