🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
All posts

How Much Does a Ransomware Attack Cost a Company?

September 19, 2026 · PlayCISO

A ransomware attack costs a company far more than the ransom demand itself. The total price is the sum of several categories: the ransom payment (if made), downtime and lost revenue, incident response and forensics, system recovery and rebuilds, legal and regulatory costs, and long-term reputational damage. For most organizations, downtime and recovery—not the ransom—are the largest line items. Treating the ransom figure as "the cost" leads to badly underfunded defenses.

The costs that show up on day one

These are the direct, immediate expenses that hit as soon as systems go dark:

  • Ransom payment — if you pay, this is one number. But paying doesn't guarantee full recovery, and decryption tools are often slow and incomplete.
  • Downtime — every hour production, sales, or clinical systems are offline has a dollar value. For revenue-generating operations, this frequently exceeds the ransom within days.
  • Incident response — external forensics, DFIR retainers, and emergency consultants bill quickly during an active incident.
  • Overtime and staffing — your own team works around the clock, and you may hire temporary help to keep the business running manually.

The costs that arrive later

The bill doesn't stop when systems are restored. Several categories accrue over weeks and months:

  • System rebuilds — many organizations rebuild rather than trust decrypted or restored machines, which extends recovery time and cost.
  • Legal and regulatory — breach notification, regulatory fines, and legal counsel, especially where personal or health data was exposed.
  • Customer and partner churn — lost contracts and canceled deals after an outage or data exposure.
  • Insurance premium increases — a claim typically raises your cyber insurance costs at renewal, if you remain insurable at all.

Why the range is so wide

There is no single dollar figure for a ransomware attack because the outcome depends on your organization. A small business with good backups might recover in days for a modest amount. A hospital or manufacturer with interconnected systems and no tested recovery plan can face weeks of disruption and losses that threaten the business. The variables that matter most:

  • Whether you have tested, offline backups you can actually restore from.
  • How much of the business depends on the affected systems.
  • The sensitivity of exposed data and the regulations that apply.
  • How fast you can detect and contain the intrusion before encryption spreads.

What this means for your budget

The lesson for security leaders is that the ransom is the wrong anchor for planning. Investments that shrink downtime and recovery time—tested backups, network segmentation, an incident response plan you've actually rehearsed, and reliable detection—cut the largest cost categories, not just the smallest one. When you make the business case for security spend, frame it against total incident cost, not the headline ransom.

To put a defensible number on what an attack would cost your organization, try PlayCISO's free Breach Cost Calculator—it helps you model downtime, recovery, and regulatory exposure so you can back your budget requests with figures leadership understands.

Ready to practise the decisions these articles describe?

Run a free War Room →