Total the cost of one security incident: response labour, downtime, third-party support, remediation and overtime.
Degradation is applied as a multiplier because outages are rarely total: a payment path at 40% capacity for fourteen hours is not fourteen hours of zero revenue. Overtime is modelled explicitly, because incident response is mostly out-of-hours work and the uplift is a real, visible line in the cost. Every dollar figure here is your assumption, not an industry constant — but the resulting cost per hour of downtime is what turns a request for automation or 24×7 coverage into a business case a CFO can compare against the spend.
Incident Cost
Total = response hours × blended rate × overtime uplift + downtime hours × revenue per hour × degradation + external and remediation costs.
Cost per downtime hour
Cost per hour of downtime = total cost ÷ downtime hours — the number that prices faster containment.
Total = response hours × blended rate × overtime uplift + downtime hours × revenue per hour × degradation + external and remediation costs. Degradation is applied as a multiplier because outages are rarely total: a payment path at 40% capacity for fourteen hours is not fourteen hours of zero revenue. Overtime is modelled explicitly, because incident response is mostly out-of-hours work and the uplift is a real, visible line in the cost.
Every dollar figure here is your assumption, not an industry constant — but the resulting cost per hour of downtime is what turns a request for automation or 24×7 coverage into a business case a CFO can compare against the spend.
This calculator takes 9 inputs: Internal response hours, Blended internal hourly rate, Response hours at overtime rates, Overtime multiplier, Hours of service disruption, Revenue or productivity per hour of full service, Average service degradation during the outage, External forensics, legal and PR, Remediation, rebuild and hardening. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
No. They are your inputs, and the calculator only does the arithmetic. Published breach studies give useful ranges for context, but the revenue per hour, blended rate and degradation for your own services are the only inputs that make this number defensible.
Internal labour. Three hundred hours sounds like a lot until you count the platform engineers, service desk, legal, communications and executive time consumed by a serious incident — the true figure is often several times the security team's own hours.