# Data breaches and ransomware, what they cost you in Norway

> A breach and a ransomware attack are different problems with different bills. Here is what each costs a Norwegian business, and what the board decides.

Source: https://fmcybersecurity.com/en/insights/endpoint/data-breaches-and-ransomware-in-norway/
Locale: English
Other locale: https://fmcybersecurity.com/insights/endpoint/datainnbrudd-og-losepengevirus/

## Metadata

- Date: 2026-07-30
- Author: kenny-le
- Topic: endpoint
- Format: article

A data breach and a ransomware attack arrive as two separate bills, and boards keep reading them as one. The breach bill is legal and contractual. You report to the regulator within three days, you write to the people whose data was taken, and you answer the security clause in your largest customer contract. The ransomware bill is operational. Payroll does not run, the warehouse goes back to paper, and the rebuild takes weeks.

I watch Norwegian endpoints from a CrowdStrike Falcon console. In the customer onboardings I ran this spring, the way in was rarely exotic. It was usually a password that already sat in a public leak, on an account with no second factor.

## What a data breach is, and where ransomware differs

A data breach means someone reached data they had no right to reach. Ransomware is what an attacker does next, locking your files or threatening to publish what they took until you pay.

Norwegian cases usually combine both. Attackers steal the data first and encrypt second, then threaten publication if the money does not come. NSM describes this double extortion in [Risiko 2026](https://nsm.no/regelverk-og-hjelp/rapporter/risiko-2026), published 6 February 2026, and calls ransomware one of the most widespread attack methods against Norwegian businesses.

So the board question is not whether files were encrypted. It is what left the building, and who it belonged to.

## What a cyber attack costs a Norwegian business

Norwegian police registered 349 criminal cases of computer intrusion in 2025, 104 more than the year before. Kripos counted around 17 ransomware variants used against Norwegian small and medium businesses during 2025, and reports no large Norwegian enterprise hit in the same period ([Cyberkriminalitet 2026](https://www.politiet.no/globalassets/tall-og-fakta/datakriminalitet/cyberkriminalitet-2026.pdf)). Mid-sized is the target profile, not the protection.

The regulatory bill is public and documented. Datatilsynet fined the University of Agder NOK 150,000 in September 2024 for security measures that were not good enough to protect personal data, including missing logging ([the decision](https://www.datatilsynet.no/aktuelt/aktuelle-nyheter-2024/overtredelsesgebyr-til-universitetet-i-agder)). Fines scale with turnover, so a bigger company with the same gap pays more.

The contractual bill is the one nobody budgets for. Enterprise and public-sector customers write security clauses into their contracts, and a reported breach starts a conversation you cannot postpone. We keep a running record of confirmed Norwegian incidents in [Attacks in Norway](/en/insights/attacks/), and the names on it are ordinary companies.

## The 72-hour report to Datatilsynet

If personal data was involved, you must report the breach to Datatilsynet within 72 hours of becoming aware of it (GDPR artikkel 33). Datatilsynet sets out [which breaches must be reported](https://www.datatilsynet.no/brudd), and lets you [report in stages](https://www.datatilsynet.no/rettigheter-og-plikter/virksomhetenes-plikter/avvik/meld-avvik-til-datatilsynet/) when you do not yet have the full picture.

Datatilsynet received 3,016 breach reports in 2025, five percent fewer than in 2024, and 39 percent of them were personal data sent to the wrong recipient (Datatilsynet, [annual report for 2025](https://www.datatilsynet.no/regelverk-og-verktoy/rapporter-og-utredninger/datatilsynets-arsrapporter/arsrapport-for-2025/kontroll-og-saksbehandling/), published 8 May 2026). Most reports are not intrusions. The intrusions are the ones that also cost you customers.

## What Norwegian authorities say about paying

NSM advises against paying. Its guidance states that paying the ransom demand directly finances serious crime, and that paying marks the company as willing, which attackers have exploited across several rounds of extortion ([NSM on digital extortion](https://nsm.no/fagomrader/digital-sikkerhet/rad-og-anbefalinger-innenfor-digital-sikkerhet/digital-utpressing/digital-utpressing-situasjon)).

Report it to the police as well. Only 24 percent of Norwegian businesses that suffered a breach or data theft did so, according to Mørketallsundersøkelsen 2024 as cited by Kripos. In January 2026 the police asked companies hit through a known SonicWall SonicOS weakness to report quickly, so the cases could be linked ([politiet.no](https://www.politiet.no/aktuelt-tall-og-fakta/aktuelt/nyheter/2026/01/23/mange-norske-bedrifter-utsatt-for-datainnbrudd---vi-frykter-at-flere-star-i-fare/)).

## Denial of service is a different problem

A denial-of-service attack floods your website or login service until it stops answering. No data is taken. Kripos assesses that these attacks rarely cause more than temporary outages for businesses, though repeated campaigns create real operational load. NSM notes in Risiko 2026 that they need almost no technical skill and can be rented cheaply from a third party.

Handle it as an availability question with your hosting provider. Do not let it eat the response capacity you need for a real intrusion.

## The one decision the board makes

Decide who is watching your endpoints outside office hours, and write the answer down. Either you accept that nobody looks at an alert between 17:00 and 08:00, or you pay for someone who does. The rest follows from that call: how long an intruder sits inside before anyone notices, whether you can answer Datatilsynet inside 72 hours, and whether your largest customer keeps the contract.

## Next step

Read what separates an alert from an investigation in [EDR and antivirus](/en/insights/endpoint/edr-and-antivirus-what-the-difference-is/), or see what [managed detection and response](/en/services/mdr/) covers and why we run it on [CrowdStrike Falcon](/en/partners/crowdstrike/). If the plan matters more than the tooling right now, [incident response advisory](/en/services/incident-response/) and [what incident response is and how to run it](/en/insights/endpoint/what-incident-response-is-and-how-to-run-it/) cover the first 72 hours. Or take a 30-minute board conversation with Kenny about who is watching your endpoints tonight.

## FAQ

### Do we have to tell the people affected, or only Datatilsynet?

Both, when the breach is likely to bring a high risk to their rights and freedoms (GDPR artikkel 34). Datatilsynet always gets the report unless you are close to certain the breach carries no risk at all. The people affected get told when they need to act themselves, for example change a password they reused elsewhere.

### We are 60 people. Are we too small to be a target?

No. Kripos counted around 17 ransomware variants used against Norwegian small and medium businesses through 2025 and reports no large Norwegian enterprise hit in the same period. Criminal groups rent the tooling and pick by weak security rather than by company size.

### When does the 72-hour clock start?

When someone in the company becomes aware that a breach probably happened, not when the investigation is finished. That is why Datatilsynet accepts a first report with gaps in it and supplementary information later. Waiting for certainty is how a reportable incident turns into a late one.

### We restored from backup. Is it still reportable?

Usually yes. A breach covers loss of access to personal data, not only theft of it, so an encryption event that locked customer records is reportable even when you restored them the same day. Document the assessment either way, because you are expected to be able to show your reasoning.

Drafted with AI assistance, reviewed and edited by Kenny Le and the FM CyberSecurity editorial team.

---

For the full documentation index, see https://fmcybersecurity.com/llms.txt
For the complete corpus as a single document, see https://fmcybersecurity.com/llms-full.txt
