TLDR
Most organizations budget for incident response tools and retainers but ignore the real costs: business disruption during recovery, decision-making delays, and the technical debt that makes incidents worse. True preparedness means calculating the economics of your response capability before you need it.
Introduction
In September 2023, MGM Resorts lost $100 million to a ransomware attack that brought iconic Las Vegas properties to their knees for nearly ten days. Slot machines went dark, digital room keys stopped working, and guests waited in hours-long lines for handwritten receipts.
The most striking detail? Attackers gained access through a single ten-minute phone call to the IT help desk, where they impersonated an employee and convinced help desk staff to provide administrator credentials.[1,2,3]
MGM had incident response capabilities. They had cybersecurity insurance, IR retainers, and consultants. They even refused to pay the ransom, following best practices. Yet the attack still cost them $84 million in lost revenue plus $10 million in one-time expenses for technology consulting, legal fees, and advisors.[2,4]
The gap wasn’t in their response capability. MGM’s security team detected unusual activity the day after the initial breach and quickly shut down systems to prevent further damage.[3] Their IR plan worked as designed.
The problem was preparedness: help desk authentication protocols that failed under social engineering, network architecture that allowed credential compromise to cascade across critical systems, and decision frameworks that hadn’t calculated the business impact of defensive actions before they were needed.
Most organizations budget for incident response the same way MGM did. These are response costs. What security teams consistently miss are preparedness investments: the economics of decision-making velocity, the liability created by technical debt, and the recovery capability that determines whether you’re offline for three days or three weeks.
The Economics Security Teams Actually Miss
Decision Authority Costs
MGM’s security team detected the breach within 24 hours and responded quickly. The company shut down critical systems to prevent attackers from accessing customer bank account numbers and payment card information.[3] That defensive move prevented a catastrophic data breach.
It also cost them $8.4 million per day in lost revenue.
Here’s the economics question nobody had calculated: Who has authority to shut down revenue-generating systems at 2am on a Friday? How long does it take to reach executives who can authorize taking slot machines offline across 30 properties?
The math is straightforward: Hours of decision delay × hourly business revenue × probability of incident escalation. For a company generating $17 billion annually, six hours of delay costs roughly $11.6 million in revenue alone, before accounting for what attackers accomplish during those six hours.
Organizations that calculate these economics pre-authorize specific response actions for specific scenarios. When EDR detects ransomware deployment, security teams don’t need to wake up executives to isolate affected segments.
The alternative is incident response happening at the speed of executive scheduling while business operations bleed revenue and attackers gain deeper footholds.
Technical Debt as IR Liability
Organizations calculate breach costs but almost none calculate “breach-ability costs,” the multiplier that technical debt applies to every incident.
Building proper network segmentation might cost $200K. During a ransomware incident, that segmentation is the difference between containing the attack to three servers versus watching it spread across 100+ ESXi hypervisors. In MGM’s case, attackers deployed ransomware to more than 100 ESXi hypervisors.[3,4] Lack of segmentation turned a contained breach into a company-wide disaster.
Implementing privileged access management might cost $150K. During credential compromise, PAM is the difference between rotating one set of credentials versus discovering that the same admin password works across 40 different systems.
Technical debt isn’t just a drag on development velocity. It’s a liability that compounds every dollar you spend on incident response and multiplies every hour of business disruption.
Recovery Capability Costs
Most IR plans state: “Restore critical systems from backups.” Then teams discover during actual incidents that recovery is far more complex than restoration.
Three days offline cost MGM $25 million in revenue. Three weeks would have cost closer to $200 million. The difference isn’t backup technology. It’s whether your business processes can operate manually, whether customer service can function without reservation systems, whether transactions can be processed without payment terminals.
Most organizations test whether backups can be restored. Almost none test whether their restoration sequence actually returns the business to operations or just returns systems to an online state that can’t process transactions.
During the MGM breach, properties reverted to pen-and-paper operations, using handwritten receipts for transactions and physical keys for hotel rooms.[1,5] This kept some revenue flowing.
Organizations budget for backup infrastructure but not for the forensic capability to determine which backup contains a clean state versus compromised systems. They test restoration speed but not restoration integrity.
What Offensive Cyber Experience Reveals
From the offensive side, most successful breaches don’t happen because defenders lack detection tools. They happen because organizations haven’t calculated the economics of containment.
Red teams succeed when organizations have invested heavily in detection but minimally in the architecture that makes containment possible. Organizations deploy $500K EDR solutions that detect credential dumping within minutes. Then they discover their only containment option is shutting down the entire production environment because there’s no segmentation.
The capability to isolate a compromised segment costs roughly $150-300K. Organizations skip this investment because it’s infrastructure work that doesn’t generate security metrics executives care about.
The cost of not having it: When attackers compromise credentials or deploy ransomware, your only options are either shut down everything (MGM’s $100 million decision) or let attackers move laterally while you try to identify all compromised systems.
Organizations that invested in proper privileged access management can rotate compromised credentials rapidly. Investment cost: $150-200K. Organizations that didn’t invest spend days during incidents trying to identify every system that uses compromised credentials. During those days, attackers maintain access using credentials that everyone knows are compromised but can’t be safely rotated yet.
The preparedness investments that change outcomes:
- Network segmentation ($200-400K): Containment means isolating affected segments, not shutting down production
- Privileged access management ($150-300K): Attackers lose access in hours instead of maintaining persistence for days
- Centralized, tamper-resistant logging ($100-300K): Investigation happens through log analysis, not forensic imaging
- Pre-authorized response actions (legal review time): Response happens at security speed, not executive scheduling speed
Total investment: $600-1,300K depending on organization size.
Compare that to MGM’s $100 million in losses, or even to the average $4.44 million cost of a data breach globally (or $10.22 million in the US).[6] The preparedness investments pay for themselves in a single major incident.
Building the Real IR Budget
Split IR budgeting into three distinct categories:
Response Costs (what everyone budgets): IR retainers, forensics, legal counsel, insurance premiums, notification services. These costs scale with incident severity, and severity is determined by preparedness investments you made years before.
Preparedness Investments (what gets missed): Network segmentation, privileged access management, centralized logging, pre-authorized response frameworks, security architecture remediation. Total: $660-1,620K one-time, plus $305-720K annually.
Recovery Capability (what’s underestimated): Segmented recovery environments, business continuity planning, restoration sequence optimization, recovery architecture. Total: $380-910K one-time, plus $140-380K annually.
For a $50M revenue organization, preparedness investments represent 2.6-5.9% of revenue in Year 1, then 1.3-3.0% ongoing. A single major incident without preparedness costs 11-12% of annual revenue.
Preparedness investments are typically 10-20% of response costs during a major incident, but they prevent 70-80% of business impact.
Conclusion
Most organizations approach incident response budgeting by asking: “What does IR cost?” This produces budgets for retainers, insurance, and tools. It also produces $100 million losses when incidents occur.
The better question: “What does inadequate IR capability cost us?”
Organizations that ask this question discover that preparedness investments cost a fraction of what inadequate preparedness will cost during the next major incident.
The best question: “What’s the ROI on preparedness versus response?”
For most organizations, preparedness investments pay for themselves in a single major incident and provide 4-10x returns over five years. This isn’t theoretical. It’s visible in the difference between MGM’s $100 million loss and organizations that contain similar breaches in days with minimal business impact.
The teams that calculate preparedness economics before incidents are the ones who contain them quickly and cheaply. They’ve simply done the math and recognized that the costs of preparation are always lower than the costs of recovery.
The economics are clear: Preparation costs millions over several years. Inadequate preparation costs millions in a single incident, then requires making the same preparedness investments afterward anyway, except now you’re building them under pressure, at higher cost, with damaged credibility and depleted resources.
Organizations have a choice: Calculate preparedness economics proactively and invest based on measured ROI, or calculate them reactively during incident response when every hour of inadequate capability costs revenue, reputation, and customer trust.
Most organizations will calculate these economics eventually. The ones that survive major incidents well are simply the ones who did the calculation before they needed the capability, not after.
References
[1] MGM Resorts Cyberattack 2025 – Lessons, Costs & Recovery. Inszone Insurance. https://inszoneinsurance.com/blog/cyberattack-mgm-resort-explained
[2] ALPHV: Hackers Reveal Details of MGM Cyber Attack. University of Hawai’i–West O’ahu. https://westoahu.hawaii.edu/cyber/global-weekly-exec-summary/alphv-hackers-reveal-details-of-mgm-cyber-attack/
[3] An Overview of the MGM Cyber Attack. Netwrix. https://netwrix.com/en/resources/blog/mgm-cyber-attack/
[4] MGM Cyber Attack 2023: Impact, Updates, and Response by MGM Resorts. Netwrix Blog. https://blog.netwrix.com/mgm-cyber-attack
[5] MGM Resort Cyberattack: How Hackers Shattered Operations with $100M in Damages. TeamPassword. https://teampassword.com/blog/mgm-resort-cyberattack
[6] 110+ of the Latest Data Breach Statistics to Know for 2026 & Beyond. Secureframe. https://secureframe.com/blog/data-breach-statistics

