A practical framework for technology leaders preparing a business case for recovery investment
To quantify the cost of downtime, estimate your exposure across four dimensions: revenue impact per hour, regulatory and compliance exposure, reputational and customer impact, and internal recovery cost. Combined, these produce a defensible range rather than a single figure.
When recovery investment comes up internally, the conversation often stalls at the same point. Leadership wants to understand the financial case. The technology leader knows the risk is real but struggles to translate it into numbers that resonate in a business context.
This framework is designed to bridge that gap. It does not require precise data or financial modelling expertise. It requires honest estimates across four dimensions that together build a picture of downtime exposure that leadership can engage with.
Work through each section. Use conservative estimates where you are uncertain. The goal is not a precise figure. It is a defensible range that makes the risk concrete.
Dimension 1: What revenue is at risk per hour of downtime
Start with the systems your organisation depends on most. For each critical system or environment, estimate: what revenue-generating activity does this system support directly or indirectly? What is the approximate value of that activity per hour during business hours? What proportion of that value would be lost or deferred during an outage?
For organisations with direct transactional systems, this estimate is relatively straightforward. For organisations where the link between systems and revenue is less direct, think in terms of staff productivity loss, customer service degradation, and delayed fulfilment rather than transaction value.
Revenue that is deferred rather than lost is the most common source of overstatement in a downtime estimate.
Dimension 2: What regulatory and compliance exposure an outage creates
Regulated industries carry recovery obligations that have financial consequences when breached. Map your exposure against three questions: does your organisation operate under APRA CPS 234, SOCI, ISO 27001, or equivalent frameworks? Are there contractual SLAs with customers or partners that carry penalty clauses for extended outages? Could a prolonged incident trigger a mandatory regulatory notification with associated costs?
Regulatory obligations are triggered by the incident itself, not by whether systems were eventually restored.
Dimension 3: What the reputational and customer impact would be
This dimension is the hardest to quantify and the most important to acknowledge. Consider whether your organisation’s reputation depends on service availability or data integrity, whether there are customers or partners for whom an extended outage would trigger a contract review or termination conversation, and what the potential media or public impact of a significant incident would be.
The cost of reputational damage is rarely captured in a spreadsheet. That does not make it less real.
Dimension 4: What recovery costs to execute internally
The final dimension covers what recovery actually costs to execute internally. Estimate how many staff hours a significant recovery event would consume across IT, operations, and leadership, the approximate fully loaded cost of those hours, any third-party costs associated with incident response, forensics, or emergency vendor engagement, and the cost of data reconstruction if recovery is incomplete.
Internal recovery cost is consistently underestimated because it is distributed across teams that are not normally tracked as incident costs.
Putting it together
Once you have estimates across all four dimensions, combine them into a single downtime exposure range: a low estimate based on a short incident, and a high estimate based on an extended one. That range becomes the anchor for the investment conversation.
With that range in hand, you can compare it directly against an indicative cost of proven recoverability using the Evolution Data Resilience calculator.
FAQs
How do you calculate the cost of downtime without using generic industry averages?
Build the estimate from four areas of your own environment instead: revenue impact per hour, regulatory and compliance exposure, reputational and customer impact, and internal recovery cost. A conservative range built this way is more defensible in an internal conversation than a borrowed industry figure.
What is the most commonly overlooked cost of downtime?
Internal recovery cost. It is distributed across IT, operations, and leadership rather than tracked as a single line item, which is why it is consistently underestimated compared to more visible costs like lost revenue.
Does downtime cost only matter if an incident has already occurred?
No. Regulatory frameworks such as APRA CPS 234, SOCI, and ISO 27001 increasingly expect demonstrated recovery capability as an ongoing obligation, independent of whether a specific incident has taken place.
Do you need exact financial figures to build a business case for recovery investment?
No. A defensible range built from honest, conservative estimates across the four dimensions is generally more credible internally than a precise figure that cannot be substantiated.