What Ransomware Actually Costs (Beyond the Ransom)

Photo of Brian Largent

Brian Largent

CEO, ArcLight Group

May 11, 2026 8 min read
Share:
Virtual Chief Information Officer Services Tulsa Team

Everyone asks the same question: “How much does ransomware cost?”

And they almost always mean the ransom itself. The dollar figure the attacker puts on the screen. Fifty thousand, two hundred thousand, a million, whatever the number is.

I’m here to tell you, that number is the least of your problems.

After 30+ years in IT and cybersecurity, and after walking multiple companies through ransomware recovery, the ransom payment is like asking how much a car accident costs and only counting the price of the tow truck. The real cost is everything that comes after. And it’s shocking how many business owners don’t understand what “everything after” actually means until they’re living it.

So let me walk you through it. Real numbers. Real incidents. No hypotheticals.

The First 72 Hours: $100K Before You Recover a Single File

Here’s what happens in the first three days after a ransomware attack. Not recovery. You’re not recovering anything yet. This is just getting started.

Forensics: Your insurance company requires you to hire a forensics firm from their approved list. That forensics engagement? It starts at $100,000 and goes up from there. This is before anyone tries to restore your data. Before anyone even fully understands the scope of the attack. The forensics team needs to figure out how the attackers got in, what they touched, and whether data was exfiltrated. That process alone takes days.

Attorney fees: Insurance also requires you to retain legal counsel, again, from their approved list. You don’t get to use your regular business attorney. This is a specialized cybersecurity attorney, and they’re billing by the hour from minute one.

Lost revenue: Here’s where it starts to hurt. I worked with a manufacturing company that was losing roughly $100,000 per day while their systems were down. Production floor dead. Employees standing around. Orders not shipping. And we couldn’t even begin recovery for three-plus days because the forensics team needed time to assemble and do their analysis first.

Now imagine you’re a hospital. The losses are even higher. Patient diversions, cancelled procedures, staff working on paper. The meter is running and there is no way to slow it down.

So in the first 72 hours, before you’ve recovered a single file, you’re already looking at $100K+ in forensics, legal fees climbing, and potentially $300K or more in lost revenue. And we haven’t started rebuilding anything.

Weeks 1 Through 4: The Rebuild Nobody Budgets For

This is the part that blindsides people. You can’t just restore your backups onto the servers that got hit. The insurance company and the forensics team need to preserve your existing hardware as evidence for the investigation. Which means you need new hardware to recover onto.

Loaner and replacement servers: When one of our clients got hit, we were able to provide loaner servers, cold spares we keep on hand for exactly this situation. We charged $1,000 per month per server, and they needed two of them for about three months. That’s $6,000. Sounds reasonable, right? Here’s the thing: if you don’t have an IT partner who keeps cold spares, you’re buying brand-new servers at full retail price on an emergency timeline. That’s $15,000 to $30,000 per server, and you need them now, not in two weeks when Dell can ship them.

Desktop rebuilds: It wasn’t just servers. Almost every desktop in the organization had to be wiped and rebuilt. We’re talking a week-plus of technician time working through every machine in the building. For remote workers, it was even worse: laptops shipped back and forth, VPN configurations rebuilt, software reinstalled.

Patchwork recovery: Even when the data comes back, the systems don’t come back cleanly. I know of a hospital that got hit six, seven, maybe eight years ago now, and they’re probably still dealing with the aftermath. Login times that take forever. Applications that don’t quite work right. Because when you rebuild infrastructure under pressure, you don’t rebuild it perfectly. You rebuild it fast. And fast has a long tail.

The Costs Nobody Calculates

So we’ve covered the obvious stuff: forensics, lawyers, hardware, lost revenue. Now let me tell you about the costs that don’t show up on any invoice but might actually be worse.

Reputation damage: If your business is down for more than about 24 hours, your customers know. They’re calling you and getting voicemails. They’re emailing and getting bounce-backs. They’re showing up and finding locked doors or handwritten signs. Past that 24-hour mark, the rumors start. And in a market like Tulsa, word travels fast.

Business email compromise: Here’s a scenario that keeps me up at night. The attackers are in your email before you even know you’ve been breached. They’re watching your communications. They learn that you regularly send invoices to a major customer, big ones, like $500,000. So they send a wire transfer request from your legitimate email address to that customer, with slightly different banking details. Your customer sends half a million dollars to the wrong account. You lose the money and the customer. That’s not hypothetical. That happens.

Lost trust: This one’s harder to quantify, but it might be the most expensive of all. After a ransomware incident, you never fully trust your systems again. Every slow login makes you wonder. Every weird error message makes your heart rate spike. Your employees are on edge. Your leadership is looking over IT’s shoulder. That psychological tax doesn’t go away for years.

The Insurance Aftermath: Where the Math Really Falls Apart

I saved this section for last because it’s the one that kills businesses. Not the attack itself, but what happens to their insurance afterward.

Sub-limits: You think you have a $4 million cyber insurance policy. You do. But buried in the fine print are sub-limits. The ransomware sub-limit might be $100,000. Data exfiltration? Maybe $50,000. So your $4 million policy might only pay out $150,000 for the exact scenario you bought the policy to cover. Those sub-limits totally destroy your payout.

Getting dropped: After you file a claim, your insurance company drops you. I’ve seen it happen every single time. It’s like a car accident that was your fault. If you’ve ever had one, you know exactly what I’m talking about. Except with cyber insurance, it’s always your fault when you get ransomware. There’s no debating it. There’s no “the other driver ran a red light.” You got breached, and that means your security wasn’t good enough.

Premium increases: When you go shopping for new insurance after being dropped, you’re looking at premiums that are 10 to 30 times what you were paying before. If you were paying $15,000 a year, now you’re looking at $150,000 to $450,000. Some businesses literally cannot afford to stay in business because the new insurance costs eat their entire margin.

The Math That Should Keep You Up at Night

I talk to CFOs all the time who run this calculation: “Insurance costs us $300,000 a year for a $20 million policy. Even if we get hit, insurance pays. If we go five or six years without an incident, we saved money versus spending $60,000 to $80,000 a month on proper security.”

On paper? Sure. That math looks clean.

But here’s what they’re not calculating. They’re not calculating that insurance drops them after the first claim. They’re not calculating that premiums jump to $100,000-plus a year, if they can even get coverage. They’re not calculating that sub-limits mean the policy pays out a fraction of what they assumed. And they’re definitely not calculating that the total cost of the incident (forensics, legal, hardware, lost revenue, reputation damage, employee downtime) might exceed their policy limits anyway.

I spend close to $10,000 a year on my own premiums. I’ve talked to other IT company owners who spend $1,500 a year. I don’t even need to know how much coverage they have, because it’s not enough. It is unlikely that any ransomware incident that impacts you or your customers will be less than a million dollars. Period.

What to Do Instead

Here’s where I’m supposed to give you the pitch, right? And I will, because the pitch is the right answer.

Invest before it happens. Not instead of insurance, but alongside insurance. A proper cybersecurity posture for a business with 10 to 100 computers runs $100 to $300 per user per month. That payment should cover support, endpoint protection, threat monitoring, backup and disaster recovery, security awareness training, and incident response planning.

Is that cheap? No. But compare it to the alternative.

Forensics: $100K+. Lost revenue: $100K+ per day. New hardware: $30K+. Desktop rebuilds: weeks of labor. Insurance aftermath: premiums that could put you out of business. Reputation damage: incalculable.

The question isn’t “can we afford cybersecurity?” The question is “can we stay in business without it?” Because post claim carrier terminations are nearly 100% of all cases.

If you want to know where your business actually stands, we do a free 27-point IT Risk and Ransomware Assessment. No obligation, no pressure. We’ll tell you exactly where your gaps are and what it would take to close them. Sometimes the answer is “you’re in better shape than you think.” Sometimes it’s not. Either way, you’ll know.

Because the worst time to find out what ransomware actually costs is when you’re living it.


Brian Largent is the CEO and founder of ArcLight Group, a managed IT and cybersecurity firm based in Tulsa, Oklahoma. With 30+ years in the industry and a SOC 2 Type 1 certified team, ArcLight protects businesses with 10–100+ computers across Oklahoma and beyond. Reach Brian’s team at (918) 270-6600 or [email protected].

Photo of Brian Largent
About the Author

Brian Largent

Father to five, husband to one, founder, CEO, and all around swell fella (or so I'm told)

Ready to harden your environment?

Get the 27-point assessment we run on every new client

Two hours. One real engineer. A written report telling you exactly where your gaps are — whether or not you ever hire us.

No hard sell. No obligation. Month-to-month after — cancel anytime.