ZeroHour
BleepingComputerpublished ()ingested Sponsored by Datto

The true cost of a ransomware attack, with and without BCDR

infoIndustryimportance 20
AI summary · glm-5.3-flash

Ransomware's true cost averages $5.08 million per incident versus a $139,875 median ransom, and mature BCDR strategies with immutable backups cut downtime and recovery expenses.

IBM's Cost of a Data Breach Report 2025 puts the average ransomware incident at $5.08 million, far above the $139,875 median ransom payment cited in Verizon's 2026 DBIR. Datto's State of BCDR Report 2025 found 60% of organizations believed they could recover within a day, but only 35% actually did. The Datto-sponsored piece argues mature BCDR with immutable WORM backups shortens downtime, citing a Techify case that restored 19 TB and returned a client to operations in under two hours without paying a ransom. It also flags compliance deadlines such as GDPR's 72-hour breach notification and the SEC's four-business-day disclosure rule.

  • Average ransomware incident costs $5.08M versus $139,875 median ransom payment
  • Only 35% of organizations that expected sub-day recovery achieved it
  • Ransomware operators increasingly target backup infrastructure to block recovery
  • GDPR requires 72-hour notification; SEC requires disclosure within four business days
VendorsDatto
ProductsDatto BCDR
OrganizationsIBMVerizonTechify
Full article994 words · extracted from bleepingcomputer.com · click to collapse

Ransomware attack invoice

When businesses assess the impact of ransomware, the ransom payment often gets the most attention. But the ransom is only a small part of the total cost.

According to IBM's Cost of a Data Breach Report 2025, the average total cost of a ransomware incident reached $5.08 million when downtime, remediation, legal work and business disruption are considered. By comparison, the median ransom payment is $139,875, according to the 2026 Verizon Data Breach Investigations Report.

The gap highlights that the biggest ransomware costs often come after the attack, not from the ransom itself.

This piece examines where those costs come from and how a mature business continuity and disaster recovery (BCDR) strategy can help reduce them.

The ransom is only the first line on the invoice

A ransomware attack does not produce a single bill. It creates multiple costs at the same time: lost revenue while systems are down, recovery and remediation expenses, legal and compliance work and the operational disruption that continues until the business is back on its feet.

Downtime is where the bill starts to grow

The longer critical systems remain unavailable, the more expensive an incident becomes.

The Datto State of BCDR Report 2025 found that more than 60% of organizations believed they could recover from an incident in under a day, yet only 35% did.

Every additional hour of downtime means lost productivity, delayed transactions, disrupted customer service, and IT teams pulled away from normal operations to focus on recovery.

For mid-market businesses, recovery time is not an IT metric but a financial metric. The faster critical operations can be restored, the more of these costs can be contained.

Recovery adds another layer to the bill

Attackers increasingly target backup infrastructure during ransomware attacks, potentially leaving organizations with fewer recovery options. If backups are compromised, recovery may require forensic investigations, incident response specialists, system rebuilds, new software and significant internal IT resources.

And even when backups exist, they are only useful if they are clean, accessible and recoverable.

This is where BCDR maturity matters. A backup tells you that a copy of your data exists. A tested recovery strategy tells you how quickly you can turn that copy into a functioning business.

Then comes the compliance cost

While IT teams are working to contain and recover from an attack, the regulatory clock is already running.

EU’s General Data Protection Regulation (GDPR) requires notification of a qualifying personal data breach within 72 hours of becoming aware of it. The SEC requires public companies to disclose material cybersecurity incidents within four business days. Other regulations, including HIPAA, impose their own requirements.

That creates another potential cost layer: legal support, investigation, notification, reporting and regulatory exposure.

The longer recovery takes and the less prepared the organization is, the harder it becomes to manage these obligations alongside the technical response.

The faster you recover, the smaller the ransomware bill

And that brings us back to the central question of ransomware economics: How quickly can a business recover?

The Datto RTO & Downtime Cost Calculator can help businesses and MSPs quantify that exposure and build a more concrete case for investing in resilience.

A mature BCDR strategy cannot necessarily prevent a ransomware attack. But it can help reduce the time the business remains disrupted, limit recovery complexity, give the organization a more predictable path back to operations and reduce the size of the bill that follows.

What changes when BCDR is in place

The real value of BCDR becomes clear when you compare the cost of being unable to operate with the speed of recovery.

When Techify, a Datto MSP partner, received a call about a client hit by ransomware through a compromised printer, the team restored 19 TB of data and had the business fully operational in under two hours. The client did not pay a ransom or wait weeks to rebuild its environment.

That is the difference BCDR can make by turning recovery from a prolonged business crisis into a controlled IT event.

Recover in minutes, not days

After a ransomware attack, every hour of downtime adds to the cost. Datto BCDR is designed to reduce that recovery window by capturing snapshots of entire systems, including files, operating systems, applications and settings, at intervals as short as five minutes.

When an attack occurs, affected systems can be virtualized on the backup appliance or in the Datto Cloud while the compromised environment is isolated. This allows the business to resume critical operations while the IT team investigates the attack and works toward full recovery.

The goal is to help restore access to the business first, then complete the recovery process in the background.

Immutable backups give you a clean path to recovery

Speed only matters if you have a clean recovery point to return to.

Ransomware operators increasingly target backup infrastructure because destroying backups can leave organizations with few alternatives. Datto protects cloud backups using write-once-read-many (WORM) storage, helping prevent backup data from being modified or deleted by ransomware. Machine learning-based anomaly detection also monitors backup activity for unusual patterns.

Together, these capabilities provide a clean and usable path back to operations during an attack.

Turn downtime into a number

The most important BCDR conversation should happen before the ransomware call.

Instead of asking, "What would a ransomware attack cost us?", calculate what each hour of downtime costs the business. Then compare that figure with the organization's recovery time objective (RTO), recovery point objective (RPO), and the cost of achieving them.

The equation is straightforward:

Cost of downtime × recovery time + recovery and remediation costs + potential legal and regulatory costs = potential business impact.

Once that number is visible, the business case for BCDR becomes much easier to understand.

Whether you’re positioning yourself as a strategic partner in BCDR or fortifying your own organization’s resilience, the Datto State of BCDR Report 2025 offers actionable takeaways to help you stay ahead of cyberattacks.

Sponsored and written by Datto.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/