When Systems Go Down, What Does Your Business Lose and How Should You Respond?

Every minute of system downtime may mean revenue and customer confidence gradually disappearing from the business. Even if a system stops working only for a short period, it can still have an impact, whether through failed transactions, customers being unable to access the system, or interruptions to internal business processes.

For businesses that rely on websites, applications, payment systems, sales systems, or production systems, just one hour of downtime can cause more damage than expected. And if the cause is related to a cyberattack, the impact may not end with Downtime alone, but may also include the risk of unauthorized access to or theft of important data.

Table of Contents

When Systems Go Down, What Does a Business Lose?

The damage caused by a system outage is not limited to users being unable to access a website or application. It can affect a business in many areas, such as

Lost Revenue and Business Opportunities

Transactions that cannot be completed during Downtime may turn into lost sales, especially for businesses that primarily provide services or sell products through online systems.

Costs from Employee and Business Process Downtime

If critical systems are unavailable, employees may be unable to work as usual, production or service processes may be interrupted, and delays in delivering work to customers may occur.

System Repair and Recovery Costs

Organizations may need IT, Cybersecurity teams, or external specialists to investigate and restore systems. Additional expenses may also arise from overtime work, data recovery, and incident investigation.

Other Business Costs and Losses

Such as SLA compensation, wasted advertising spending while systems are unavailable, as well as customers who may switch to competitors.

Damage from Cyberattack

If Downtime is caused by a cyberattack, organizations may face additional costs related to Incident Response, Digital Forensics, data recovery, legal matters, and actions related to personal data, as well as impacts on reputation and customer trust.

How Can the Cost of a System Outage Be Calculated?

There is no fixed figure for how much damage a system outage will cause a business because costs depend on the nature and size of each organization. However, an initial estimate can be calculated from

Revenue lost during Downtime + wages of employees unable to work + wasted advertising costs + SLA compensation + system recovery and investigation costs + losses from customers who stop using the service

Note: The items above are only examples for an initial assessment. Actual losses may vary depending on the type of business, the affected systems, the duration of the outage, and the assessment method used by each organization.

For example, if an online sales system generates an average revenue of 100,000 baht per hour, being unable to provide service for 1 hour may mean that as much as 100,000 baht in revenue is at risk of being lost. This does not yet include advertising costs that are still running, labor costs for teams required to resolve the issue, system recovery costs, or the impact of customers deciding to purchase from competitors.

Real-world Examples – System Outages Caused by Technical Issues and Cyberattack

The causes of Downtime can range from technical problems such as Hardware or Software Failure, Configuration Error, and disruptions to Third-party systems, to Cybersecurity incidents such as DDoS, Ransomware, or system intrusion. Therefore, the response approach must begin by clearly identifying the cause.

Delta Air Lines

On July 19, 2024, a faulty CrowdStrike software update caused large numbers of Windows systems worldwide to stop working. CrowdStrike confirmed that the incident was not caused by a Cyberattack but resulted from a software update issue.

One of the organizations severely affected was Delta Air Lines, which stated that it had to cancel approximately 7,000 flights within 5 days, affecting approximately 1.4 million passengers. The company estimated a direct revenue impact of approximately 380 million US dollars and approximately 170 million US dollars in additional operating expenses related to customer compensation, passenger expenses, employee-related costs, and operational recovery.

MGM Resorts

In September 2023, MGM Resorts detected a Cybersecurity incident in certain company systems and decided to shut down some systems to limit the risk. This disrupted some hotel services and customer-related systems, including the ability to make reservations through the website and Mobile Application.

MGM estimated that the incident negatively affected Adjusted Property EBITDAR by approximately 100 million US dollarsand resulted in less than 10 million US dollars in one-time incident-related expenses, including costs for technology consultants, legal services, and external specialists.

In addition, the company later disclosed that attackers had gained access to some customers’ personal information, such as names, contact information, dates of birth, and driver’s license numbers, while a limited number of customers were also affected by the exposure of Social Security Number and passport numbers.

The MGM case therefore demonstrates how a single Cyberattack can simultaneously cause impacts involving Downtime, Incident Response costs, revenue, and Data Breach

Maersk – NotPetya

In June 2017, A.P. Moller–Maersk, one of the world’s largest shipping and logistics companies, was affected by the NotPetya malware, causing IT systems related to Container Shipping, Terminal, and Logistics operations to be partially shut down to contain the incident. This significantly disrupted business operations and customer services.

In its 2017 Annual Report, Maersk estimated losses from the incident at approximately 250–300 million US dollars, covering lost revenue, IT system recovery costs, and extraordinary operating expenses.

These cases clearly demonstrate the risks associated with Critical Infrastructure or Third-party Service Provider systems because when a central system stops working, the impact can spread widely to other organizations that are connected to and dependent on that system.

When Systems Go Down, How Should Organizations Respond?

When a system outage is detected, organizations should quickly assess which systems are affected, the scope and severity of the incident, and whether it was caused by a technical issue or shows signs of a cyberattack.

They should then contain the impact to prevent it from spreading to other systems and proceed with recovery according to the prepared Incident Response Plan , Business Continuity Plan, or Disaster Recovery Plan by selecting the plan that best suits the nature of the incident.

If there are indications that the incident is related to a Cyberattack, organizations should not rush to bring systems back online without investigating the cause because attackers may still have a way to access the systems, or important evidence required for incident investigation may be destroyed.

What Should Be Done After Systems Return to Service?

After systems return to operation, organizations should thoroughly inspect backend systems, including Logs, file changes, user accounts, access permissions, and abnormal behavior that occurred before, during, and after the outage.

Especially when an incident is related to Cybersecurity, malicious actors may take advantage of the period when teams are restoring systems to infiltrate them, install malware, create ways to regain access, or steal important data without the organization noticing.

Therefore, organizations should conduct Root Cause Analysis to identify the true cause of the incident, determine whether an intrusion occurred or data was affected, and assess whether any vulnerabilities, insecure configurations, or Security Gaps remain.

If the issue involves Infrastructure or Software, it may be necessary to improve Architecture, Redundancy, Change Management, or system recovery processes. Incidents involving Cyberattack may require Incident Response and Digital Forensics to identify the scope of the attack and close the channels used by attackers to access the systems.

Because if only the symptoms are fixed without addressing the root cause, the same incident may happen again or cause even more severe damage.

Reducing the Risk of System Outages Requires Preparation Before, During, and After an Incident

The causes of Downtime can range from Hardware and Software Failure to Human Error, Third-party Failure, and Cyberattack. Organizations should therefore prepare through multiple layers, from monitoring system status and abnormalities, detecting threats, and backing up data, to having response and recovery plans that can actually be implemented when an incident occurs.

Important measures such as Monitoring, SOC/CSOC, MDR, EDR, or XDR can help organizations identify abnormalities and detect threats more quickly, while Backup and Disaster Recovery help improve readiness to recover data and services when systems cannot operate normally.

In addition to having technology in place, organizations should regularly review their Incident Response Plan and Disaster Recovery Plan and test recovery processes to ensure that when a real incident occurs, teams can respond quickly and systematically.

How Can BMSP Help You Prepare for Downtime and Cybersecurity Incident?

Reducing the impact of system outages requires both system readiness and the ability to detect and respond to incidents that may occur.

BMSP provides services and solutions for Monitoring, SOC/CSOC and MDR to help monitor, detect, and respond to threats, as well as EDR and XDR solutions that enhance visibility into abnormal behavior and enable faster responses to threats.

Alongside the implementation of Backup and Disaster Recovery to prepare for data and system recovery when unexpected incidents occur, helping reduce both the risk of data loss and business Downtime.

References


Prepare Your Systems and Reduce the Impact of Downtime Before Unexpected Incidents Affect Your Business. Contact BMSP Today for a Free Consultation!

รับคำปรึกษาฟรี!

เตรียมระบบให้พร้อม ลดผลกระทบจาก Downtime ก่อนเหตุไม่คาดคิดจะกระทบธุรกิจ ติดต่อ BMSP วันนี้

Share

Related Content

Get in touch with us. We’re here to assist you.

08. Home Bottom (EN)

Learn how we helped 100 top brands gain success