Tools
Ransomware Cost Calculator: What a Cyber Attack Could Cost Your Business
The cost of ransomware is mostly the days you cannot trade, not the ransom. This calculator estimates the realistic total of a serious incident so you can set a cyber insurance limit that actually covers it, rather than buying the cheapest figure on the quote.
Estimate the cost of a serious ransomware incident
An estimate to inform how much cover to buy, not a prediction of any specific attack. Every incident differs. The figures use mid-range UK assumptions for incident response and recovery.
How this ransomware calculator estimates the cost
The calculator builds a realistic total from the parts of an incident that actually drain money: lost trading days while systems are down, the cost of recovery and rebuilding, professional incident response and legal support, breach notification, and only then the ransom itself. Recovery times improved sharply in 2025, when Sophos found 53% of victims back within a week, up from 35% the year before, but a stubborn minority still take a month or more, and the average recovery bill went back up in 2026. Because each of those days has a cost, downtime, not the ransom, is usually the largest line on the bill.
Enter your own figures and the tool right-sizes the number for your business, then compares it against a cyber insurance limit so you can see whether your cover would actually hold up.
What the published benchmarks actually say
Before you trust any ransomware calculator, including this one, it helps to know what the survey data says, because the headline numbers point in two directions at once.
- Ransomware is rarer than the coverage suggests. The government's Cyber Security Breaches Survey 2025/2026 found 43% of UK businesses identified a breach or attack of some kind, around 612,000 businesses, but only 1% were hit by ransomware, down from 3% in each of the two previous years. That is roughly 21,000 UK businesses.
- Most breaches cost nothing, which is exactly why averages mislead. The same survey puts the median perceived cost of the most disruptive breach at £0, with the middle half of businesses reporting between £0 and £200. Averages are dragged upwards by a small number of severe incidents. Planning to the median is planning for the incident that was never going to hurt you.
- The severe end is where the money is, and it is rising again. Sophos's State of Ransomware 2026, a survey of 2,158 IT and security leaders across 17 countries whose organisations were actually hit, puts the average recovery cost, excluding any ransom, at $1.7 million, up 11% year on year. The 2025 edition had recorded $1.53 million, itself down from $2.73 million, so the two-year trend is down then back up, not a steady fall.
- Ransoms are falling while encryption is climbing. In the same 2026 survey the median ransom demand fell to $698,000 and the median payment to $769,000, down from $1 million, but the share of attacks that succeeded in encrypting data rose to 56% from 50%. Paying less does not mean losing less: the recovery bill went up while the ransom went down.
- Recovery is getting faster, but not fast. Sophos's 2025 edition found 53% were back within a week, up from 35% in 2024. A week of lost trading is still the biggest line on most bills.
Put those together and the case for modelling your own figures rather than borrowing an average is straightforward: the probability is low, the median is nil, and the tail is severe enough to end a business. A calculator is how you size the tail.
The inputs a ransomware calculator needs, and why each one matters
A ransomware calculator is only as good as the factors it accounts for. A figure pulled from a single industry average tells you very little, because a seven-person accountancy practice and a 200-seat manufacturer face wildly different bills. The inputs below are the levers that actually move the total, which is why the tool asks for them rather than guessing.
- Daily revenue and downtime. Lost trading is usually the single largest cost, so the calculator multiplies what you turn over in a day by the days you are down. UK recovery commonly runs to several weeks, and every one of those days has a price.
- Trading capacity during recovery. Few businesses go from fully offline to fully back overnight. Modelling a period at reduced capacity, rather than a clean on-or-off switch, gives a far more honest number.
- Staff affected. People sitting idle, or working around broken systems, are a real cost even when nothing is being sold. The more of your team the outage touches, the higher this line climbs.
- Personal records held. This is the driver of breach notification, legal advice and any regulatory exposure under UK GDPR. The more personal data you hold, the more an attack costs once lawyers and the ICO are involved.
- Incident response and recovery. Specialist forensics, system rebuilds and IT overtime scale with how bad the incident is, so the tool steps this up with the length of the outage.
- The ransom itself, treated as optional. Deliberately the smallest and last factor. Paying is never advised, carries no guarantee of a clean recovery, and is usually dwarfed by the downtime above it.
Add these together and the point of a ransomware calculator becomes clear: it is not about predicting one attack, it is about seeing the full shape of the bill so you can buy cover, and build backups and response plans, that match it.
What a ransomware calculator can and cannot tell you
Search for a ransomware calculator and you get three quite different tools, and it is worth knowing which one you have landed on.
- A cost calculator, like this one, models what a serious incident would cost your business so you can size cover and a recovery budget against it.
- A vendor ROI calculator models the saving from buying that vendor's product. Useful for a business case, but the assumptions are chosen by the seller.
- A ransom decision tool weighs paying against rebuilding. In the UK, paying is not illegal in itself but carries sanctions risk, no guarantee of a working decryption key, and it marks you as a payer.
No calculator can tell you your probability of being hit. The government's own survey puts UK ransomware incidence at 1% of businesses a year, so any tool that multiplies a cost by a made-up likelihood is inventing the important half of the sum. What a calculator is genuinely good at is sizing the tail: the number you need to survive rather than the number you expect.
One 2026 finding is worth building into your thinking rather than your spreadsheet. Sophos found 79% of ransomware attacks started with an identity-based approach, with malicious email behind 26% of incidents, phishing 24%, compromised credentials 23% and exploited vulnerabilities only 18%. If the calculator's output frightens you, the cheapest thing you can do about it is not more insurance: it is multi-factor authentication and credential hygiene, because that is where four in five attacks begin.
Ransomware calculator: common questions
What does a ransomware attack really cost a UK business?
It depends entirely on severity, which is why one number is never enough. The UK government's Cyber Security Breaches Survey 2025/2026 puts the median perceived cost of the most disruptive breach at £0, because most incidents are minor. At the other end, Sophos's 2026 survey of organisations that were actually hit by ransomware put the average recovery cost, excluding any ransom, at $1.7 million. The headline ransom is often only a fraction of the total. This is why the calculator focuses on the whole incident rather than the ransom figure alone.
Is the ransom the biggest cost?
Usually not. For most businesses the days spent unable to trade, plus the cost of rebuilding systems and paying specialists, add up to far more than any ransom demand. Paying also carries no guarantee of a clean, complete recovery, which is why many organisations plan around not paying at all.
How should I use the result?
Treat the estimate as a floor for your cyber insurance limit, not a ceiling. Pick cover that comfortably exceeds the figure and stress-test it against a worse case, rather than buying the lowest limit on a quote.