INTEL-33: The Cost of Week Two
Posted on July 22, 2026 • 4 min read • 652 wordsThe INTEL
Cyber damage doesn’t grow in proportion to downtime — it compounds. Economic modeling in a new Microsoft/Accenture report shows each extension of recovery time roughly triples the loss: 1.4% of monthly national GDP if operations are restored within a week, 4.6% at three weeks, 13.7% at thirty days. And the empirical anchor is real: the 2025 Jaguar Land Rover cyberattack measurably showed up in UK national statistics.
The model simulates a cyberattack on an upstream oil-and-gas operation in an oil-dependent economy using input-output tables — the standard tool for tracing how a shock to one industry propagates through everything that buys from and sells to it. Three resilience scenarios, three outcomes: restore within a week and the damage is contained (1.4% of monthly GDP); slip to three weeks and it more than triples (4.6%, ~$4.7B); slip to thirty days and it triples again (13.7%).
The real-world companion needs no model. When a cyber incident halted Jaguar Land Rover’s manufacturing, UK motor vehicle production fell 28.6% in September — the country’s lowest car output in 73 years — and roughly 0.1% came off UK monthly GDP (~$2.5B), per the Office for National Statistics. One company’s incident, visible in a G7 economy’s output. (The two analyses are separate in the report: the real event proves it happens; the model quantifies how it scales.)
Why It Matters
Every CISO already argues that downtime is expensive. What most cannot do is put a shape on the claim — and the shape is the finding. A convex loss curve means the difference between a one-week recovery and a three-week recovery is not “twice as bad.” It’s triple. And the difference between three weeks and thirty days is triple again.
That flips the budget logic. If losses compound with duration, then investment that compresses recovery time buys exponential risk reduction — while marginal prevention spend buys linear improvement at best. Most security budgets are still weighted heavily toward prevention and detection, with recovery treated as an insurance afterthought. The curve says that weighting is backwards for any organization whose revenue stops when operations stop: manufacturers, logistics, healthcare delivery, payment processors.
It also gives risk leaders something rare: a citable multiplier for the board memo. “Resilience matters” is a platitude. “Each extra week of downtime roughly triples the economic damage, per Microsoft/Accenture economic modeling, with the JLR incident as the empirical anchor” is a planning input.
What To Do — One Key Action
Re-price your recovery time. Take your honest, tested answer to “how many days to restore core operations after a destructive incident” — not the paper-plan number — and put it on the convex curve in your next BC/DR budget conversation. If the honest answer is week two or later, the marginal dollar belongs in recovery-time compression (tested failover, immutable backups, rebuild automation, stopwatch-timed exercises), not in another prevention tool.
The test that makes this real: when did your organization last prove its restore time with a live failover exercise rather than a tabletop narrative? If the answer is “never” or “before the cloud migration,” you don’t actually know which point on the curve you occupy — and the curve is unforgiving about being wrong by a week.
MITRE ATT&CK
- T1486 — Data Encrypted for Impact and T1489 — Service Stop: The impact techniques whose cost is duration-driven. The convex-curve finding doesn’t change how these attacks arrive — it changes what they cost, which is set almost entirely by how long recovery takes after they land.
Learn More
- FIR Risk Tuesday E92 — Time Is the Attack Surface — The full three-clock analysis
- Securing Nations in the Intelligent Economy (Microsoft & Accenture) — Primary source, including the input-output methodology
- FIR Risk Tuesday E91 — The Window Closed — Why reaction speed alone can no longer offset exposure
Powered by FIR Risk Platform — AI-driven threat intelligence for enterprise risk leaders.