The Ransom Is Rarely the Real Number
When organizations budget for ransomware risk, the instinct is to price out the ransom demand. That instinct is wrong, and industry data backs this up consistently. IBM's Cost of a Data Breach Report 2025 put the average cost of a ransomware or extortion breach at $5.08 million once downtime, remediation, legal work, and business disruption are factored in — while the median ransom payment was just $139,875. The gap between those two numbers is the entire story: the payment attackers demand is a rounding error next to what the incident actually costs to survive.
Separately, Sophos' State of Ransomware 2025 survey found the mean cost to recover from an attack, excluding any ransom paid, was $1.53 million. Whether or not a victim pays, recovery itself is the expensive part.
Where the Money Actually Goes
Downtime and lost revenue. This is consistently the largest and least predictable cost. Coveware and other incident-response trackers put average ransomware-related downtime at around 24 days industry-wide in 2026, though outcomes vary widely by sector — highly regulated industries like healthcare can take many months to fully "normalize" every system and satisfy compliance obligations. Every additional day offline compounds lost sales, idle payroll, missed SLAs, and stalled operations.
Incident response and forensics. Engaging outside IR firms, malware reverse-engineering, root-cause analysis, and chain-of-custody evidence collection for law enforcement or insurers all carry specialist hourly rates that add up quickly, especially on a compressed timeline.
Recovery and rebuild costs. A growing and underappreciated risk is restoring from a compromised backup. Analysts tracking recovery failures have flagged that a large share occur because organizations unknowingly restore infected backups, undoing the recovery and resetting the clock. That reality has pushed some practitioners toward "Mean Time to Clean Recovery" — not just how fast you restore, but how fast you restore and confirm the restoration is actually clean — as the metric that matters.
Legal and regulatory obligations. Breach notification law adds hard deadlines on top of an already chaotic recovery: GDPR requires notification to regulators within 72 hours of becoming aware of a breach, and U.S. public companies face SEC rules requiring disclosure of material incidents within four business days. Missing those windows carries its own penalties, independent of the attack itself.
Reputational and customer-trust cost. Harder to put a single number on, but real: churn among affected customers, lost new-business pipeline, and negative press cycles all show up in revenue well after the incident is technically "closed."
Insurance premium impact. Cyber insurers increasingly price policies — and in some cases exclude coverage — based on an applicant's backup and recovery maturity, meaning weak BCDR posture shows up as a direct, recurring cost even in years without an attack.
How BCDR Maturity Changes the Math
This is where business continuity and disaster recovery (BCDR) planning earns its keep. A recent BleepingComputer piece examining Datto's BCDR approach illustrates the core idea: when local systems and even local backups are compromised, clean and isolated copies of data held elsewhere let a business restore operations without negotiating with an attacker or gambling on a decryption key ever working. Datto's own State of BCDR Report 2025 found a sobering gap between confidence and reality — 60% of organizations believed they could recover within a day, but only 35% actually did — which is precisely the gap a tested, immutable, verified backup strategy is designed to close.
Mature BCDR doesn't just make recovery possible; it makes the cost of an attack predictable. Instead of an open-ended outage measured in weeks, organizations with tested failover and verified-clean backups can often resume operations in hours, running from a virtualized environment while primary systems are rebuilt in the background. That shift — from "how bad could this get" to "we know roughly what this costs" — is the actual return on BCDR investment.
A Practical Takeaway for IT and Security Teams
Evaluating your own BCDR posture doesn't require a specific vendor — it requires honest answers to a few questions:
- Are backups immutable and isolated from the production network an attacker could reach?
- Are backups actually tested, including a full restore drill, not just a successful nightly job log?
- Is there a way to verify a backup is clean before it's trusted for recovery, rather than discovering an infection mid-restore?
- Do you know your real recovery time, measured from a live drill, not the number on a vendor's slide deck?
- Does your incident response plan account for legal notification deadlines, not just technical recovery steps?
None of this eliminates the risk of a ransomware attack. What it does is convert an open-ended, business-threatening event into a bounded, budgetable one — which, based on the numbers above, is where the real savings are.