Assistance 24/7/365 · Bureaux 9h–17h MT, lun–ven +1 (208) 391-7176 team@alcousa.org

What an hour of downtime actually costs

The published averages are enormous and nearly useless, because they average across organizations nothing like yours. Here is how to calculate a figure for your own business that will survive contact with a finance director.

Every vendor in this industry quotes a cost-of-downtime figure, and the figures are large. They are also drawn from surveys weighted towards very large enterprises, which makes them close to meaningless for a two-hundred-person manufacturer or a regional clinic group.

Worse, using them damages your credibility. Present a finance director with a per-hour figure lifted from a vendor slide and the conversation becomes about the figure rather than about the risk. Present one you derived from your own numbers and the conversation is about the risk.

This is how to derive it.

The four components

Downtime cost is the sum of four things, and organizations routinely calculate only the first.

Lost revenue is the direct one. For transactional businesses it is straightforward: revenue per operating hour, adjusted for what is genuinely lost rather than deferred. That adjustment matters — a manufacturer whose line stops for two hours and runs overtime on Saturday has incurred a cost, but it is the overtime premium, not two hours of revenue.

Lost productivity is usually larger and almost always omitted. Staff who cannot work are still paid. The calculation is affected headcount, times fully-loaded hourly cost, times the fraction of their work that is actually blocked. Be honest about that fraction; most outages degrade rather than halt.

Recovery cost is the labour of restoration, internal and external, plus any emergency procurement. For a serious incident this includes overtime, specialist engagement, and the opportunity cost of everything the technical team was not doing that week.

Consequential cost is the hardest to quantify and often the largest. Contractual penalties, SLA credits owed to your own customers, regulatory exposure, lost orders that went to a competitor, and reputational damage that shows up as a slower sales quarter. Estimate it conservatively; a defensible small number is more persuasive than an indefensible large one.

Over 50%Of operators said their most recent significant outage cost more than $100,000
~1 in 6Said it cost more than $1 million
MostSignificant outages traced to configuration, process or human error
Uptime Institute Annual Outage Analysis 2024, surveying data centre and IT operators. Weighted towards larger operators, which is precisely why you should calculate your own figure.

A worked example

Take a 180-person distribution business. The warehouse management system fails at 9am on a Tuesday and is restored at 2pm — five hours.

Lost revenue: orders are not lost, they are delayed, and the day's dispatch target is missed by roughly 40%. That volume is recovered over the following two days with overtime. Direct revenue loss is near zero; the cost appears as 60 hours of overtime at a premium, approximately $2,700.

Lost productivity: 45 warehouse staff are substantially idle and 20 office staff are partially blocked. At a fully-loaded average of $34 per hour, five hours, with an honest blocking fraction of 0.8 for warehouse and 0.4 for office — that is $6,120 plus $1,360, so $7,480.

Recovery cost: two internal engineers for the full five hours plus four hours each of follow-up, and a vendor support engagement at $1,800. Roughly $3,400.

Consequential cost: three customers missed a promised next-day delivery. Two are indifferent. One is in a competitive tender. Estimated at $5,000, deliberately conservative.

Total: approximately $18,600 for five hours, or $3,700 per hour. That is an order of magnitude below the published averages, and it is the number that will actually survive scrutiny in a budget meeting.

ComponentThis exampleCommonly overstatedCommonly omitted
Lost revenue$2,700Yes — deferred is not lost
Lost productivity$7,480Yes, frequently
Recovery labour$3,400Sometimes
Consequential$5,000Varies wildlyYes
Illustrative worked example. The structure is the transferable part, not the figures.

Using the number well

Once you have a per-hour figure, two things become possible that were not before.

You can size the investment. If an outage costs $3,700 an hour and your realistic recovery time is fourteen hours, a serious incident costs roughly $52,000. A warm standby that reduces recovery to one hour costs perhaps $900 a month. The payback calculation is now arithmetic rather than argument, and it depends on your view of frequency rather than on anyone's opinion about the importance of resilience.

You can prioritize honestly. Applying the calculation per system usually produces surprises. The system everyone assumed was critical turns out to cost little when unavailable because there is a manual workaround. The unglamorous integration nobody thinks about turns out to halt fulfilment entirely. Resilience spending should follow that ranking, and frequently it does not.

The argument this makes possible

The reason to do this is not documentation. It is that it changes the character of the conversation about resilience spending.

Without a number, the case for redundancy is a technical person asserting that something bad might happen, against a finance person who has to fund it out of a real budget. That argument is usually lost, and it is reasonable that it is lost, because it is an assertion against a certainty.

With a number, it is a comparison between a known monthly cost and a quantified exposure at an agreed frequency. Sometimes the honest answer is still no — the exposure does not justify the spend, and the organization accepts the risk deliberately. That is a legitimate and much better outcome than accepting it accidentally, which is what happens when nobody has done the arithmetic.

Autres publications

Least privilege without breaking everything

Removing local administrator rights is one of the highest-value security changes available and one of the most frequentl

Lire la suite

Infrastructure as code for organizations that are not software companies

The practice is usually explained by software companies, to software companies, with examples from software companies. T

Lire la suite

Keeping a public website out of the incident queue

A marketing site is usually the least critical system an organization runs and the most frequently compromised. That com

Lire la suite

Est-ce le bon choix pour vous ?

Nous qualifions chaque mission avant de la chiffrer. C’est un échange technique sur votre infrastructure, pas un appel commercial — et une réponse franche si nous ne sommes pas le bon cabinet.

Regardons ensemble ce que vous exploitez.

Un échange de cadrage avec un ingénieur senior. Nous vous dirons ce que nous changerions, ce que cela coûterait, et si nous sommes le bon cabinet pour cela.