What a breach costs
on Wall Street
Stock performance of public NASDAQ and NYSE companies in the days, months, and year after a major cybersecurity incident was disclosed. Each line is indexed to 0 at the disclosure date.
The board question every CISO faces: "What's the real cost of a breach?" This page answers with market data. The stock doesn't lie — it prices in regulatory fines, remediation costs, lost revenue, executive departures, and reputational damage simultaneously.
Ransomware hurts longer than data theft
Ransomware attacks correlate with extended operational disruption — visible to markets as lost revenue, not just cleanup costs. Data exfiltration breaches often see faster recovery as long as there's no secondary regulatory fallout.
The disclosure delay amplifies the drop
Companies that disclosed quickly (MGM: 3 days, Colonial: 1 day) saw shorter initial shock windows. Delayed disclosures (Equifax: 78 days, Marriott: 4 years) tend to see sharper drops at disclosure as pent-up uncertainty resolves at once.
Supply chain multiplies the blast radius
SolarWinds and MOVEit show that being the attack vector — not just a victim — creates existential investor pressure. Markets price in the liability of thousands of downstream customers.
The MGM vs Caesars experiment
Same week, same attacker (Scattered Spider), same sector. Caesars paid ~$15M ransom, avoided operational disruption, and barely moved. MGM refused, suffered 10 days of outages, and lost an estimated $100M in EBITDA. The market noticed.
Put this in front of your board
CISOs who present breach impact in market terms get bigger budgets. Use PlayCISO to simulate a live incident, then generate a board-ready risk report with the financial impact modeled.
No card needed · Free to try
Stock price data sourced from Yahoo Finance. Breach details sourced from public disclosures, SEC 8-K filings, and ITRC reports. Cost figures are disclosed or estimated totals; actual costs often exceed disclosed figures. This page is updated weekly. Not financial advice.