New insights by RSS

Ransomware Downtime: Why the Outage Costs More Than the Ransom

Reference briefing by Daniel Hirsch · Last reviewed · 10 min read
Ransomware Downtime: Why the Outage Costs More Than the Ransom

In May 2021 Colonial Pipeline paid a ransom of about $4.4 million, and the Justice Department later recovered roughly $2.3 million of it. That figure made the headlines. The figure that shaped the event was time: the company shut down a pipeline carrying a large share of the East Coast's fuel for the better part of a week, reportedly in part because the attack had hit the business systems used to track and bill deliveries. The fuel was fine. The ability to run the business around it was not.

That pattern repeats in nearly every serious case. The ransom is one visible line item. The outage is a long tail of costs across every department, usually several times larger.

Ransomware is a business, and it prices you

Modern ransomware runs as a marketplace with its own supply chain. Initial access brokers sell footholds into networks. Ransomware-as-a-service operators license their tooling to affiliates who carry out intrusions for a cut. Negotiators, leak sites, and money launderers handle the back office. Like any business, it optimizes for return on effort, and that has two consequences for defenders.

First, the demand is calibrated to your pain. Crews research a victim's revenue and insurance and set the price at what they think the outage will make you pay. Second, most crews are opportunistic. They move on from targets that are slow and expensive to work. Being a harder target than the next organization (patched edge devices, phishing-resistant MFA, segmented networks, backups the attacker cannot reach) shifts the economics in your favor without making you immune.

Two buckets of cost

It helps to split the bill the way finance will eventually split it.

Recovery costs Downtime costs
Forensics and incident response Lost revenue: orders not taken, services not delivered
Outside counsel Lost productivity: payroll for staff who cannot work
Rebuilding servers, workstations, identity systems Contractual penalties and service credits
Replacement hardware, emergency licensing Overtime and temporary staff to clear backlogs
IT and security overtime Expedited shipping, spoiled or expired inventory
Notification, call centers, credit monitoring Customer churn and lost bids
The ransom, if paid Regulatory and litigation exposure that follows the outage

The ransom sits in the left column, often as one of the smaller entries. Paying does not shrink the right column much. Decryptors can be slow and unreliable on large systems, the environment still has to be treated as compromised, and every rebuilt system has to be validated before it touches production. NotPetya in 2017 made the point brutally. It looked like ransomware, but there was no working way to pay and recover. Companies such as Maersk lost global operations for days and reported costs in the hundreds of millions of dollars, nearly all of it rebuild and downtime.

Estimating downtime from BIA data

If the business impact analysis has daily impact figures per function, most of the inputs already exist. The adjustment for ransomware is duration. Conventional DR planning assumes the infrastructure is trustworthy and only the restore is slow. In a ransomware recovery the clock is set by forensic clearance and rebuild throughput, and publicly reported cases routinely run to weeks of disruption rather than hours.

Take a hypothetical regional distributor: $180 million in annual revenue, 400 employees, about 250 trading days a year. That is roughly $720,000 of revenue and $110,000 of payroll per day.

Impact line (from BIA) Days 1–3 Days 4–10 Days 11–21 Basis
Revenue lost, not deferred 60% of daily 40% 15% Manual ordering recovers some volume
Idle payroll 70% of staff 40% 10% Workarounds put people back to work
Penalties and credits Minor Begin around day 5 Material Key customer contracts
Catch-up overtime None Heavy Moderate Backlog clearance

Work it through. Lost revenue comes to about $1.3 million for days one to three, about $2 million for days four to ten, and about $1.2 million for days eleven to twenty-one. Idle payroll adds roughly $230,000, $310,000, and $120,000. Before penalties, overtime, forensics, or rebuild, the outage is already a little over $5 million. A hypothetical $1 million demand is a fraction of that bill, whether or not it is paid.

The example shows three things:

  • The steepest losses come first. Workarounds that recover even partial volume in the first three days pay for themselves fastest.
  • The tail is long. Days eleven to twenty-one look small per day and add up anyway.
  • The number executives need is the downtime number. It reframes the pay-or-not discussion, because paying rarely shortens the outage by much.

Why continuity owns the outage

Security owns containment and eradication. IT owns the rebuild. Neither is set up to decide which business function comes back first, how customers get served meanwhile, or when to take orders again. That is a continuity job.

Workstream Typical owner Continuity's role
Containment, forensics, eradication Security and the IR firm Feed business priorities into isolation decisions
Rebuild and restore IT / DR Supply the restore order from the BIA
Keeping functions running Business units Activate workarounds, track capacity
Customers, staff, regulators Communications, legal Align messages with recovery milestones
Pay or not pay, disclosure Executives, counsel, board Provide the downtime estimate

The BIA's priority list becomes the rebuild queue. If that list was built for a site loss, it may be wrong for an attack that takes out identity, email, and every endpoint at once. Re-rank it for the scenario where everything is down at the same time and nothing is trusted. The guide to immutable backups and clean-room recovery covers the technical side of restoring into a known-good environment.

Manual workarounds that hold up

Workarounds that work are boring and staged in advance.

  • Offline extracts. A weekly export of the customer master, open orders, price lists, and staff contact list, encrypted and kept on media that is not connected to the network.
  • Paper and phone ordering. Pre-printed order forms, a phone script, and a numbering scheme so orders can be keyed in later without duplicates.
  • Payroll continuity. An arrangement with the payroll provider or bank to rerun the previous cycle if the current one cannot be calculated, with reconciliation afterward.
  • Standalone communications. A notification tool and messaging channel that do not depend on corporate identity or email.
  • Clean devices. A small stock of laptops, still boxed, ready to issue to the recovery team.

Hospitals have run "downtime procedures" for years, and their experience carries a warning: workarounds degrade. Day one on paper is manageable. Day nine, with a growing stack of records to back-enter, is not. Plan the reconciliation as carefully as the workaround.

Decision points the plan should name

Ransomware forces a short list of high-stakes decisions. The plan should name who makes each, with what information.

  1. Declare. Who can declare a cyber crisis and stand up the crisis team.
  2. Isolate. Who can shut down systems or disconnect sites and accept the business impact. Colonial's shutdown was a deliberate choice to limit risk.
  3. Engage. The incident response firm, outside counsel (partly to protect privilege where possible), the insurer, and law enforcement. CISA's Stop Ransomware hub lists the federal reporting routes.
  4. Pay or not. A legal and executive decision, never a technical one. The Treasury Department's Office of Foreign Assets Control has warned that paying a sanctioned person or group can violate US sanctions even when the payer did not know who was on the other end (OFAC's 2021 updated advisory). Counsel needs to work that question before anyone opens a wallet. Paying does not guarantee that stolen data stays private, either. Change Healthcare's parent company said it paid $22 million in 2024, still faced further extortion over the data, and put its total costs in the billions.
  5. Disclose. Public companies may have SEC disclosure obligations for material incidents, New York–regulated financial firms have their own notification rules (including for extortion payments), and sector regulators add more.
  6. Restore. Who signs off that a system is clean enough to return to production.
  7. Reopen. When to tell customers you are back, and at what capacity.

The long middle: responder fatigue

A serious ransomware recovery is a marathon run at sprint pace. The same handful of infrastructure engineers, identity administrators, and help-desk leads are needed at every step, and they will try to work straight through. By the end of the first week, fatigue produces mistakes: a restore pointed at the wrong target, a firewall change with no ticket, a short temper on an executive bridge call.

Build these into the plan before you need them:

  • A shift structure from day two. Twelve-hour shifts at most, formal handovers, a written status log.
  • Named depth. At least two people who can perform each critical recovery task, plus partner or vendor staff arranged in advance.
  • A team resiliency lead. Someone whose job is to watch for stress signs (irritability, tunnel vision, refusal to hand off, rising error rates) and send people home.
  • Logistics. Food, transport, and hotels, handled by a non-responder.
  • Aftercare. Employee assistance contacts, real time off after stand-down, and an after-action review that also asks how the team held up.

Exercising the outage, not just the attack

Most ransomware tabletops stop at hour four, once the incident response firm is on the phone. The expensive part comes later. Run one that jumps to day five and day twelve: the CFO wants a downtime estimate, a large customer is threatening to move volume, the help desk is three people short, and the first rebuilt systems are ready but nobody has defined "clean." Pair it with live tests. Run order entry on paper for an hour, and time a restore from immutable backups into an isolated environment to learn your real throughput. The guide to designing a tabletop exercise that exposes real gaps has the structure, and the annotated business continuity plan outline shows where each of these decisions belongs in the plan.

Downtime readiness checklist

  • BIA impacts are expressed per day, per function, and separate lost from deferred revenue
  • The restore order has been re-ranked for "everything down, nothing trusted"
  • Executives have seen a downtime estimate for a three-week outage
  • Offline extracts of critical data are produced and test-restored on a schedule
  • Manual workarounds are written, staged, and practiced by the people who would use them
  • The pay-or-not decision owner, counsel, and sanctions screening step are named
  • Out-of-band communications work without corporate email or identity
  • Shift, fatigue, and logistics arrangements are written into the plan
  • At least one exercise has gone past day five

Frequently asked questions

Does paying the ransom shorten the outage?

Rarely by much. Decryptors can be slow and unreliable, and the environment still has to be investigated, cleaned, and validated before production. Paying may help when backups are gone, but it does not replace a rebuild.

How do we estimate downtime cost without a finished BIA?

Start with finance: daily revenue, daily payroll, and the penalty clauses in your largest customer contracts. Estimate what share of revenue is lost rather than delayed, and assume a multi-week disruption with partial recovery in weeks two and three. A rough, defensible number now beats a precise one after the incident.

Who should decide whether to pay?

Senior executives, usually with board involvement, advised by outside counsel, the incident response firm, and the insurer. Counsel should screen for sanctions exposure and disclosure obligations first. The continuity team supplies the downtime estimate and the status of workarounds that inform the choice.

How long should we assume a ransomware recovery will take?

Longer than any four-hour RTO. Publicly reported cases commonly involve weeks of disruption before operations are close to normal, followed by a long tail of cleanup and reconciliation. Planning on two to four weeks for core systems is more realistic and produces better workaround planning.

Ransomware Downtime: Why the Outage Costs More Than the Ransom | CPE World