Live National Cyber Helpline · 0300 123 2040
Assured Cyber Protection Cyber & insurance briefing

Tools

Ransomware Cost Calculator: What a Cyber Attack Could Cost Your Business

By the Assured Cyber Protection team · Updated 2026 · Reviewed
Ransomware Cost Calculator: What a Cyber Attack Could Cost Your Business

The cost of ransomware is mostly the days you cannot trade, not the ransom. This calculator estimates the realistic total of a serious incident so you can set a cyber insurance limit that actually covers it, rather than buying the cheapest figure on the quote.

Estimate the cost of a serious ransomware incident

The ransom decision

An estimate to inform how much cover to buy, not a prediction of any specific attack. Every incident differs. The figures use mid-range UK assumptions for incident response and recovery.

How this ransomware calculator estimates the cost

The calculator builds a realistic total from the parts of an incident that actually drain money: lost trading days while systems are down, the cost of recovery and rebuilding, professional incident response and legal support, breach notification, and only then the ransom itself. Recovery times improved sharply in 2025, when Sophos found 53% of victims back within a week, up from 35% the year before, but a stubborn minority still take a month or more, and the average recovery bill went back up in 2026. Because each of those days has a cost, downtime, not the ransom, is usually the largest line on the bill.

Enter your own figures and the tool right-sizes the number for your business, then compares it against a cyber insurance limit so you can see whether your cover would actually hold up.

What the published benchmarks actually say

Before you trust any ransomware calculator, including this one, it helps to know what the survey data says, because the headline numbers point in two directions at once.

  • Ransomware is rarer than the coverage suggests. The government's Cyber Security Breaches Survey 2025/2026 found 43% of UK businesses identified a breach or attack of some kind, around 612,000 businesses, but only 1% were hit by ransomware, down from 3% in each of the two previous years. That is roughly 21,000 UK businesses.
  • Most breaches cost nothing, which is exactly why averages mislead. The same survey puts the median perceived cost of the most disruptive breach at £0, with the middle half of businesses reporting between £0 and £200. Averages are dragged upwards by a small number of severe incidents. Planning to the median is planning for the incident that was never going to hurt you.
  • The severe end is where the money is, and it is rising again. Sophos's State of Ransomware 2026, a survey of 2,158 IT and security leaders across 17 countries whose organisations were actually hit, puts the average recovery cost, excluding any ransom, at $1.7 million, up 11% year on year. The 2025 edition had recorded $1.53 million, itself down from $2.73 million, so the two-year trend is down then back up, not a steady fall.
  • Ransoms are falling while encryption is climbing. In the same 2026 survey the median ransom demand fell to $698,000 and the median payment to $769,000, down from $1 million, but the share of attacks that succeeded in encrypting data rose to 56% from 50%. Paying less does not mean losing less: the recovery bill went up while the ransom went down.
  • Recovery is getting faster, but not fast. Sophos's 2025 edition found 53% were back within a week, up from 35% in 2024. A week of lost trading is still the biggest line on most bills.

Put those together and the case for modelling your own figures rather than borrowing an average is straightforward: the probability is low, the median is nil, and the tail is severe enough to end a business. A calculator is how you size the tail.

The inputs a ransomware calculator needs, and why each one matters

A ransomware calculator is only as good as the factors it accounts for. A figure pulled from a single industry average tells you very little, because a seven-person accountancy practice and a 200-seat manufacturer face wildly different bills. The inputs below are the levers that actually move the total, which is why the tool asks for them rather than guessing.

  • Daily revenue and downtime. Lost trading is usually the single largest cost, so the calculator multiplies what you turn over in a day by the days you are down. UK recovery commonly runs to several weeks, and every one of those days has a price.
  • Trading capacity during recovery. Few businesses go from fully offline to fully back overnight. Modelling a period at reduced capacity, rather than a clean on-or-off switch, gives a far more honest number.
  • Staff affected. People sitting idle, or working around broken systems, are a real cost even when nothing is being sold. The more of your team the outage touches, the higher this line climbs.
  • Personal records held. This is the driver of breach notification, legal advice and any regulatory exposure under UK GDPR. The more personal data you hold, the more an attack costs once lawyers and the ICO are involved.
  • Incident response and recovery. Specialist forensics, system rebuilds and IT overtime scale with how bad the incident is, so the tool steps this up with the length of the outage.
  • The ransom itself, treated as optional. Deliberately the smallest and last factor. Paying is never advised, carries no guarantee of a clean recovery, and is usually dwarfed by the downtime above it.

Add these together and the point of a ransomware calculator becomes clear: it is not about predicting one attack, it is about seeing the full shape of the bill so you can buy cover, and build backups and response plans, that match it.

A worked example: the same business, three different weeks

Numbers in the abstract are easy to shrug off, so here is the calculator run properly. The business is a UK SME turning over about £1m a year, which is roughly £4,000 of revenue on a trading day, with 15 people whose work stops when the systems do and under 25,000 personal records on file. Nothing exotic: an accountancy practice, a wholesaler, a small manufacturer. The only thing that changes between the three runs is how long it takes to get back, and that is almost entirely a question of backups.

About 3 days, clean backups restore£25,050
About 7 days, the typical case£52,450
About 14 days, no clean backups£98,900

Read the gap between the first and third rows, because that is the part worth acting on. Being able to restore in three days rather than fourteen is worth about £73,850 to this business, and no insurance product delivers that saving. Tested, offline backups do. That single number is usually a better argument for a backup budget than any amount of threat-intelligence briefing.

Now push it to the severe end and the picture changes again. Take the same firm, 21 or more days down, unable to trade at all rather than limping at half capacity, and over 100,000 records in scope so the notification and legal line jumps:

Lost revenue while offline£84,000
Staff time lost and disruption£56,700
Incident response and IT recovery£55,000
Breach notification, legal and regulatory£45,000
Estimated total£240,700

That is £240,700 against a £250,000 policy limit, which is to say a limit that looks generous on a broker's schedule is all but exhausted by one bad month at a business turning over £1m. Notice too what is not in that table: the ransom. Every figure above is what the incident costs whether or not anybody pays anyone. Add an indicative demand on top and the £250,000 limit is gone.

Two practical conclusions come out of running it this way rather than reading an average. Lost revenue and idle staff are the two biggest lines in every scenario, together running from about 48% of the bill when backups restore in three days to about 60% when the outage stretches to a fortnight, so anything that shortens the outage pays back faster than anything that softens the aftermath. And the breach line moves with the records you hold, not with your turnover, so a small business sitting on a large customer database is exposed out of all proportion to its size. Put your own figures in above and check which of those two is doing the damage in your case.

What a ransomware calculator can and cannot tell you

Search for a ransomware calculator and you get three quite different tools, and it is worth knowing which one you have landed on.

  • A cost calculator, like this one, models what a serious incident would cost your business so you can size cover and a recovery budget against it.
  • A vendor ROI calculator models the saving from buying that vendor's product. Useful for a business case, but the assumptions are chosen by the seller.
  • A ransom decision tool weighs paying against rebuilding. In the UK, paying is not illegal in itself but carries sanctions risk, no guarantee of a working decryption key, and it marks you as a payer.

No calculator can tell you your probability of being hit. The government's own survey puts UK ransomware incidence at 1% of businesses a year, so any tool that multiplies a cost by a made-up likelihood is inventing the important half of the sum. What a calculator is genuinely good at is sizing the tail: the number you need to survive rather than the number you expect.

One 2026 finding is worth building into your thinking rather than your spreadsheet. Sophos found 79% of ransomware attacks started with an identity-based approach, with malicious email behind 26% of incidents, phishing 24%, compromised credentials 23% and exploited vulnerabilities only 18%. If the calculator's output frightens you, the cheapest thing you can do about it is not more insurance: it is multi-factor authentication and credential hygiene, because that is where four in five attacks begin.

Ransomware calculator: common questions

What does a ransomware attack really cost a UK business?

It depends entirely on severity, which is why one number is never enough. The UK government's Cyber Security Breaches Survey 2025/2026 puts the median perceived cost of the most disruptive breach at £0, because most incidents are minor. At the other end, Sophos's 2026 survey of organisations that were actually hit by ransomware put the average recovery cost, excluding any ransom, at $1.7 million. The headline ransom is often only a fraction of the total. This is why the calculator focuses on the whole incident rather than the ransom figure alone.

What does a ransomware attack cost a small business in the UK?

Run the calculator on a typical UK SME turning over about £1m a year, with £4,000 of revenue a trading day, 15 staff affected and under 25,000 personal records, and a seven day outage at half capacity comes to about £52,450. Restore cleanly in three days and it falls to roughly £25,050; go 14 days with no usable backups and it climbs to about £98,900. At the severe end, 21 days or more with no trading at all and over 100,000 records in scope, the same business is looking at around £240,700, which would all but exhaust a £250,000 cyber policy before anyone has discussed a ransom.

Is the ransom the biggest cost?

Usually not. For most businesses the days spent unable to trade, plus the cost of rebuilding systems and paying specialists, add up to far more than any ransom demand. Paying also carries no guarantee of a clean, complete recovery, which is why many organisations plan around not paying at all.

How should I use the result?

Treat the estimate as a floor for your cyber insurance limit, not a ceiling. Pick cover that comfortably exceeds the figure and stress-test it against a worse case, rather than buying the lowest limit on a quote.

The Threat Brief

A calm, plain-English security update. Once a week.

New scams, breach lessons, and cyber insurance changes that affect UK businesses, explained without the jargon. No alarmism, no vendor spin.

Unsubscribe anytime. We never share your address.