{
  "slug": "ransomware-downtime-cost",
  "title": "Ransomware Downtime Cost Calculator",
  "heading": "Ransomware Downtime Cost Calculator",
  "category": "financial",
  "url": "https://www.revenuelab.fyi/toolbox/ransomware-downtime-cost",
  "summary": "Model lost revenue, labor, and recovery cost for each day systems are down.",
  "description": "The ransom demand is usually the smallest number in a ransomware incident. Downtime cost, which includes lost revenue, idle payroll, overtime for recovery staff, and rebuilding systems from backup, typically runs 5-10x the ransom itself according to Sophos and Coveware incident data. This calculator estimates daily revenue loss based on your normal daily revenue and what fraction of operations are actually knocked offline (a manufacturing plant with paper-based fallback loses less than a pure e-commerce site), adds idle and overtime labor costs, and multiplies by your estimated recovery timeline. Recovery time is the input people underestimate most: restoring from backup sounds fast until you account for rebuilding domain controllers, re-imaging endpoints, validating data integrity, and staged bring-up of interdependent systems, which routinely stretches a 'we have backups' recovery from 2 days to 3 weeks.",
  "formula": "Downtime cost = (daily revenue × operational impact %) × recovery days + (idle labor cost + overtime cost) × recovery days.",
  "dateModified": "2026-09-30",
  "run_url": "https://www.revenuelab.fyi/api/public/calc?tool=ransomware-downtime-cost",
  "inputs": [
    {
      "id": "dailyRevenue",
      "label": "Normal daily revenue",
      "kind": "number",
      "hint": null,
      "default": 150000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "operationalImpact",
      "label": "Share of operations knocked offline",
      "kind": "number",
      "hint": null,
      "default": 70,
      "unit": null,
      "min": 0,
      "max": 100
    },
    {
      "id": "recoveryDays",
      "label": "Estimated recovery time",
      "kind": "number",
      "hint": null,
      "default": 12,
      "unit": null,
      "min": 0.5,
      "max": 90
    },
    {
      "id": "idleLaborDay",
      "label": "Idle staff labor cost per day",
      "kind": "number",
      "hint": null,
      "default": 8000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "overtimeDay",
      "label": "IT/recovery overtime cost per day",
      "kind": "number",
      "hint": null,
      "default": 4000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "ransomAmount",
      "label": "Ransom demand (for comparison)",
      "kind": "number",
      "hint": null,
      "default": 250000,
      "unit": null,
      "min": 0,
      "max": null
    }
  ],
  "outputs": [
    {
      "id": "totalCost",
      "label": "Total downtime cost",
      "format": "currency",
      "hint": null,
      "primary": true
    },
    {
      "id": "revenueLoss",
      "label": "Lost revenue",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "laborCost",
      "label": "Idle + overtime labor cost",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "dailyLossRate",
      "label": "Cost per day of downtime",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "ratioToRansom",
      "label": "Downtime cost as multiple of ransom demand",
      "format": "decimal",
      "hint": null,
      "primary": false
    }
  ],
  "worked_example": {
    "inputs": [
      "Normal daily revenue: 150000",
      "Share of operations knocked offline: 70",
      "Estimated recovery time: 12",
      "Idle staff labor cost per day: 8000",
      "IT/recovery overtime cost per day: 4000",
      "Ransom demand (for comparison): 250000"
    ],
    "outputs": [
      "Total downtime cost: $1,404,000",
      "Lost revenue: $1,260,000",
      "Idle + overtime labor cost: $144,000",
      "Cost per day of downtime: $117,000",
      "Downtime cost as multiple of ransom demand: 5.6"
    ]
  },
  "how_to": {
    "title": "How to use this",
    "steps": [
      "Enter normal daily revenue.",
      "Enter share of operations knocked offline.",
      "Enter estimated recovery time.",
      "Enter idle staff labor cost per day.",
      "Enter it/recovery overtime cost per day.",
      "Enter ransom demand (for comparison).",
      "Read your total downtime cost on the right — it updates as you type.",
      "Hit Share to keep the scenario or send it to someone."
    ]
  },
  "scenarios": [
    {
      "name": "Conservative",
      "description": "Lower-end numbers — what if things land soft?",
      "values": {
        "dailyRevenue": 90000,
        "operationalImpact": 40,
        "recoveryDays": 7.199999999999999,
        "idleLaborDay": 5000,
        "overtimeDay": 2500,
        "ransomAmount": 150000
      }
    },
    {
      "name": "Typical",
      "description": "Defaults — the most common real-world setup.",
      "values": {
        "dailyRevenue": 150000,
        "operationalImpact": 70,
        "recoveryDays": 12,
        "idleLaborDay": 8000,
        "overtimeDay": 4000,
        "ransomAmount": 250000
      }
    },
    {
      "name": "Ambitious",
      "description": "Higher-end numbers — what if things really pop?",
      "values": {
        "dailyRevenue": 240000,
        "operationalImpact": 100,
        "recoveryDays": 19.200000000000003,
        "idleLaborDay": 13000,
        "overtimeDay": 6500,
        "ransomAmount": 400000
      }
    }
  ],
  "limitations": [
    "Results are estimates before tax, fees, and inflation unless an input explicitly covers them.",
    "Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.",
    "This is educational maths, not financial advice. Check anything contractual with the lender or your accountant."
  ],
  "faq": [
    {
      "q": "Why is downtime so much worse than the ransom itself?",
      "a": "The ransom is a one-time payment demand, but downtime bleeds revenue, payroll, and customer trust every single day systems are down, and recovery is never instant even with good backups. Coveware and Sophos data consistently show total incident cost running 5-10x the ransom demand once you count business interruption."
    },
    {
      "q": "How do I estimate recovery days more accurately?",
      "a": "Run a tabletop exercise where you actually time a restore of a representative system from backup, including validation, not just the copy job. Most organizations that haven't tested this discover their real recovery time is 3-5x longer than assumed because of dependency chains between systems."
    },
    {
      "q": "Does paying the ransom reduce downtime?",
      "a": "Sometimes, but not reliably. Coveware's incident response data shows decryptors provided by attackers frequently fail to fully restore data, meaning many victims still rebuild from backup after paying, so budget recovery time as if payment won't happen even if leadership decides to pay."
    },
    {
      "q": "What's the single best lever to reduce this number?",
      "a": "Tested, immutable, offline backups with a known and rehearsed restore procedure. Every other control (EDR, segmentation, MFA) reduces the chance of the event; backups are what determine how many days the recovery-days input actually is."
    }
  ],
  "related": [
    "https://www.revenuelab.fyi/toolbox/annualized-loss-expectancy",
    "https://www.revenuelab.fyi/toolbox/backup-rpo-rto-data-loss-cost",
    "https://www.revenuelab.fyi/toolbox/soc-staffing-coverage"
  ],
  "license": "CC-BY-4.0",
  "citation": "RevenueLab — Ransomware Downtime Cost Calculator (https://www.revenuelab.fyi/toolbox/ransomware-downtime-cost)"
}