Posted on

The real cost of a 72-hour ransomware outage

Incident Response23 June 202610 min read

The real cost of a 72-hour ransomware outage

Boards consistently underestimate incident cost by a factor of three or more. The reason is that the obvious costs are the small ones.

When we run tabletop exercises, we ask the finance lead to estimate what three days offline would cost. The number is almost always built from two components: lost revenue for three days, and whatever the response provider charges.

Both are real. Together they are usually less than a third of the total.

What follows is a composite reconstruction based on engagements we have worked, sized to a 200-person professional services firm with roughly £40m turnover. Your figures will differ. The categories are what we want you to take away, because it is the missing categories — not the mis-estimated ones — that produce the surprise.

Days one to three: the visible costs

CostEstimateNote
Lost billable output£340,000Three working days of fee-earner capacity, partially recoverable
Incident response engagement£95,000Emergency rate; roughly 30% lower under a retainer
Overtime and weekend recovery£48,000Internal IT plus contractors through the following weekend
External counsel£62,000Breach counsel engaged day one to establish privilege
Emergency hardware and licensing£27,000Replacement endpoints, temporary infrastructure

Running total: about £572,000. This is the part most organisations forecast reasonably well, and it is the part that ends in week one.

Weeks two to eight: the costs nobody forecasts

Systems come back before the organisation does. The invisible tail is longer than the outage and usually larger.

CostEstimateNote
Productivity drag during recovery£410,0006–8 weeks at reduced throughput; the single largest line and the one most often omitted
Backlog clearance£155,000Overtime and temporary staff to clear three days of accumulated work
Forensic investigation completion£70,000Determining what data was accessed drives your notification obligations
Regulatory notification and response£45,000Preparation, submission and follow-up correspondence
Client notification and remediation£88,000Communications, credit monitoring, contractual service credits
Security remediation£240,000The controls that should have existed, now bought under time pressure
Insurance excess£50,000Before any premium impact

Subtotal: about £1,058,000. Nearly double the visible phase.

The twelve-month tail

Then there are the costs that do not appear on an incident ledger at all, because they show up as ordinary business performance being slightly worse than expected.

  • Insurance premium increase — typically 40–80% at the following renewal, often with new conditions and a higher excess. On a £60,000 premium that is £24,000–£48,000 a year, and it persists for several cycles.
  • Client attrition — usually modest in professional services, but it lands on your largest and most security-conscious accounts, which are rarely your smallest.
  • Sales friction — every prospect’s security questionnaire now has a question you must answer honestly. Deal cycles lengthen.
  • Staff turnover — IT and security teams that work an incident and its aftermath have elevated attrition. Replacement and lost institutional knowledge are real costs.
  • Management distraction — the hardest to quantify and frequently the most expensive. Your leadership team spends a quarter on this instead of on the business.

A defensible total for the scenario above lands between £1.8m and £2.4m. The finance lead’s opening estimate is typically around £400,000.

What actually moves the number

The useful question is not how to reduce the cost of an incident. It is which investments change the shape of the curve. From the engagements we have worked, four do most of the work.

Detection speed

The difference between detecting an intruder at hour four and at day nine is the difference between an isolated incident and an enterprise-wide encryption event. Attackers typically spend days moving laterally and locating backups before triggering anything. That window is where the outcome is decided, and it is the entire argument for round-the-clock monitoring.

Backup integrity

Ransomware operators target backups first, because they understand the economics better than most boards do. Immutable, offline or air-gapped copies with tested restores are what turn a negotiation into an inconvenience. An untested backup is a hypothesis, and incidents are a poor time to test hypotheses.

Identity segmentation

Most catastrophic outcomes involve a single credential with excessive reach. Tiered administration, just-in-time privilege and phishing-resistant multi-factor authentication on privileged accounts limit how far one compromised account travels.

A retainer signed in advance

Without one, the first six hours go on procurement: finding a provider with capacity, scoping, contracting, provisioning access. Those six hours frequently determine whether encryption completes. A retainer converts them into response time, and most insurers now treat it as a qualifying control.

The conversation to have

Take the categories above to your next leadership meeting and populate them with your own numbers. Revenue per working day. Fee-earner cost. Current premium. Contractual service credits. It takes about an hour.

The resulting figure is the one that makes a security budget conversation straightforward, because it stops being a debate about whether an incident is likely and becomes a comparison between two numbers you can both see.

Written by the AIONYX SOLUTIONS team

Replace with the author’s name, role and a two-line biography. Attributed articles by a named engineer perform measurably better with technical readers than anonymous company posts.

Talk to the team

Keep reading

Related insights