The Real Cost of an OT Cyber Incident: Downtime, Safety, Reputation
When leaders picture the cost of a cyber incident, they often think of a ransom demand. In operational environments, the ransom is usually the smallest number on the bill. The real costs come from stopped production, slow recovery, safety exposure, broken commitments and lasting damage to trust.
Lost production and recovery

For most industrial organizations, lost production is the largest and most immediate cost. Every hour a line, unit or pipeline is down carries a measurable price in lost throughput, and often in wasted product, missed shipments and the cost of restarting safely. Even when control systems themselves aren't touched, an incident on the business network can force a precautionary shutdown if the company can't schedule, bill, track product or trust what its systems are telling it.
Recovery costs follow close behind:
Incident response specialists, forensic investigators and legal counsel
Overtime for internal staff working around the clock
Rebuilding servers, workstations and HMIs, and reloading controller logic from backups
Vendor support, sometimes at premium emergency rates
Replacement hardware where devices can't be trusted or restored
Running manual operations, with extra staff and slower throughput, until systems return
Recovery often takes far longer than the initial disruption. Restoring a business network might take days; confirming that every controller, safety system and HMI is running the right logic, and that instruments are reading correctly, can take weeks.
Safety, environmental and regulatory exposure
In OT, consequences don't stay on the screen. A compromised or disrupted control system can lead to unsafe conditions, equipment damage or an environmental release. Even when an incident is contained without physical harm, operating in a degraded or manual mode raises risk for the people on site.
Regulatory exposure can follow quickly. Depending on the sector and jurisdiction, organizations may face mandatory incident reporting, investigations, orders to implement specific controls and penalties where obligations weren't met. Pipelines, power and water utilities in particular operate under regulatory frameworks that increasingly include cybersecurity requirements.
Contracts, insurance and reputation
Contractual costs are easy to overlook. Missed delivery commitments can trigger penalties, lost customers or force majeure disputes. Customers and partners may demand assurance reviews before resuming business, and supply agreements may be renegotiated.
Insurance helps, but rarely covers everything. Policies may exclude certain events, cap payouts, carry high deductibles or require the insurer's approval for response decisions. Premiums and underwriting scrutiny typically rise after a claim, and insurers increasingly ask detailed questions about OT controls before offering coverage.
Reputation is the hardest cost to measure and often the longest lasting. Customers, regulators, investors and communities all form views based on how an organization prepares for and responds to an incident. Transparent, well-handled responses can preserve trust; slow or confused ones can erode it for years.
What public incidents tell us
A few widely reported incidents show how these costs combine. The figures below are those reported by the companies or authorities themselves.
Norsk Hydro (2019). The aluminium producer was hit by LockerGoga ransomware in March 2019 and switched several plants to manual operations. The company refused to pay the ransom and was widely praised for its openness. Its own estimates put the financial impact at up to roughly US$75 million for the first half of 2019, with insurance covering only part of that.
Maersk (2017). The shipping company was badly disrupted by the NotPetya malware in June 2017, affecting operations including its port terminals. Maersk estimated the impact at US$250–300 million. The US and UK governments later publicly attributed NotPetya to the Russian military.
Colonial Pipeline (2021). A ransomware attack on the company's IT systems in May 2021 led it to shut down its pipeline, a major fuel supplier for the US East Coast, for several days as a precaution. Colonial paid a ransom of about US$4.4 million in bitcoin, of which the US Department of Justice later recovered roughly US$2.3 million. The FBI attributed the attack to the DarkSide ransomware group. The wider costs, including fuel shortages and public scrutiny, far exceeded the ransom.
In each case, the ransom, where one was paid, was a small fraction of the total impact. Lost operations, recovery effort and reputational exposure drove the real cost.
Making the business case for prevention
Security budgets compete with every other capital and operating priority. A clear, operations-focused case makes the conversation easier:
Start with downtime. Work with operations and finance to estimate the cost per hour or per day of losing each critical unit, line or system. This figure alone often reframes the discussion.
Estimate realistic recovery time. Ask how long it would actually take to rebuild HMIs, restore servers and verify controller logic from current backups. Test it if you can.
Identify the plausible scenarios. Focus on events that are realistic for your environment, such as ransomware spreading from the business network or misuse of vendor remote access.
Compare against the cost of controls. Many of the most effective measures, including segmentation, brokered remote access, tested backups, passive monitoring and a practised incident plan, cost a small fraction of a single day's lost production at a large facility.
Speak the board's language. Present the case in terms of production, safety, customer commitments and regulatory exposure, not technical vulnerabilities.
Show progress over time. Pick a few measurable indicators, such as percentage of assets inventoried or remote access paths brokered, and report them regularly.
Prevention doesn't need to be perfect to be worthwhile. Reducing the likelihood of an incident, limiting how far it spreads and shortening recovery all shrink the total cost.
Key takeaways
In OT, lost production and recovery usually dwarf any ransom.
Safety, environmental, regulatory, contractual and reputational costs add up and can last for years.
Public incidents at Norsk Hydro, Maersk and Colonial Pipeline show business and operational impacts far beyond the initial attack.
The strongest business case starts with the cost of downtime and realistic recovery time.
How QBits Networks can help
A passive-first OT security assessment can give leaders a grounded view of where the biggest risks to production sit, which makes the business case much easier to build. OT incident response readiness work can then help shorten recovery time, which is where much of the real cost lives. Tell us what you need through our contact page and we'll scope it with you.