Key Takeaways

  • Ransom payments represent only one part of the financial damage caused by ransomware incidents
  • Datto argues that tested BCDR can contain costs by reducing downtime and recovery complexity
  • Immutable backups, realistic RTOs and rehearsed recovery procedures are central to operational resilience

The number attached to a ransom demand tends to dominate the conversation after an attack. It is immediate, easy to understand and potentially dramatic. Yet for many businesses, that payment is nowhere near the largest expense.

Research from IBM and Verizon illustrates the gap. IBM's Cost of a Data Breach Report 2025 puts the average total cost of a ransomware or extortion incident at $5.08 million once downtime, remediation, legal work and business disruption are included. Verizon's 2026 Data Breach Investigations Report, by comparison, places the median ransom payment at $139,875.

That difference changes the investment argument. The question is not simply whether an organization will pay. It is how long operations will remain impaired, how much rebuilding will be required and whether the business can meet its obligations while technical teams are still restoring systems.

Downtime spreads quickly. An unavailable application can interrupt sales, manufacturing, billing, customer support and supply-chain processes at the same time. Employees may be left without the systems they need, while IT staff abandon planned work to support containment and recovery.

The Datto State of BCDR Report 2025 points to a substantial gap between confidence and performance. More than 60% of organizations believed they could recover from an incident in under a day, but only 35% actually achieved that outcome. Recovery time, in other words, is not just a technical service level. It is a financial variable.

Recovery itself creates another bill. Sophos' State of Ransomware 2025 placed the average recovery cost excluding ransom at $1.53 million. That category can encompass incident response, forensic analysis, system reconstruction, outside specialists, software replacement and internal labor. It also demonstrates why refusing a ransom does not make an incident inexpensive.

Backups help, but merely possessing copies of data says little about how quickly operations can resume. Are the copies isolated from compromised credentials? Are they clean? Can applications, operating systems and configurations be restored in the correct sequence? And has anyone tested the process under realistic conditions?

Datto positions business continuity and disaster recovery, or BCDR, as the bridge between stored data and usable operations. Its platform can capture system snapshots at intervals as short as five minutes, including files, applications, settings and operating systems. During an incident, affected workloads can be virtualized on a dedicated appliance or in the cloud while the compromised environment is isolated and investigated.

The provider also says its cloud backups use write-once-read-many storage, which is intended to prevent ransomware from modifying or deleting protected data. Machine learning-based anomaly detection monitors backup activity for unusual patterns. These controls matter because ransomware operators increasingly seek to damage backup infrastructure before encrypting production systems.

There is a practical example behind the pitch. Techify, a managed service provider partner, responded after a client was hit through a compromised printer. According to published company data, the team restored 19 TB of data and returned the client to full operation in under two hours, without a ransom payment. One case does not establish a universal recovery timeline, but it shows what rehearsed procedures and accessible recovery points can make possible.

Regulation adds pressure. A qualifying personal-data breach can trigger the General Data Protection Regulation's 72-hour notification requirement, while material cybersecurity incidents at public companies can fall under the SEC's four-business-day disclosure timetable. Technical recovery and legal assessment therefore happen in parallel, often with incomplete information.

Guidance from ENISA identifies ransomware as one of the most directly impactful cybercrime threats and highlights backup and remote data storage as continuity controls. NIST SP 800-34 similarly provides a basis for contingency planning, while NIST SP 800-207 can inform Zero Trust measures that limit access to recovery infrastructure.

For business leaders, the useful calculation starts with hourly downtime cost. Multiply that amount by the expected recovery time, then add remediation, investigation and potential legal or regulatory expenses. Compare the result with the investment required to meet the organization's recovery time objective and recovery point objective.

BCDR will not stop every intrusion. It can, however, give the business a cleaner and more predictable route back to operation. When the largest costs accumulate after encryption begins, shortening that route may have more financial value than focusing on the ransom demand alone.