Skip to content

Cybersecurity business continuity

The True Downtime Cost Framework

If someone told you to lock your doors, power everything off, and not open again for 30 days - no sales, no service, no revenue - could you afford it? That is exactly what a serious cyberattack asks of you. The ransom is the smallest number on the list.

Illustration for the article: The True Downtime Cost Framework
If someone told you to lock your doors, power everything off, and not open again for 30 days - no sales, no service, no revenue - could you afford it? That is exactly what a serious cyberattack asks of you. The ransom is the smallest number on the list.

Here is a question I ask every business owner I sit down with.

If someone walked in tomorrow and told you to lock your doors, power everything off, send your staff home, and not open again for 30 days – no sales, no service, no revenue – could you afford it?

Most cannot answer that question immediately. They pause. They start doing math in their head. And somewhere in that pause, the conversation changes.

Because that is exactly what a serious cyberattack asks of you. Not the dramatic Hollywood version where a hacker demands a ransom and you wire the money and life goes back to normal. The reality is slower, messier, and far more expensive than most business owners have ever been shown.

The Number They Always Lead With

When I ask a business owner what a cyberattack would cost them, they almost always lead with the ransom. That is the number they have heard about. That is the check they imagine writing.

It is the wrong number to start with.

I had a client whose bank caught a $60,000 ACH wire transfer that had been redirected through a man-in-the-middle email attack. The bank caught it – this time. That $60,000 was the number the owner could see. What they could not see was everything underneath it: the cost of the investigation, the forensic work, the staff hours lost, the client communication required, the question of whether other accounts had been compromised.

The wire transfer is the number that makes the news. The True Downtime Cost is everything that does not.

The Six-Part Formula

When I walk a business owner through what a real incident actually costs, I build it in six layers. Most people have never seen all six at once.

1. Payroll – for work that is not happening

A serious ransomware attack does not pause your payroll. Your staff still gets paid while your systems are down, while the forensic team is working, while the rebuilding process is underway. For most businesses, that is two full payroll cycles – 30 days – before operations are anywhere close to normal. That clock starts running on day one whether you are generating revenue or not.

2. Regulatory fines and FTC exposure

If customer data was accessed – and in most attacks, it was – you are now in a conversation with regulators. The FTC has enforcement authority over data security practices. State breach notification laws have timelines and requirements that begin the moment the breach is discovered. Missing those deadlines adds fines to an already expensive situation.

3. Identity protection for every customer in your database

This one surprises people. If your customer records were exposed, the standard response is to provide identity protection services to every affected individual – typically for a minimum of one year. If you have 2,000 customers in your database, you are providing identity protection for 2,000 people for 12 months. That is not a small line item.

4. Hardware replacement

Here is where it gets expensive in ways most people do not anticipate. After a ransomware attack, you do not just clean the infected systems and move on. Every machine that touched the network is suspect. Paying the ransom does not make your data safe and it does not close the door – it just hands you back a key while the attacker potentially still has one of their own.

What actually has to happen: every PC gets wiped and inspected. Servers get rebuilt from scratch. Dormant software sitting on an uncleaned machine is an open door waiting for the next round. You are not just recovering from an attack – you are rebuilding an environment you can actually trust.

5. Software rebuilding and system migration

This is the cost nobody budgets for because nobody thinks about what rebuilding actually means until they are inside it.

Stay Ahead of Technology Risk

Practical, no-jargon insights on cybersecurity, resilience, and IT strategy - built for business leaders, not engineers.

I worked at a company that ran a single server hosting all company files with no backups. If that server had been ransomed, the recovery process would have looked like this: wipe the server, attempt data recovery, reload the operating system, reinstall every application, recreate every user account, reset every permission, and migrate everything to current software versions – because you did not update for eight years and now you have no choice.

That process takes weeks. It requires outside expertise. And it costs money at every step.

6. The insurance that does not pay

This is the one that hits hardest. Most business owners with cyber insurance believe they have a safety net. What they actually have is a policy that was filled out based on what they thought their security posture was – not what it actually was.

I have yet to see a cyber insurance claim filed correctly and honestly. Not because business owners are dishonest – because nobody ever showed them what the policy actually required them to have in place. When the claim is filed after the attack, the gap between the application and reality becomes the reason the claim is denied.

So add that to the list: the money they paid in premiums, and the payout they expected and will not receive.

The Business That Does Not Survive

Here is the honest conversation.

Most businesses I work with have not been ransomed. They have planned for workers compensation. They are bonded and insured against installation failures – fires, equipment failures, HVAC units dropping through a roof during a lift. They have thought carefully about the physical risks their business faces.

What they have not planned for is the digital one.

And the digital one is not a 50/50 proposition anymore. That framing is outdated. It is not a question of whether it will happen. It is a question of when – and whether you will still have a business on the other side of it.

Most businesses that face a serious ransomware event without preparation do not write a check and recover. They close. Not because the ransom was too high. Because the total cost of everything underneath the ransom – the payroll, the fines, the hardware, the rebuilding, the lost revenue, the insurance that did not pay – added up to a number the business could not absorb.

They planned for a worker getting hurt on a job site. They did not plan for the thing that is statistically more likely to put them out of business.

What the Framework Is Actually For

The True Downtime Cost framework is not meant to frighten you. It is meant to give you an accurate number.

Because here is what I find when I walk business owners through all six layers: the number is always bigger than they expected. And once they see the real number, the conversation about prevention changes completely.

Spending money on backups, security tools, staff training, and proper insurance documentation stops feeling like an IT expense. It starts feeling like what it actually is – the most affordable version of an event you do not want to survive twice.

The question is not whether you can afford to protect your business.

The question is whether you could afford 30 days with the doors locked.

Kelly Hansen is the author of The IT Dilemma: Why Good Businesses Fail During Cyberattacks, Outages, and Technology Disasters – and How to Prevent It. Have a question about your own environment? Reach out: Contact, or connect with me on LinkedIn.

Key Takeaways

  • The ransom is the wrong number to start with — it is the smallest item on the list
  • Paying the ransom does not make your data safe and does not close the door
  • Cyber insurance almost never pays out because applications are never filled out honestly or correctly
  • It is not a 50/50 proposition anymore — it is a matter of when
  • The question is not whether you can afford to protect your business — it is whether you could afford 30 days with the doors locked