Skip to content
Commentary Critical InfrastructureOT / ICSTransportHealthcare

The Real Cost of a Critical Infrastructure Attack: Beyond the Ransom

Colonial Pipeline paid $4.4 million to DarkSide. That’s the number that made headlines. The total cost of the incident, when you account for the full recovery, the regulatory aftermath, the insurance consequences, and the economic disruption across six US states, is estimated at over $500 million.

The ransom was less than 1% of the actual cost.

This isn’t an unusual ratio. It’s close to typical. The ransom figure dominates coverage because it’s a round number with a Bitcoin wallet attached to it. Everything else is harder to report and far more significant.

Colonial: What the Coverage Missed

Six days. That’s how long the largest refined products pipeline on the US East Coast was offline in May 2021. Fuel shortages across six states. Panic buying. Flight cancellations. Supply chain disruption whose economic cost, separate from Colonial’s own, ran to hundreds of millions of dollars.

The recovery itself was its own category of cost. Getting a complex OT environment back online safely after a ransomware event isn’t like restoring a file server. It requires specialist ICS recovery engineers (day rates run £8,000–£15,000 for experienced practitioners), hardware replacement, vendor engagement, and weeks of testing before you can trust the process readings enough to restore full operations. These are not people you can find on short notice, and there’s no shortcut past the testing phase when the systems in question move liquid hydrocarbons at pressure.

Colonial then faced multiple regulatory investigations and civil claims. The scrutiny of pipeline cybersecurity that followed has generated compliance obligations that continue to cost money years later. Their insurance covered part of the damage. Not all of it. Cyber insurance for CNI operators has tightened substantially since then, with exclusions added and premiums increased across the sector.

NotPetya: The Blast Radius

The 2017 NotPetya deployment is the clearest demonstration of how a critical infrastructure attack generates costs that propagate far beyond the original victim. NotPetya was not ransomware. It was a destructive wiper, deployed by Russian military intelligence primarily against Ukrainian targets. The collateral damage to Western companies with Ukrainian or Russian operations was catastrophic and unintended by the attackers.

Maersk lost its entire IT infrastructure across 130 countries in hours. Reinstalling 45,000 PCs. Rebuilding 4,000 servers. Starting from scratch, because the backups were on the same network. Approximately $300 million in damage. Merck: $870 million. FedEx’s TNT Express subsidiary: $400 million. Mondelez: $180 million. Reckitt Benckiser: $130 million.

None of these were the target. They were in the blast radius.

Several had security programmes that were reasonable by the standards of the time. The lesson isn’t that they were careless. It’s that a sufficiently destructive attack overwhelms mature defences, that the costs accumulate across dimensions most financial models don’t have rows for, and that a single nation-state operation can generate cascading costs measured in billions across organisations that weren’t even on the adversary’s list.

The Cost Stack That Boards Don’t See

When a CNI operator is hit, the costs sort into categories that are harder to quantify than a ransom figure but far more significant in aggregate:

Operational downtime: the revenue impact of reduced or suspended operations for the duration of recovery. For a hospital: cancelled surgeries, diverted patients, deferred procedures. For a utility: manual operations, reduced output, contractual penalties. For transport: service cancellations and compensation claims. This is the largest single cost for most operators and it’s barely discussed.

Specialist recovery costs: OT environments don’t recover from standard IT playbooks. The people who understand ICS recovery are scarce. Recovery is measured in weeks. There’s no way to compress the testing phase without accepting operational risk.

Regulatory exposure: NIS2 reporting obligations, sector-specific regulators, ICO involvement for any personal data impact. Regulatory investigations generate cost regardless of outcome, and for regulated businesses the relationship damage with a regulator has consequences that extend years forward.

Insurance deterioration: a significant incident almost guarantees worse terms at renewal: higher premiums, new exclusions, reduced coverage limits. Cyber insurance for CNI operators was already difficult before a claim. After one, some operators find it effectively unavailable at reasonable cost.

Third-party systemic costs: in interconnected supply chains and infrastructure networks, the cost at one operator propagates to others. This creates legal exposure and relationship damage that’s genuinely hard to model but very real when the lawyers show up.

Framing the Investment Decision Honestly

A £500,000 investment in OT security controls, network segmentation, and IR capability looks large against an IT security budget. Against a £50 million total incident cost (a conservative estimate for a mid-size CNI operator) it’s 1% of the exposed risk. The financial case is not difficult to make. The problem is that most boards are not framing the decision that way.

The organisations that have suffered the most serious damage are rarely ones that made a considered decision that investment wasn’t worthwhile. They’re ones where the risk wasn’t properly quantified, the board wasn’t adequately informed, and the investment decision was made without anyone running the scenario model.

That model is not complex. Ask the finance team: if our core operational systems are unavailable for two weeks (not a data breach, a production stoppage), what does that actually cost, across each of the categories above? That number, not the penetration testing bill, is what should frame the investment conversation.