Every security-budget request that opens with “cost of downtime” is either quoting a real number or a folk number. The difference matters, because the folk numbers (a decade-old Gartner figure, the “$1 million a minute” quote no one can source, the internal calculation done on a napkin) do not survive a CFO’s second follow-up question. This piece walks through the industry-standard measurement, what it says, and how to derive your organisation’s own figure without folklore.
The industry-standard measurement is the Information Technology Intelligence Consulting (ITIC) Hourly Cost of Downtime Survey, run annually since 2008. The 2024 edition polled roughly 1,200 IT and business managers at organisations with 1,000+ employees across all major sectors. Its headline finding: the majority of mid/large enterprises now cross $300,000/hour in cost per hour of unplanned downtime, with 41% reporting $1M–$5M/hour and the top of the industry table clearing $5M/hour (ITIC, 2024, retrieved 2026-09-03).
The Headline Numbers
Distilling ITIC’s 2024 report:
- 90%+ of mid/large enterprises report hourly downtime cost above $300,000.
- 41% report $1M–$5M/hour.
- 44% of the top-of-industry sectors report above $5M/hour. Those sectors: banking and brokerage, government, healthcare, manufacturing, media, retail, transportation, and utilities.
- 91% of respondents say hourly downtime costs have risen year-over-year — inflation, transaction volume growth, and reliance on real-time integrations all push the number up.
For anyone building a first-time cost-of-downtime calculation for their own organisation, the ITIC bands are the reference. Almost every organisation above small-business scale will land inside one of them.
Why $300K Is a Floor
$300K/hour is the median across all sectors. Every serious analysis segments beyond that:
Regulated industries clear it before lunch
Banking, brokerage, and financial services routinely clear $5M/hour when trading platforms go dark. Healthcare clears similar figures when EMR systems or lab-integration services are unavailable — the additional cost is not just revenue but downstream regulatory exposure under HIPAA and its state equivalents. Utilities and telecom clear it because outage duration correlates with mandatory public reporting under FCC and equivalent regimes.
Physical operations amplify it
Manufacturing shop floors have a distinct cost curve. An idled production line does not resume where it stopped; setup, cleanup, and material spoilage add fixed costs on top of lost throughput. The Ericsson-O2 SSL outage of December 2018 shows the amplified curve at telecom scale — 24 hours of data-plane outage clearing approximately £100M for a single operator.
High-transaction-volume businesses see linear scaling
An e-commerce platform that processes $50M in annual GMV loses roughly $5,700/hour to a naive uptime formula. That platform’s hourly cost during Black Friday and Cyber Monday is 20–50× the annual average. Any survey number is a mean; any organisation-specific calculation has to factor in peak vs off-peak.
How the Number Is Built
Reputable downtime-cost surveys aggregate five components. Any calculation missing one materially understates the true number:
- Direct revenue lost — the transactions that would have completed if the service had been available. Straightforward to compute for transactional businesses; harder for subscription and B2B.
- Recovery labour and third-party engagement — loaded FTE rates for the internal responders (typically 4–10 people on a serious incident) times the mean time to restore, plus any emergency third-party engineering or forensic engagements at premium rates.
- SLA credits to customers — most enterprise agreements carry uptime SLAs with credit ladders. A 99.9% SLA missed by an hour typically triggers a 10–25% monthly credit; the aggregate across a customer base compounds quickly.
- Regulatory or contractual penalties — GDPR, HIPAA, PCI DSS, and sector-specific regimes carry penalties for prolonged outages or the data-exposure incidents that accompany them.
- Churn and reputational impact — measured across the following quarters, not the outage day itself. Industry-average churn multiplied by affected customer count multiplied by customer LTV gives a defensible estimate; anything above that is speculation.
For a walk-through of how one specific outage class rolls up under this framework, see the 86%-of-enterprises certificate outages piece — it uses the same five components against the Keyfactor 2024 PKI report data.
Gartner’s $5,600/Minute — Still Directionally Correct
The single most-cited number in the space is Gartner’s $5,600/minute — approximately $336,000/hour — figure. Gartner published it in a 2014 blog post that summarised customer conversations at the time; the number has survived a decade of citation despite being explicitly a rough baseline rather than a rigorous median.
Cross-checking against ITIC 2024:
- Gartner’s $336K/hour sits right at the ITIC 2024 median for mid/large enterprises.
- For small businesses, the true figure is lower — the ITIC data implies small-business hourly cost in the tens of thousands, not hundreds of thousands.
- For top-quartile enterprises, the Gartner figure is roughly 15–30× too low.
Which means Gartner’s number is still directionally correct as a floor for mid-market and above, still too high for genuinely small businesses, and still an order of magnitude too low for the top of the enterprise distribution. Use it as a first-pass sanity check, not a final answer.
The Cause Distribution
ITIC’s cause-attribution data has been broadly stable across recent years. Rounded percentages (categories overlap, so totals exceed 100%):
- Security incidents — roughly 40% of unplanned downtime. Ransomware alone accounts for the fastest-growing share within this category.
- Human error — roughly 35–40%. Misconfiguration, deployment errors, and access-management mistakes.
- Third-party or vendor issues — roughly 30–50%. Cloud provider outages, SaaS vendor incidents, and payment-processor failures. Most surveyed organisations put this in second place after security.
- Hardware and software failure — roughly 25–35%. Steady over time.
The security-incident share is the one most amenable to a control roadmap. See the Ericsson-O2 SSL outage analysis for the certificate-expiry variant, the subdomain-takeover write-up for the dangling-CNAME variant, and the wider DMARC enforcement gap analysis for the email-side controls that block business-email-compromise incidents that often surface as outages when finance systems freeze during recovery.
Calculating Your Own Number
For any organisation with revenue and a service worth measuring, the first-pass calculation is:
Hourly downtime cost =
(annual revenue / annual operating hours)
+ (loaded FTE rate × responder count × expected MTTR in hours)
+ (annualised SLA credit exposure / expected annual downtime hours)
+ (expected regulatory / contractual penalty exposure)
+ (industry churn rate × affected customer count × customer LTV / expected incident count)
For a mid-market SaaS with $50M ARR, ~40 engineers, a 99.9% SLA, moderate regulatory exposure, and 5% annual churn, this typically lands in the $250K–$600K/hour range. Which is why the ITIC $300K/hour band feels right for most of the mid-market — the survey and the arithmetic converge.
What One Prevented Outage Is Worth
The reason cost-of-downtime matters is not the number itself; it is the ROI case for controls. Consider:
- Preventing one hour of downtime saves the ITIC median organisation approximately $300,000.
- The DomainScan Business tier at $82/month is $984/year.
- One prevented hour of downtime funds the tier for 304 years.
That math extends across every downtime-adjacent control: certificate monitoring, DMARC enforcement, subdomain-takeover detection, blacklist watch, DNS drift alerts. Every one of these controls pays for itself the first time it flags something a manual process would have missed. And the empirical data from ITIC, Keyfactor, and IBM Cost of a Data Breach consistently shows they miss things — 86% of enterprises hit at least one certificate-related outage per year, and the median IBM 2024 breach costs $4.88M.
Where DomainScan Fits
DomainScan reduces the two hardest-to-move components of the downtime equation — detection latency and cause identification — by monitoring domain-adjacent failure surfaces continuously. Every SSL expiry, DMARC drift, subdomain change, WHOIS event, and blacklist listing lands as an alert with a paste-ready fix, not a raw indicator. Free forever for 2 domains, no credit card. The Business tier’s $82/month is less than one minute of the ITIC median downtime cost.
Frequently Asked Questions
What is the current benchmark cost of one hour of downtime?
ITIC’s 2024 Hourly Cost of Downtime Survey — the industry’s most-cited annual benchmark — puts the median mid/large enterprise (1,000+ employees) at above $300,000 per hour. 41% of surveyed organisations report $1M–$5M per hour, and top-of-industry sectors (banking, brokerage, healthcare, manufacturing, utilities) clear $5M per hour. Gartner’s older but still-cited $5,600/minute baseline (~$336K/hour) sits at the low end of ITIC’s mid-market band.
Why is the $300K/hour figure called a floor and not a ceiling?
$300K/hour is a median across all mid/large enterprises. Regulated industries, high-transaction-volume businesses, and 24/7 physical operations sit above it. Manufacturing shop-floor downtime often clears $1M/hour on its own. Financial services trading platforms clear $5M/hour when a single trading session is disrupted. The published median averages across sectors — the sector you actually operate in almost certainly sits above it.
What counts as downtime cost in these reports?
Reputable downtime-cost surveys aggregate five components: (1) direct revenue lost while systems are unavailable, (2) recovery labour and third-party engagement, (3) SLA credits owed to customers or partners, (4) regulatory or contractual penalties, and (5) churn and reputational impact measured across subsequent quarters. Not every organisation tracks all five with equal rigour, which is why survey methodology matters.
How does Gartner’s $5,600/minute figure compare to ITIC’s data?
Gartner published the $5,600/minute figure (~$336K/hour) in 2014, and it remains one of the most-cited baselines in the industry despite being over a decade old. ITIC’s 2024 median of $300K+/hour brackets the Gartner number closely — meaning the Gartner figure is still directionally correct but sits at the low end of today’s distribution. For any organisation above the small-business band, the ITIC 2024 data is the better reference.
How do I calculate my own hourly downtime cost?
Start with your organisation’s revenue divided by annual operating hours as a first-pass number. Add average recovery-labour cost (loaded FTE rates × expected responder count × MTTR). Add expected SLA credits at contract rates. Add expected regulatory or contractual exposure. Add a reasonable churn assumption (industry-average churn × affected customer count × customer LTV). The result is your organisation-specific expected cost per hour of unplanned outage. It will almost certainly be higher than the ITIC median if you run any transactional service.
What are the main causes of unplanned enterprise downtime?
ITIC’s cause-attribution data across recent survey years has been broadly stable: security incidents (roughly 40% of unplanned downtime), human error (35–40%), third-party or vendor issues (30–50% with overlap across categories), and hardware/software failure (25–35%). Certificate-related outages fall inside the security-incident and third-party categories — see the certificate outages statistics analysis for how 86% of enterprises hit one in the past year alone.
Related Learning
- /blog/ericsson-o2-ssl-outage-100m — one certificate expiry, £100M cost, national telecom outage
- /blog/certificate-outages-statistics-2024 — Keyfactor 2024 data on how often cert outages actually happen
- /learning/what-is-subdomain-takeover — the dangling-CNAME class of failure that shows up on the downtime ledger
Sources
- ITIC — 2024 Hourly Cost of Downtime Report
- Gartner — 2014 baseline commentary on downtime cost
- Atlassian — Cost of downtime summary and industry framing
- IBM — Cost of a Data Breach 2024 (breach-cost cross-reference)
- Keyfactor — 2024 PKI & Digital Trust Report (certificate-outage cross-reference)
Common Questions
What is the current benchmark cost of one hour of downtime?
ITIC's 2024 Hourly Cost of Downtime Survey — the industry's most-cited annual benchmark — puts the median mid/large enterprise (1,000+ employees) at above $300,000 per hour. 41% of surveyed organisations report $1M–$5M per hour, and top-of-industry sectors (banking, brokerage, healthcare, manufacturing, utilities) clear $5M per hour. Gartner's older but still-cited $5,600/minute baseline (~$336K/hour) sits at the low end of ITIC's mid-market band.
Why is the $300K/hour figure called a floor and not a ceiling?
$300K/hour is a median across all mid/large enterprises. Regulated industries, high-transaction-volume businesses, and 24/7 physical operations sit above it. Manufacturing shop-floor downtime often clears $1M/hour on its own. Financial services trading platforms clear $5M/hour when a single trading session is disrupted. The published median averages across sectors — the sector you actually operate in almost certainly sits above it.
What counts as downtime cost in these reports?
Reputable downtime-cost surveys aggregate five components: (1) direct revenue lost while systems are unavailable, (2) recovery labour and third-party engagement, (3) SLA credits owed to customers or partners, (4) regulatory or contractual penalties, and (5) churn and reputational impact measured across subsequent quarters. Not every organisation tracks all five with equal rigour, which is why survey methodology matters.
How does Gartner's $5,600/minute figure compare to ITIC's data?
Gartner published the $5,600/minute figure (~$336K/hour) in 2014, and it remains one of the most-cited baselines in the industry despite being over a decade old. ITIC's 2024 median of $300K+/hour brackets the Gartner number closely — meaning the Gartner figure is still directionally correct but sits at the low end of today's distribution. For any organisation above the small-business band, the ITIC 2024 data is the better reference.
How do I calculate my own hourly downtime cost?
Start with your organisation's revenue divided by annual operating hours as a first-pass number. Add average recovery-labour cost (loaded FTE rates × expected responder count × MTTR). Add expected SLA credits at contract rates. Add expected regulatory or contractual exposure. Add a reasonable churn assumption (industry-average churn × affected customer count × customer LTV). The result is your organisation-specific expected cost per hour of unplanned outage. It will almost certainly be higher than the ITIC median if you run any transactional service.
What are the main causes of unplanned enterprise downtime?
ITIC's cause-attribution data across recent survey years has been broadly stable: security incidents (roughly 40% of unplanned downtime), human error (35–40%), third-party or vendor issues (30–50% with overlap across categories), and hardware/software failure (25–35%). Certificate-related outages fall inside the security-incident and third-party categories — see the certificate outages statistics analysis for how 86% of enterprises hit one in the past year alone.