The Ransom Is Usually the Smallest Bill After a Ransomware Attack
Downtime, recovery work and legal fees can dwarf the payment itself. Backup and disaster recovery planning changes the maths.

Key points
- The ransom demand is usually a small slice of what a ransomware attack actually costs a business.
- Downtime, rebuilding systems and legal fees can push the total into the millions.
- Ransomware is malicious software that locks a company's files until a payment is made.
- A mature BCDR plan, meaning business continuity and disaster recovery, shortens outages and makes recovery times predictable.
- Datto, a vendor that sells backup and recovery tools, published the guidance summarised here.
Ransomware bills rarely stop at the ransom. What the criminals receive is often the smallest line on the invoice.
The real cost shows up in the days and weeks after the attack: staff can't work, customers can't buy, engineers rebuild servers around the clock, lawyers draft breach notifications, regulators ask questions. All of that stacks up fast.
A guide from backup vendor Datto, first written up by BleepingComputer, walks through those hidden costs and argues that a proper recovery plan changes the shape of the bill. We've been tracking this thread since our 2 September story on what MSPs should actually test before the next hit.
What actually costs the money?
The ransom is one line. Downtime while systems are offline, hours spent restoring data, replacement hardware, outside consultants, legal advice, regulator filings and, later, higher insurance premiums are the expensive part.
For a mid-sized company, a week without core systems means lost sales, idle staff on full pay and missed contracts. That's before anyone counts the reputational hit when customers hear their data was taken.
Datto's point is simple: the visible number in the news, the ransom demand, is often a fraction of what the victim actually spends getting back on its feet.
What is BCDR, in plain words?
BCDR stands for business continuity and disaster recovery. It's the plan and the tools that let a company keep running, or restart quickly, when something goes badly wrong.
The backup half means keeping clean copies of data somewhere attackers can't reach. Continuity means having a tested way to switch to those copies on spare infrastructure within hours instead of weeks.
Without it, a ransomware victim negotiates from weakness. With it, the company can often refuse the ransom and restore from backups instead.
How much difference does a plan make?
A lot, according to Datto. Organisations with a tested BCDR setup recover faster, spend less on emergency consultants and are far less likely to pay a ransom at all.
Tested is the operative word. Backups never verified have a habit of failing on the day they're needed. Immutable backups, meaning copies that can't be altered or deleted once written, are now standard advice because attackers routinely hunt for backup systems and wipe them before triggering the encryption.
| Cost area | Without BCDR | With mature BCDR |
|---|---|---|
| Downtime | Days to weeks | Hours |
| Recovery work | Rebuild from scratch | Restore from clean copies |
| Ransom pressure | High | Low |
| Legal and regulatory work | Full breach process | Still required if data was taken |
Having covered this beat for a while: the companies that get hit hardest are almost never the ones with no backups at all. They're the ones who had backups, never ran a restore test, and found out on the worst possible morning that nothing came back.
Common questions
Should a company ever pay the ransom?
Law enforcement in the US, UK and across the EU advises against it. Payment doesn't guarantee files return, it funds further attacks, and in some jurisdictions can breach sanctions rules.
Does cyber insurance cover all of this?
Policies vary and have tightened sharply. Many now require proof of tested backups and multi-factor authentication before paying out, and sub-limits on ransom payments are common.



