IT Operations

The True Cost of IT Downtime for Small and Mid-Sized Businesses

MSP Worx · 4 min read · Updated Oct 10, 2026

Downtime statistics in IT marketing are close to useless. The widely quoted per-minute figures come from surveys of large enterprises, where a minute of outage genuinely does cost thousands. Applied to a 30-person business they are absurd, and everyone reading them knows it.

The useful exercise is calculating your own number. It is not difficult, and the result tends to be considerably higher than people expect — not because of the obvious costs, but because of what follows the outage.

The direct cost, calculated properly

Start with the simple version: affected staff, multiplied by their fully loaded hourly cost, multiplied by the duration.

For 25 people at a fully loaded average of $45 per hour, a four-hour outage is $4,500 in wages paid for work that did not happen. That is the floor, not the estimate.

Two refinements matter. First, productivity rarely drops to zero — some work continues offline, so apply a realistic impairment factor rather than assuming a total stop. Second, and pulling hard in the other direction, recovery is not instant. When systems return, there is a backlog to clear, context to rebuild, and a queue of accumulated work. The disruption reliably outlasts the outage by a meaningful margin.

The costs that do not appear on any invoice

Revenue that does not arrive

For businesses where systems are directly involved in earning — booking, quoting, dispatching, billing — an outage during business hours is lost transactions, not just lost time. Some return later. Some do not.

Deadlines that do not move

This is where downtime cost becomes non-linear. A day lost in a quiet week is absorbed. The same day lost against a court filing deadline, a tax deadline, a payroll run or a contractual delivery date is a different category of event entirely.

It is why the same outage costs an accounting firm dramatically more in March than in September, and why any serious calculation has to account for timing rather than producing a single annual average.

The client-facing cost

Clients who cannot reach you, or who learn you were down, draw conclusions. This is unmeasurable and real, and it scales with how visible the outage was to people outside the business.

Recovery labour

Emergency response is billed at emergency rates. Overtime for staff catching up. Management time spent on the incident rather than the business. And if data was lost, the reconstruction effort, which is frequently the largest single line and the one nobody forecasts.

A worked example

A 40-person professional services firm loses file access for six hours on a Tuesday.

  • Direct productivity: 40 staff × 6 hours × $50 fully loaded, at 70% impairment — approximately $8,400
  • Recovery backlog, conservatively half a day at partial productivity — approximately $4,000
  • Emergency response from the provider — $1,500 to $4,000 depending on the hour and the arrangement
  • Two client deliverables slipping past their committed date — unquantified, occasionally significant

Somewhere between roughly $14,000 and $16,500 for a single Tuesday, before counting anything client-facing. Against that, a monthly managed IT fee stops looking like the expensive option.

Cost line (40 staff, 6-hour outage)BasisEstimate
Direct productivity40 × 6 hours × $50 fully loaded × 70% impairment≈ $8,400
Recovery backlogHalf a day at partial productivity≈ $4,000
Emergency responseDepends on the hour and the arrangement$1,500 – $4,000
Slipped client deliverablesTwo deliverables past committed dateUnquantified
TotalBefore client-facing costs≈ $14,000 – $16,500

What actually causes it

In smaller businesses, the recurring causes are unglamorous and largely preventable:

  • Hardware failure on equipment past its service life, usually a server or a switch nobody was tracking
  • Failed updates applied without a rollback path
  • Internet or carrier failure with no secondary connection
  • Ransomware, which is the scenario where downtime is measured in days rather than hours
  • Accidental deletion or misconfiguration, which is far more frequent than attack
  • Cloud service outages, where you have no control and only your continuity plan matters

Of these, only carrier and cloud outages are genuinely outside your control, and even those are mitigable with planning. The rest are lifecycle management, patch discipline, and backup verification — which is precisely the work that reactive support models cannot deliver.

CauseIn your control?What prevents or limits it
Hardware failure past service lifeYesLifecycle management
Failed updates with no rollbackYesPatch discipline
Internet or carrier failureNo, but mitigableA secondary connection
RansomwareYesPatch discipline and backup verification
Accidental deletion or misconfigurationYesBackup verification
Cloud service outageNo, but mitigableYour continuity plan

Deciding what to spend

Once you have your hourly figure, prevention spending becomes a straightforward comparison rather than a matter of judgment.

If four hours of downtime costs you $15,000 and you experience two such events a year, you are absorbing roughly $30,000 annually in unplanned cost. Measures that meaningfully reduce that frequency have an obvious business case — and the calculation also tells you where the ceiling is, which prevents overspending on resilience you do not need.

The two questions worth answering explicitly: how long can this business be down before the damage becomes serious, and how much data can we afford to lose? Those are your recovery time and recovery point objectives, and every meaningful continuity decision follows from them.

Sources

  1. NIST Computer Security Resource Center — Recovery Time Objective (RTO) — Glossary
  2. NIST Computer Security Resource Center — Recovery Point Objective (RPO) — Glossary
  3. Cybersecurity and Infrastructure Security Agency (CISA) — #StopRansomware Guide

Want a straight answer for your business?

Talk to an advisor about your environment. No pitch, no obligation.