
This is Article 4 of WEI’s “The Hybrid Truth” blog series. For Article 3, please click here. In Post 5, we’ll close the series by covering how WEI approaches hybrid architecture end to end — from workload assessment through DR design to long-term rightsizing.
Over a 20-plus-year career in IT, I’ve sat through more disaster recovery and business continuity meetings than I can count. The pattern is almost always the same…the infrastructure team walks in with a well-researched proposal. They’ve mapped recovery tiers, calculated replication bandwidth, and documented every dependency.
Then someone from finance asks a simple question: What happens if we don’t do this?
The room generally goes quiet. Not because the answer is unclear, but because nobody has tied the risk to a number the business recognizes. Technology explains the problem while dollars justify the investment.
That translation is the whole job.

Figure 1: The Cost-of-Delay Spectrum — as downtime stretches from minutes to weeks, business impact compounds from operational buffer to permanent revenue and brand loss.
The Threat Environment Isn’t Theoretical
The threat environment has shifted, and dramatically so. Ransomware incidents rose from under 1,400 in 2020 to roughly 6,500 in 2025 (a 360% increase) and projected global damages reached $74 billion in 2026, up 30% year over year.
But the statistic that should get every operations leader’s attention is this: attacks on manufacturers rose 40% in early 2026 because threat actors understand that operational disruption creates leverage.
Think about what that means in practice. A discrete manufacturer with three plants is hit on a Tuesday morning. The ERP system that schedules production, tracks inventory, and releases work orders goes dark. Lines don’t stop immediately as there’s usually a few hours’ buffer in staged materials. By Wednesday, the plant floor is guessing. By Thursday, customer ship dates start slipping. By Friday, the customer’s procurement team will call to ask whether to dual source.
The attackers know this and every hour on that timeline strengthens their position, so they price accordingly.
Recovery is also slower than most plans assume. Only 53% of ransomware-affected organizations fully recovered within a week. Nearly half operated in a degraded state for more than seven days—long enough for customers, partners, and sometimes regulators to notice.
What Downtime Actually Costs
Industry benchmarks matter, but CFOs care most about numbers derived from their own business. Calculating actual downtime exposure underpins a successful business case.
The benchmarks are a useful starting point, and they’re quite sobering:
- 91% of mid-size enterprises say a single hour of downtime costs more than $300,000, and 41% of large enterprises put it between $1 million and $5 million per hour
- Cisco and Oxford Economics put annual unplanned downtime cost for Global 2000 companies at $600 billion. That is 50% higher than two years earlier, averaging roughly $95 million in lost revenue per organization
- High-impact outages carry a median cost of about $2 million per hour
- In critical sectors, the average breach runs $4.82 million per incident, and that figure excludes production loss entirely
But the number that persuades a CFO is the one derived from your own data. Take a specialty retailer with $400 million in annual revenue, 60% of which flows through e-commerce. That’s roughly $27,000 per hour in direct online revenue during business hours — closer to $70,000 during a peak season window. Add abandoned carts that never return, support call volume, and the goodwill discount you’ll offer to make it right, and the real figure is meaningfully higher than the raw revenue math.
Now compare that to a regional bank. Direct hourly revenue loss may be lower, but a four-hour outage on transaction processing triggers regulatory reporting, customer trust erosion, and potential SLA penalties with corporate clients. Same four hours, entirely different cost profile.
No universal number exists, and using a generic one weakens the case. The exercise of calculating your own is half the value.
“Technology explains the problem. Dollars justify the investment.”
Turning RTO and RPO Into a Business Conversation
Recovery objectives are technical metrics that translate directly into financial impact and business risk. Recovery Time Objective (RTO) is how quickly a system must be restored. Recovery Point Objective (RPO) is how much data the business can afford to lose. Consider an order management system with a realistic RTO of six hours and an RPO of 24 hours, because backups run nightly and recovery is largely manual.
Translated for the business: a single incident costs roughly six hours of downtime plus up to a full day of order data that would have to be reconstructed from email, phone records, and customer complaints.
For the retailer above at $27,000 per hour, that’s about $162,000 in direct downtime exposure, plus the operational chaos of rebuilding a day of orders by hand, which is the part that actually generates angry customers.
Move that system to a warm standby posture and the same workload might land at a 30-minute RTO and a 15-minute RPO. The same incident now costs roughly $13,500 and 15 minutes of order data.
That’s the sentence that gets funded: “This investment reduces our per-incident exposure from roughly $162,000 to under $15,000 and eliminates the risk of losing a full day of customer orders.”
No jargon, just a number, a comparison, and a removed risk.
Continuity Is Bigger Than Recovery

Figure 2: DR answers how systems recover. BCP answers how the business keeps operating while that happens.
Business continuity includes communications, vendor dependencies, compliance obligations, and executive decision-making during an incident. Disaster recovery addresses how systems are restored. Continuity addresses how the business keeps functioning — and maintains credibility — while that happens. Four failure modes show up repeatedly in otherwise solid plans:
- The disclosure problem: Modern ransomware usually includes data exfiltration, not just encryption. You aren’t only restoring systems; you’re managing a potential public disclosure while the technical team is heads-down on recovery. If those workstreams aren’t planned separately with separate owners, one gets dropped. That’s usually the communication one.
- The silence problem: A brand that goes dark during an incident, with no status page, no acknowledgment, and no timeline, takes a reputational hit that outlives the outage. Customers are surprisingly forgiving of downtime. They’re much less forgiving of being ignored during it. A status page and a pre-drafted communication template cost almost nothing and are consistently the highest-ROI element of a continuity plan.
- The third-party problem: Supply chain compromise means the continuity plan has to account for a vendor going down, not just internal systems. If the payment processor, logistics provider, or identity provider is the one breached, the DR runbook doesn’t help. A documented fallback does.
- The decision-rights problem: Who declares an incident? Who authorizes a failover that may cause data loss? Who speaks to press? If the answer is “we’d figure it out,” that figuring out happens at 2 a.m. under maximum pressure, which is when expensive mistakes get made.
Why Cloud Changes the Math
Cloud recovery improves testing, geographic separation, and automation while reducing dependency on idle infrastructure. Each of those directly affects the business case.
You stop paying for insurance you never test. A traditional secondary data center costs money every month whether or not it’s used, and testing it requires a maintenance window nobody wants to schedule. The cloud lets you stand up a recovery environment in isolation, validate it against real data, and tear it down again without touching production.
Geographic separation comes standard. Cloud regions provide off-site, geographically distinct recovery by default, satisfying the off-site requirement foundational to any credible backup design.
Automation removes the 2 a.m. human error. Most catastrophic recoveries fail not because the technology broke, but because someone executed step 14 of a 40-step manual runbook incorrectly while exhausted. Automated failover removes that variable.
That last point is increasingly what boards want to see. Given how sharply ransomware volume has grown, “we have backups” is no longer a satisfying answer. “We tested failover last quarter and recovered in 22 minutes” is.
A Four-Number Framework for Building the Case
When presenting to leadership, structure the ask around four figures and nothing else:
- Current exposure: Your own cost per hour of downtime for the specific systems in scope
- Current gap: Realistic RTO and RPO today, versus what the business actually requires
- Cost to close the gap: What moving to the target architecture costs, whether pilot light, warm standby, or active/active
- Risk-adjusted return: Hours of exposure eliminated, multiplied by cost per hour, multiplied by probability of an incident
Where WEI Comes In
WEI helps organizations quantify downtime exposure, align recovery objectives, and build continuity strategies that support business outcomes. The hard part is rarely the technology as it’s typically the translation work. That includes determining the cost of downtime, securing business stakeholders’ commitment to recovery objectives they’ll stand behind, matching each workload tier to the appropriate recovery model, and building the surrounding continuity plan that covers communication, compliance, and decision rights.
WEI works end to end, designing cloud recovery architectures across AWS and Microsoft Azure and helping leadership build the case to fund continuity before an incident makes the case instead.
Nest Steps: Speaking of AWS, did you know WEI is a certified AWS Select Tier Services Partner? Our deep and certified bench of AWS experts have proven experience across the full range of AWS services. Ensure your critical applications and data are always available with comprehensive BCDR solutions on AWS:
- AWS Elastic Disaster Recovery
- Veeam Backup & Replication on AWS
