
- 01Public incident-cost reports are aggregate and abstract. Alexa Research analyzed 31 incidents we responded to in the past 24 months with detailed cost breakdowns. The composition is not where most teams budget.
- 02Where the cost actually lives: business interruption (35-45% of total), customer notification + credit monitoring (10-20%), regulatory response and fines (15-25%), litigation reserve (10-20%), technical response (5-15%), reputation and customer churn (variable, often dominant in retail/finance).
- 03Implication: technical response is the smallest line item — and the one most heavily over-budgeted in pre-incident planning. Better preparation reduces business interruption and regulatory cost much more than forensic cost. Tabletops including legal, comms, customer-care leaders are higher-leverage than additional forensic retainers.
- 04Insurance reality: cyber insurance has tightened materially. Sub-limits for ransomware, exclusions for nation-state attribution, extensive pre-incident control requirements are now the norm. Read your policy as part of IR planning; the time to discover a sub-limit is not during a payout discussion.
Public incident-cost reports are aggregate and abstract. Alexa Research analyzed 31 incidents we responded to in the past 24 months, with detailed cost breakdowns from each. The composition of the cost is not where most teams budget.
Where the cost actually lives
- 01Business interruption — 35-45% of total
- 02Customer notification and credit monitoring — 10-20%
- 03Regulatory response and fines — 15-25%
- 04Litigation reserve — 10-20%
- 05Technical response (forensics, IR firms, remediation) — 5-15%
- 06Reputation and customer churn — variable, often dominant in retail/finance
What this implies for budget
The technical response is the smallest line item — and the one most heavily over-budgeted in pre-incident planning. Better preparation reduces business interruption and regulatory cost much more than it reduces forensic cost. Tabletop exercises that include legal, comms, and customer-care leaders are higher-leverage than additional forensic retainers.
Insurance reality
Cyber insurance has tightened materially. Sub-limits for ransomware, exclusions for nation-state attribution, and extensive pre-incident control requirements are now the norm. Read your policy as part of incident response planning; the time to discover a sub-limit is not during a payout discussion.


