A ransomware incident can cost an organization hundreds of thousands to several million dollars. The total is often much higher than the ransom because an attack can stop operations, require specialist recovery work, trigger legal obligations and damage customer trust.
Recent benchmarks show:
| Cost benchmark | Reported amount | What it measures |
|---|---|---|
| Average recovery cost | $1.7 million | Sophos' 2026 average recovery cost, excluding ransom payments |
| Median ransom payment | $769,000 | Sophos' 2026 median payment among surveyed organizations |
| Average 2024 SME ransomware incident | $1.1 million | NetDiligence total incident cost where business interruption was recorded |
| Average 2024 SME business interruption cost | $751,000 | Lost income and operating impact from ransomware downtime |
| Five-year SME ransomware average | $2.1 million | Total incident cost for ransomware claims involving business interruption |
These figures measure different losses. A ransom demand, ransom payment, recovery cost and total incident cost are not interchangeable.
What Costs Are Included in a Ransomware Incident?
The total cost usually includes the ransom, lost income, response work, recovery, legal support and the effects of data theft.
1. Ransom Payment
A ransom payment is money sent to attackers, usually in cryptocurrency, in exchange for a decryption key or a promise not to publish stolen data.
Coalition reported that the average ransomware demand in 2024 was $1.1 million. Demands varied widely by ransomware group. The average demand linked to Black Basta was about $4 million in Coalition's claims data.
The ransom is only one part of the loss. Organizations that refuse to pay can still face large costs for system restoration, forensic investigation, legal advice and data breach response.
2. Business Interruption and Downtime
Business interruption is often the largest cost when employees cannot access essential systems.
Lost revenue and extra operating costs can come from:
- Websites, payment systems or customer portals going offline
- Manufacturing or logistics operations stopping
- Employees losing access to business systems
- Delayed orders, cancelled appointments or missed deadlines
- Service-level agreement credits and contractual penalties
- Emergency manual processes
- Overtime and temporary staff during recovery
NetDiligence found that ransomware claims involving business interruption at small and medium-sized enterprises had an average 2024 total incident cost of $1.1 million. The average business interruption cost was $751,000. Across its five-year dataset, the average total cost was $2.1 million, including $1.4 million attributed to business interruption.
3. Incident Response and Forensic Investigation
Incident response and forensic investigation establish how the attackers entered, what they accessed and whether they still have access.
Specialists may need to determine:
- How attackers entered the network
- Which accounts and systems were compromised
- Whether attackers stole data before encrypting systems
- Whether malware or backdoors remain active
- Whether systems are safe to reconnect
- Which evidence should be preserved for law enforcement or regulators
The bill may include emergency cybersecurity consultants, malware analysis, digital forensics, threat hunting and 24-hour response support.
4. Recovery and Rebuilding
Recovery and rebuilding return systems to a safe operating state.
The work may include:
- Restoring data from backups
- Rebuilding servers, endpoints and cloud environments
- Replacing compromised credentials and access tokens
- Reinstalling applications
- Reconfiguring networks and security controls
- Removing unauthorized persistence
- Testing systems before reconnecting them
- Purchasing replacement hardware or temporary infrastructure
Sophos reported an average recovery cost of $1.7 million in its 2026 ransomware research, excluding ransom payments. The research included 2,158 respondents from organizations with between 100 and 5,000 employees.
5. Legal, Regulatory and Notification Costs
A ransomware incident involving personal, financial, health or confidential business data may require legal advice and breach response.
Potential costs include:
- Legal counsel
- Regulatory assessments
- Customer and employee notifications
- Credit monitoring or identity protection
- Public relations support
- Contract reviews
- Litigation and settlements
- Regulatory penalties, where applicable
The obligations depend on the organization's location, industry, affected data and contractual responsibilities. An incident involving encryption only may have a different legal impact from one involving data theft.
6. Data Extortion and Customer Impact
Data extortion adds another layer of cost when attackers steal information before encrypting systems and threaten to publish or sell it.
CISA says ransomware and data extortion can disrupt critical business processes and cause economic and reputational harm during the attack and the recovery period.
Data theft can lead to:
- Customer churn
- Loss of confidential intellectual property
- Competitive disadvantage
- Supplier and partner concerns
- Fraud monitoring
- Additional regulatory scrutiny
- Public disclosure of sensitive information
Example: How a $1.55 Million Incident Could Develop
The following calculation is illustrative, not an industry average:
| Cost item | Example amount |
|---|---|
| Five days of downtime at $50,000 per day | $250,000 |
| Incident response and recovery | $300,000 |
| Legal, notification and customer support | $500,000 |
| Ransom payment | $500,000 |
| Illustrative total | $1,550,000 |
The organization could still face a major loss without paying the ransom. The ransom line might disappear, but downtime, investigation, rebuilding and legal costs would remain. Some could increase if the recovery took longer.
Does Paying the Ransom Reduce the Total Cost?
Paying a ransom does not guarantee a lower total cost. A payment may provide a decryption tool, but it does not guarantee that files will be recovered or stolen data will be deleted.
CISA warns that victims who pay may receive ineffective decryption tools, face another attack or receive further demands. CISA, the FBI and the NSA strongly discourage ransom payments because they can fund ransomware operations and encourage further criminal activity.
Payment can also create additional costs, including:
- Cryptocurrency transaction and negotiation fees
- Legal advice and sanctions screening
- Tax and accounting treatment
- Investigation into the attacker's identity
- Recovery work that remains necessary after decryption
- Rebuilding systems that cannot be trusted
Why Do Ransomware Costs Vary So Widely?
Ransomware costs vary because the operational, technical and legal effects differ from one incident to the next.
The main factors are:
- Organization size: A large enterprise may lose more revenue per hour than a small business.
- System criticality: An attack on email is disruptive, while an attack on production, healthcare or payment systems may halt core operations.
- Backup quality: Tested, isolated backups can reduce the need to pay and shorten recovery.
- Attacker access: Attackers with domain administrator privileges can affect more systems.
- Data theft: Extortion can create legal, regulatory and reputational costs beyond the outage.
- Recovery time: A one-day outage and a one-month outage produce very different losses.
- Third-party dependencies: A compromised supplier or managed service provider can extend the disruption.
- Insurance coverage: Insurance may cover some costs, but deductibles, exclusions, limits and cash-flow requirements still apply.
NetDiligence's data shows the difference between claim groups. Its SME ransomware claims involving recovery expense had a five-year average incident cost of $961,000. In a small sample of large-company claims with recovery expense, the average incident cost was $10.2 million. The large-company figure varied substantially and should not be treated as a universal benchmark.
How Can You Estimate Your Organization's Ransomware Exposure?
Estimate exposure across three scenarios rather than relying on one average.
Best Case
- The attack is contained before encryption
- No material data theft occurs
- Operations are restored from tested backups
- External consultants are needed for a limited period
- Customer and regulatory effects are minimal
Likely Case
- Operations are disrupted for several days
- External incident response and legal support are required
- Some systems need to be rebuilt
- Customers need to be contacted
- The organization loses revenue and pays overtime
- An insurance deductible applies
Severe Case
- Critical operations stop for an extended period
- Attackers steal data and publish it as part of an extortion attempt
- Critical systems must be rebuilt from scratch
- Customers and suppliers are affected
- Regulators investigate or parties bring litigation
- The organization faces a ransom demand or payment
- Remediation continues and insurance costs rise
A simple planning formula is:
Total ransomware exposure = downtime cost + response cost + recovery cost + legal and notification cost + data-impact cost + ransom payment, if any
Bottom Line
The largest ransomware costs usually come from downtime and recovery, not the ransom alone. Organizations with critical systems should model at least a seven-figure incident scenario, then test whether their backups, response plan and insurance would cover the cash demands of a prolonged outage.
The strongest cost controls are offline backups, tested restoration procedures, rapid detection, multifactor authentication, privileged-access controls, an incident response plan and regular recovery exercises. CISA specifically recommends offline encrypted backups and tested restoration because accessible backups may also be deleted or encrypted during an attack.