The real cost of a 72-hour ransomware outage
Boards consistently underestimate incident cost by a factor of three or more. The reason is that the obvious costs are the small ones.
When we run tabletop exercises, we ask the finance lead to estimate what three days offline would cost. The number is almost always built from two components: lost revenue for three days, and whatever the response provider charges.
Both are real. Together they are usually less than a third of the total.
What follows is a composite reconstruction based on engagements we have worked, sized to a 200-person professional services firm with roughly £40m turnover. Your figures will differ. The categories are what we want you to take away, because it is the missing categories — not the mis-estimated ones — that produce the surprise.
Days one to three: the visible costs
| Cost | Estimate | Note |
|---|---|---|
| Lost billable output | £340,000 | Three working days of fee-earner capacity, partially recoverable |
| Incident response engagement | £95,000 | Emergency rate; roughly 30% lower under a retainer |
| Overtime and weekend recovery | £48,000 | Internal IT plus contractors through the following weekend |
| External counsel | £62,000 | Breach counsel engaged day one to establish privilege |
| Emergency hardware and licensing | £27,000 | Replacement endpoints, temporary infrastructure |
Running total: about £572,000. This is the part most organisations forecast reasonably well, and it is the part that ends in week one.
Weeks two to eight: the costs nobody forecasts
Systems come back before the organisation does. The invisible tail is longer than the outage and usually larger.
| Cost | Estimate | Note |
|---|---|---|
| Productivity drag during recovery | £410,000 | 6–8 weeks at reduced throughput; the single largest line and the one most often omitted |
| Backlog clearance | £155,000 | Overtime and temporary staff to clear three days of accumulated work |
| Forensic investigation completion | £70,000 | Determining what data was accessed drives your notification obligations |
| Regulatory notification and response | £45,000 | Preparation, submission and follow-up correspondence |
| Client notification and remediation | £88,000 | Communications, credit monitoring, contractual service credits |
| Security remediation | £240,000 | The controls that should have existed, now bought under time pressure |
| Insurance excess | £50,000 | Before any premium impact |
Subtotal: about £1,058,000. Nearly double the visible phase.
The twelve-month tail
Then there are the costs that do not appear on an incident ledger at all, because they show up as ordinary business performance being slightly worse than expected.
- Insurance premium increase — typically 40–80% at the following renewal, often with new conditions and a higher excess. On a £60,000 premium that is £24,000–£48,000 a year, and it persists for several cycles.
- Client attrition — usually modest in professional services, but it lands on your largest and most security-conscious accounts, which are rarely your smallest.
- Sales friction — every prospect’s security questionnaire now has a question you must answer honestly. Deal cycles lengthen.
- Staff turnover — IT and security teams that work an incident and its aftermath have elevated attrition. Replacement and lost institutional knowledge are real costs.
- Management distraction — the hardest to quantify and frequently the most expensive. Your leadership team spends a quarter on this instead of on the business.
A defensible total for the scenario above lands between £1.8m and £2.4m. The finance lead’s opening estimate is typically around £400,000.
What actually moves the number
The useful question is not how to reduce the cost of an incident. It is which investments change the shape of the curve. From the engagements we have worked, four do most of the work.
Detection speed
The difference between detecting an intruder at hour four and at day nine is the difference between an isolated incident and an enterprise-wide encryption event. Attackers typically spend days moving laterally and locating backups before triggering anything. That window is where the outcome is decided, and it is the entire argument for round-the-clock monitoring.
Backup integrity
Ransomware operators target backups first, because they understand the economics better than most boards do. Immutable, offline or air-gapped copies with tested restores are what turn a negotiation into an inconvenience. An untested backup is a hypothesis, and incidents are a poor time to test hypotheses.
Identity segmentation
Most catastrophic outcomes involve a single credential with excessive reach. Tiered administration, just-in-time privilege and phishing-resistant multi-factor authentication on privileged accounts limit how far one compromised account travels.
A retainer signed in advance
Without one, the first six hours go on procurement: finding a provider with capacity, scoping, contracting, provisioning access. Those six hours frequently determine whether encryption completes. A retainer converts them into response time, and most insurers now treat it as a qualifying control.
The conversation to have
Take the categories above to your next leadership meeting and populate them with your own numbers. Revenue per working day. Fee-earner cost. Current premium. Contractual service credits. It takes about an hour.
The resulting figure is the one that makes a security budget conversation straightforward, because it stops being a debate about whether an incident is likely and becomes a comparison between two numbers you can both see.
Written by the AIONYX SOLUTIONS team
Replace with the author’s name, role and a two-line biography. Attributed articles by a named engineer perform measurably better with technical readers than anonymous company posts.
Talk to the teamKeep reading
Related insights
Agentic AI in the back office: where it pays off first
Six process shapes that return their build cost fastest, ranked by payback period, with the diagnostic questions to identify them in your own operation.
SOC 2, CMMC and HIPAA: a practical readiness sequence
The order to tackle overlapping frameworks so you build each control once instead of three times.
Why your camera network is now a cyber risk
What we find on installed camera estates during assessments, and the eight-point hardening baseline that closes it.
Your choice about cookies
We use cookies that are strictly necessary to run this site. We would also like to set optional cookies to understand which pages are useful and to remember your preferences — but only if you say yes. Declining changes nothing about how the site works for you. Read our privacy policy.
