Disaster recovery
What does downtime really cost your business, and how do you calculate it?
A reusable three-layer model, a worked example and sourced benchmarks, so you can turn RTO and RPO into a number the board will act on.

The short answer
The cost of downtime is your hourly loss multiplied by how long recovery takes. Hourly loss has three layers: revenue you can't earn back, wages paid for idle staff, and indirect costs such as penalties, recovery fees and lost customers. ITIC's 2024 survey found hourly downtime costs exceed $300,000 for 90% of firms.
Key takeaways
- Downtime cost = (lost revenue + idle payroll + recovery costs per hour) × hours of outage, plus one-off costs such as rework, penalties and customer churn.
- Recovery time (RTO) is the biggest variable you control: the same incident costs several times more at 72 hours than at 4 hours.
- Use your tested recovery times, not the targets in your policy, or the model will understate your exposure.
- Under NIS2 Article 21(2)(c), backup management and disaster recovery are required risk-management measures, so downtime is also a governance and compliance cost.
- Present the result as expected annual loss per scenario against the cost of reducing recovery time; boards approve trade-offs, not technical metrics.
How much does an hour of downtime cost?
For most mid-sized and large organisations, an hour of downtime costs tens to hundreds of thousands of euros. The figure that matters is your own, and you can calculate it with the model below and the guidance on our disaster recovery page.
Picture a Monday morning. Your ERP and file servers are encrypted, 120 people can't work and orders stop. Everyone asks one question: how long until we're back? The answer decides the bill.
Published benchmarks give you a sense of scale:
- According to ITIC's 2024 Hourly Cost of Downtime Survey of more than 1,000 firms, hourly downtime costs exceed $300,000 for 90% of firms, and 41% of enterprises put the cost at $1 million to over $5 million per hour. ITIC adds that hourly costs of $25,000 to $75,000 can be serious enough to put a small business out of business.
- Splunk and Oxford Economics (2024) estimate that downtime costs the Global 2000 companies $400 billion a year, about $200 million per company or roughly 9% of profits. They attribute 56% of downtime to cybersecurity incidents.
- In the Uptime Institute's 2026 outage analysis, 57% of respondents said their most recent major outage cost more than $100,000, and one in five reported costs above $1 million.
These are survey results, mostly from large enterprises, and they are reported in US dollars. Use them to check whether your own number is plausible, not as a replacement for it.
What goes into a downtime cost calculation?
A credible calculation has three layers: direct revenue loss, idle payroll and indirect costs. Most organisations count only the first and underestimate the total.
| Layer | Formula | Who provides the number |
|---|---|---|
| 1. Direct revenue loss | Revenue per business hour × share of revenue that depends on the affected systems × share that is lost rather than deferred | Finance, per process (sales, production, billable hours) |
| 2. Idle payroll | Affected employees × fully loaded hourly cost × productivity loss (%) | HR and Finance |
| 3a. Recovery costs | Overtime, external incident response, temporary hardware or licences, per hour or per incident | IT and your suppliers |
| 3b. Rework from lost data | Hours of work lost since the last good restore point (your RPO) × staff affected × hourly cost | IT (RPO) and department heads |
| 3c. Long-tail costs | Contractual or SLA penalties, regulatory and legal costs, customer churn, higher insurance premiums | Legal, sales and your insurer |
Two terms drive the model. RTO (recovery time objective) is how long a system may be down: it multiplies layers 1, 2 and 3a. RPO (recovery point objective) is how much work you can afford to lose: it drives the rework in layer 3b. We explain both in more detail in RTO and RPO explained.
The long tail is the hardest layer to estimate and often the largest after a ransomware attack. Splunk and Oxford Economics list regulatory fines as the second-largest direct cost of downtime after lost revenue, and they report that brand health took around 60 days to recover after an incident.
How do you calculate your own cost of downtime?
Work through five steps with Finance and IT, then run three outage scenarios. The worked example below uses illustrative figures for a company with 150 staff; replace them with your own.
- Get hourly values from Finance. Annual revenue divided by business hours gives revenue per hour. Ask which share would be lost outright rather than caught up later.
- List critical systems and who depends on them. ERP, email, file shares, line-of-business apps. Count the people who stop working when each one goes down.
- Use tested recovery times. Take RTO and RPO from your last restore test, not from the policy. If you have never tested a full restore, assume the slow scenario.
- Model three scenarios. A short outage (4 hours), a serious one (24 business hours) and a ransomware-scale one (72 business hours or more).
- Add the long tail and regulatory exposure. Penalties from your contracts, notification and legal costs, and the NIS2 and GDPR duties described below.
Worked example (illustrative figures)
Assumptions: €24 million annual revenue over 2,000 business hours (€12,000 per hour), 40% of that revenue lost rather than deferred, 120 affected staff at a loaded cost of €50 per hour with 70% productivity loss, and €1,000 per hour in recovery costs. That gives a direct cost of about €10,000 per business hour.
| Scenario | Direct cost | Rework (RPO) | Total before long tail |
|---|---|---|---|
| 4-hour outage, 4-hour RPO | €40,000 | €12,000 | €52,000 |
| 24 business hours, 1-day RPO | €240,000 | €24,000 | €264,000 |
| 72 business hours, 1-day RPO | €720,000 | €24,000 | €744,000 |
Rework is calculated as staff × hours of lost work × €50 × 50%, on the assumption that half of the lost work has to be redone. The long tail comes on top: a lost customer, an SLA penalty or a regulator's inquiry can outweigh the direct cost.
Why is recovery time the biggest lever?
Because recovery time multiplies every hourly cost. In the example, moving from 72 hours to 4 hours cuts the cost of the incident by more than 90%, and no other variable in the model moves the total that much.
Ransomware is where recovery time gets out of hand, because attackers go after the backups first. Sophos found that in 94% of ransomware attacks in its 2024 study, the attackers tried to compromise backups. When they succeeded, median recovery costs were eight times higher ($3 million against $375,000), and only 26% of victims fully recovered within a week, against 46% when backups were intact, according to Sophos' analysis of compromised backups.
The Sophos State of Ransomware 2026 puts the average recovery cost, excluding any ransom, at $1.7 million. The IBM Cost of a Data Breach Report 2025 puts the global average cost of a breach at $4.44 million.
To keep recovery time under control, you need three things in place before an incident:
- Backups attackers can't change. Immutable copies and an air-gapped copy, following the 3-2-1-1-0 rule.
- Somewhere clean to recover. An isolated recovery environment, so you don't restore onto infected infrastructure.
- Proof that it works. Regular restore tests that measure real recovery times. Our guide on how to verify your backup works covers the metrics.
For a realistic picture of how long each phase takes after an attack, see our ransomware recovery timeline.
What does downtime cost under NIS2 and GDPR?
For organisations in scope of NIS2, poor recovery is a compliance failure as well as a business loss. GDPR applies to almost every organisation that handles personal data.
- NIS2 Article 21(2)(c) of Directive (EU) 2022/2555 requires "business continuity, such as backup management and disaster recovery, and crisis management" as part of your risk-management measures.
- NIS2 Article 34 sets maximum fines of at least €10 million or 2% of worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever is higher.
- NIS2 Article 20 makes management bodies approve and oversee these measures, and they can be held liable for failures.
- NIS2 Article 23 requires an early warning within 24 hours of a significant incident, a notification within 72 hours and a final report within one month.
- GDPR Article 32(1)(c) of Regulation (EU) 2016/679 requires "the ability to restore the availability and access to personal data in a timely manner" after an incident, and Article 32(1)(d) requires regular testing of those measures.
In the Netherlands, NIS2 is implemented through the Cyberbeveiligingswet, in force since 15 August 2026. In Germany, the NIS2UmsuCG has applied since 6 December 2025. See our overview of the Article 21 measures for what this means in practice.
Put the regulatory layer in your model as a separate line. Fines are a maximum, not a forecast, but supervisory follow-up, legal advice and notification work are real costs after any significant incident.
How do you present downtime cost to your CFO or board?
Present it as expected annual loss per scenario, set against the cost of reducing recovery time. Boards decide on trade-offs, so give them one.
- Show the three scenarios side by side, with the cost of each at your current tested RTO.
- Add a likelihood per scenario from your own risk register, and multiply it by the cost to get the expected annual loss.
- Show the same scenarios at a shorter RTO, for example with standby disaster recovery infrastructure in place.
- Compare the reduction in expected loss with the annual cost of the measures that achieve it.
- Attach the evidence: the date and result of your last restore test, and which systems were included.
The last point matters more each year. Under NIS2 Article 20, management has to approve these measures and can be held liable, so a model built on untested assumptions puts the board at risk too. Reframe the question from "what would an hour cost us?" to "could we prove we recover within the time we promised?"
What to do next
The cost of downtime is a number you can calculate this week: hourly loss times recovery time, plus the long tail. Recovery time is the part you control, and only a tested recovery gives you a figure you can defend in front of a CFO, an auditor or an insurer.
With Mindtime, critical workloads are restored on a 4-hour SLA. Backups are immutable, with an air-gapped copy, and VMs can boot instantly in an isolated recovery environment on a separate, clean network. Our disaster recovery service adds standby infrastructure: a certified engineer validates the first test failover, typically within 10 days, and automated DR tests run every quarter with evidence for your auditors. Your data stays in our own Tier III data centres in the Netherlands and Germany.
Want to see what your recovery time would look like? Book a free 15-minute demo and bring your current RTO.
This article is information, not legal advice.
Frequently asked questions
How do I calculate the cost of downtime per hour?
Add three figures per business hour: revenue you lose and can't recover later, the fully loaded cost of employees who can't work, and recovery costs such as overtime and external help. Multiply by the expected outage length, then add one-off costs: rework for data lost since the last restore point, contractual penalties, legal and notification costs, and lost customers.
What is the average cost of IT downtime?
There is no single average, because it depends on your size and sector. ITIC's 2024 survey found hourly downtime costs above $300,000 for 90% of firms, mostly mid-sized and large organisations. Uptime Institute's 2026 analysis found that 57% of major outages cost more than $100,000. Smaller businesses have lower figures, but ITIC notes that $25,000 to $75,000 an hour can be fatal for them.
What is the difference between RTO and RPO in financial terms?
RTO, the recovery time objective, is how long you are down, so it multiplies every hourly cost: lost revenue, idle staff and recovery fees. RPO, the recovery point objective, is how much data you lose, so it determines the cost of rework and of transactions that can't be reconstructed. Reducing RTO usually saves the most money; reducing RPO protects the work you can't recreate.
Does NIS2 make downtime more expensive?
It adds a regulatory layer. NIS2 Article 21(2)(c) requires backup management and disaster recovery, and Article 34 sets maximum fines of at least €10 million or 2% of worldwide turnover for essential entities. Article 23 also requires incident reports within 24 hours, 72 hours and one month, which takes staff time and legal support while you are still recovering.
How often should I update a downtime cost model?
Review it at least once a year, when Finance closes the books and revenue per hour changes. Update it straight away after a major change, such as a new ERP or line-of-business system, an acquisition, a move to the cloud or a change in your NIS2 classification. Also update it after every restore test, because tested recovery times are the inputs that matter most.
Sources
- ITIC 2024 Hourly Cost of Downtime Survey, Part 2Information Technology Intelligence Consulting (ITIC), 2024
- Uncovering downtime's $400B impact (The Hidden Costs of Downtime)Splunk and Oxford Economics, 2024
- Uptime announces Annual Outage Analysis Report 2026Uptime Institute, 2026
- Cost of a Data Breach Report 2025 (press release)IBM, 2025
- State of Ransomware 2026Sophos, 2026
- The impact of compromised backups on ransomware outcomesSophos, 2024
- Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, Publications Office of the European Union, 2022
- Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex, Publications Office of the European Union, 2016


