The true cost of a ransomware attack, with and without BCDR
· BleepingComputerWhen businesses assess the impact of ransomware, the ransom payment often gets the most attention. But the ransom is only a small part of the total cost.
According to IBM's Cost of a Data Breach Report 2025, the average total cost of a ransomware incident reached $5.08 million when downtime, remediation, legal work and business disruption are considered. By comparison, the median ransom payment is $139,875, according to the 2026 Verizon Data Breach Investigations Report.
The gap highlights that the biggest ransomware costs often come after the attack, not from the ransom itself.
This piece examines where those costs come from and how a mature business continuity and disaster recovery (BCDR) strategy can help reduce them.
The ransom is only the first line on the invoice
A ransomware attack does not produce a single bill. It creates multiple costs at the same time: lost revenue while systems are down, recovery and remediation expenses, legal and compliance work and the operational disruption that continues until the business is back on its feet.
Downtime is where the bill starts to grow
The longer critical systems remain unavailable, the more expensive an incident becomes.
The Datto State of BCDR Report 2025 found that more than 60% of organizations believed they could recover from an incident in under a day, yet only 35% did.
Every additional hour of downtime means lost productivity, delayed transactions, disrupted customer service, and IT teams pulled away from normal operations to focus on recovery.
For mid-market businesses, recovery time is not an IT metric but a financial metric. The faster critical operations can be restored, the more of these costs can be contained.
Recovery adds another layer to the bill
Attackers increasingly target backup infrastructure during ransomware attacks, potentially leaving organizations with fewer recovery options. If backups are compromised, recovery may require forensic investigations, incident response specialists, system rebuilds, new software and significant internal IT resources.
And even when backups exist, they are only useful if they are clean, accessible and recoverable.
This is where BCDR maturity matters. A backup tells you that a copy of your data exists. A tested recovery strategy tells you how quickly you can turn that copy into a functioning business.
Then comes the compliance cost
While IT teams are working to contain and recover from an attack, the regulatory clock is already running.
EU’s General Data Protection Regulation (GDPR) requires notification of a qualifying personal data breach within 72 hours of becoming aware of it. The SEC requires public companies to disclose material cybersecurity incidents within four business days. Other regulations, including HIPAA, impose their own requirements.
That creates another potential cost layer: legal support, investigation, notification, reporting and regulatory exposure.
The longer recovery takes and the less prepared the organization is, the harder it becomes to manage these obligations alongside the technical response.
How Does Your Recovery Plan Stack Up? The Data Might Surprise You.
Most organizations believe they can recover from an incident in under a day — but only 35% actually do.
The Datto State of BCDR Report 2025 reveals the recovery gaps putting businesses at risk, and what mature BCDR looks like in practice.
The faster you recover, the smaller the ransomware bill
And that brings us back to the central question of ransomware economics: How quickly can a business recover?
The Datto RTO & Downtime Cost Calculator can help businesses and MSPs quantify that exposure and build a more concrete case for investing in resilience.
A mature BCDR strategy cannot necessarily prevent a ransomware attack. But it can help reduce the time the business remains disrupted, limit recovery complexity, give the organization a more predictable path back to operations and reduce the size of the bill that follows.
What changes when BCDR is in place
The real value of BCDR becomes clear when you compare the cost of being unable to operate with the speed of recovery.
When Techify, a Datto MSP partner, received a call about a client hit by ransomware through a compromised printer, the team restored 19 TB of data and had the business fully operational in under two hours. The client did not pay a ransom or wait weeks to rebuild its environment.
That is the difference BCDR can make by turning recovery from a prolonged business crisis into a controlled IT event.
Recover in minutes, not days
After a ransomware attack, every hour of downtime adds to the cost. Datto BCDR is designed to reduce that recovery window by capturing snapshots of entire systems, including files, operating systems, applications and settings, at intervals as short as five minutes.
When an attack occurs, affected systems can be virtualized on the backup appliance or in the Datto Cloud while the compromised environment is isolated. This allows the business to resume critical operations while the IT team investigates the attack and works toward full recovery.
The goal is to help restore access to the business first, then complete the recovery process in the background.
Immutable backups give you a clean path to recovery
Speed only matters if you have a clean recovery point to return to.
Ransomware operators increasingly target backup infrastructure because destroying backups can leave organizations with few alternatives. Datto protects cloud backups using write-once-read-many (WORM) storage, helping prevent backup data from being modified or deleted by ransomware. Machine learning-based anomaly detection also monitors backup activity for unusual patterns.
Together, these capabilities provide a clean and usable path back to operations during an attack.
Turn downtime into a number
The most important BCDR conversation should happen before the ransomware call.
Instead of asking, "What would a ransomware attack cost us?", calculate what each hour of downtime costs the business. Then compare that figure with the organization's recovery time objective (RTO), recovery point objective (RPO), and the cost of achieving them.
The equation is straightforward:
Cost of downtime × recovery time + recovery and remediation costs + potential legal and regulatory costs = potential business impact.
Once that number is visible, the business case for BCDR becomes much easier to understand.
Whether you’re positioning yourself as a strategic partner in BCDR or fortifying your own organization’s resilience, the Datto State of BCDR Report 2025 offers actionable takeaways to help you stay ahead of cyberattacks.
Sponsored and written by Datto.