The Cost of an Incident
Amanda Draeger
Blue Team Con Online 2026 · Day 1 · Blue Team Con Online
Overview
In her compelling Blue Team Con Online talk, "The Cost of an Incident," Amanda Draeger, a Cyber Risk Engineer at Liberty Mutual, tackles a pervasive challenge in cybersecurity: bridging the communication gap between technical security practitioners and organizational leadership. Draeger argues that security professionals often struggle to secure adequate funding and buy-in for critical controls because they frame security in abstract, technical terms rather than the language of business – dollars and cents. The core of her presentation is a practical guide on how to translate the value of security defenses into tangible financial impacts, demonstrating precisely how much an incident can cost an organization across various categories.

Key moments
- 2:18 The challenge: getting leadership to fund security.
- 3:39 Key strategy: Translate security defenses into dollars.
- 4:51 Understanding where incident costs truly come from.
- 5:07 Direct costs: incident response, recovery, and ransom payments.
- 6:30 Compliance costs: regulatory and individual notifications.
- 7:59 Hard numbers: The high cost of data breach notification.
The Cost of an Incident
Speakers: Amanda Draeger, Cyber Risk Engineer, Liberty Mutual
Conference: Blue Team Con Online
YouTube: https://www.youtube.com/watch?v=mZ3sJUpKvKA
Overview
In her compelling Blue Team Con Online talk, "The Cost of an Incident," Amanda Draeger, a Cyber Risk Engineer at Liberty Mutual, tackles a pervasive challenge in cybersecurity: bridging the communication gap between technical security practitioners and organizational leadership. Draeger argues that security professionals often struggle to secure adequate funding and buy-in for critical controls because they frame security in abstract, technical terms rather than the language of business – dollars and cents. The core of her presentation is a practical guide on how to translate the value of security defenses into tangible financial impacts, demonstrating precisely how much an incident can cost an organization across various categories.
Draeger's insights are particularly vital for any organization grappling with the ever-present threat of cyber incidents, from small businesses to multinational corporations. By dissecting the multifaceted financial repercussions of a breach, she empowers security teams to articulate risk and propose solutions in a way that resonates with executive decision-makers. The talk underscores that understanding the true financial burden of an incident—extending far beyond immediate response costs—is paramount for effective cybersecurity strategy, resource allocation, and ultimately, organizational resilience.
Background
▶ Watch: The challenge: getting leadership to fund security. (2:18)
The persistent struggle for cybersecurity teams to secure adequate funding and executive attention stems from a fundamental disconnect: security professionals are trained to think in terms of technical vulnerabilities, threats, and controls, while business leaders primarily focus on revenue, profit, and risk in financial terms. As Draeger explains, "we are taught to think in terms of security which is a really nebulous concept and it doesn't necessarily apply to how businesses operate." This semantic chasm leads to a perpetual challenge in justifying investments in critical security measures like multi-factor authentication (MFA), segmentation, or robust data governance.
Draeger, drawing from her background as a "recovering fed" and her current role in cyber insurance, emphasizes that learning to "talk in dollars" is an essential skill for security practitioners. Her perspective is informed by a unique blend of experiences, from military service where budgets could be "fungeable" to the rigid financial realities of a large insurance carrier. The data underpinning her analysis is derived from a combination of public sources, such as news reports and annual industry benchmarks like the IBM Cost of a Data Breach Report, alongside proprietary claims data observed by Liberty Mutual as an insurance provider. This dual perspective allows her to present a comprehensive, real-world view of incident costs, moving beyond theoretical risks to concrete financial consequences. The talk aims to equip attendees with the knowledge to translate defensive measures into demonstrable financial value, linking them directly to the potentially catastrophic expenses of various incident types.
Key Findings
▶ Watch: Understanding where incident costs truly come from. (4:51)
Amanda Draeger's presentation meticulously breaks down the multifaceted financial impacts of a cyber incident, revealing that the true cost extends far beyond the immediate technical response. Her key findings revolve around categorizing these costs and emphasizing their scale:
- Comprehensive Cost Categorization: Draeger identifies six primary categories of incident costs:
- Direct Incident Response and Immediate Recovery: The initial "stop the bleeding" activities, including hiring IR firms, legal counsel, and potential ransom payments.
- Required and Compliance Costs: Expenses mandated by regulations, such as regulatory notifications (e.g., SEC 8K filings), individual data breach notifications, and credit monitoring.
- Business Interruption: The most significant and often underestimated cost, representing lost profits due to downtime, supply chain disruptions (contingent business interruption), and the complexities of forensic accounting.
- Regulatory Costs: Broader legal and governmental repercussions, including investigations, legal settlements (especially class-action lawsuits in the U.S.), and direct governmental fines.
- Reputational Costs: The difficult-to-quantify impact on customer perception, brand value, and stock price, which can be mitigated by transparency.
- Betterment: Long-term upgrades and improvements made post-incident to prevent recurrence, distinct from immediate recovery.
- Data is a Liability: A central and repeated theme is that data is not the new oil; it is nuclear waste. While useful, it carries significant inherent liability. Draeger stresses that "what you collect, you must protect," and recommends aggressive data minimization and secure cold storage or offline archiving whenever possible to reduce this risk. The cost of notifying individuals of a data breach alone can range from a few thousand dollars for a small company to hundreds of millions for a large data broker (approximately $1 per person for notification, plus $10-15 per person for credit monitoring).
- Business Interruption Dominates Costs: Draeger highlights that business interruption is often "easily an order of magnitude more expensive than the direct incident response costs." While direct IR might be in the hundreds of thousands, business interruption can quickly escalate into millions or even hundreds of millions. The average ransomware incident can cause downtime ranging from three weeks to three months, with severe cases extending to six months or more, leading to substantial lost profits.
- The Imperative of Plans and Practice: Having well-documented incident response (IR), disaster recovery (DR), and business continuity (BC) plans is crucial. Critically, these plans must be accessible "even when the rest of your network is not," meaning they should exist on paper and be stored out-of-band. Beyond documentation, Draeger stresses the absolute necessity of practice, practice, practice through tabletop exercises and actual system restoration drills to minimize errors and speed up recovery during a real incident.
- Transparency and Crisis Communications are Key: Managing reputational costs requires a strategic approach to communication. A "legal team-led approach" that says "nothing useful" can erode trust. Draeger strongly recommends engaging crisis communications teams to guide public messaging, restore customer confidence, and prevent further damage to the organization's image.
These findings collectively arm security professionals with a financial lexicon and a strategic framework to advocate for security investments, emphasizing the profound and often overlooked expenses of cyber incidents.
Technical Deep Dive
▶ Watch: Direct costs: incident response, recovery, and ransom payments. (5:07)
The technical deep dive in Amanda Draeger's talk, while not focused on code or protocols, meticulously dissects the financial mechanics of various incident cost categories, offering granular insights into how these expenses accrue.
Direct Incident Response and Immediate Recovery:
These are the most intuitive costs. When an incident strikes, organizations often need external expertise. This can include hiring a law firm (specifically a breach coach) to navigate legal ramifications and ensure attorney-client privilege, or a dedicated incident response firm to contain the threat and eradicate the adversary. These firms typically bill hourly, meaning costs scale linearly with the duration and complexity of the incident. For instance, a prolonged investigation into a sophisticated threat actor will naturally incur higher costs.
A critical, though controversial, cost can be a ransom payment. While not universally recommended, some organizations choose to pay to restore systems or prevent data leaks. Draeger notes that threat actors sometimes leverage discovered cyber insurance policies to set their ransom demands, although their understanding of policy nuances can be limited.
Finally, network asset loss refers to situations where equipment is so severely compromised or misconfigured that it's more cost-effective to replace it (e.g., "bricking") rather than attempting complex restoration.
Required and Compliance Costs:
These expenses are driven by legal and regulatory obligations. For publicly traded companies in the U.S., a material incident necessitates an 8K filing with the Securities and Exchange Commission (SEC) within a specific timeframe. Breaches involving personally identifiable information (PII) trigger individual notification requirements, varying by jurisdiction (state, country). Draeger provides crucial hard numbers:
- Notification alone: Approximately $1 per person in the U.S. This can range from a few thousand dollars for a small business with only employee data to $350 million for a large data broker with nationwide PII.
- Credit monitoring: An additional $10 to $15 per person. This can increase the overall cost by an order of magnitude.
A significant challenge here is data mining – the process of identifying who needs to be notified. If PII is in structured databases, it's relatively straightforward. However, dealing with unstructured data, archives, or even scanned handwritten documents (e.g., in healthcare) requires extensive human effort, making this cost highly unpredictable and potentially budget-blowing. This underscores the principle that data is a liability.
Business Interruption (BI):
Often the largest and least understood cost, BI represents lost profits, not just lost revenue, due to an organization's inability to conduct normal operations. Calculating this requires complex forensic accounting, factoring in seasonal sales, temporary layoffs (which save money), and overtime for salaried vs. hourly IT staff. Incidents can cause significant downtime: a "relatively short ransomware incident can be about 3 weeks," while "a little bit more common can be around 3 months," and "particularly bad incident and that drags on for six months or more."
Contingent or Dependent Business Interruption extends this to supply chain disruptions, where an incident at a supplier impacts the victim organization's ability to operate. Organizations seeking this coverage must be aware of subrogation, where their insurer might seek to recoup costs from the affected supplier, potentially straining business relationships.
Regulatory Costs:
Beyond compliance notifications, these involve deeper legal and governmental actions. Legal or regulatory investigations divert internal staff from their profit-generating work. In the U.S., where direct government fines for data breaches might be less common than in other regions (e.g., Europe with GDPR), class-action lawsuits by affected individuals can result in "very, very expensive" legal settlements, particularly for breaches of sensitive data affecting a large population. Governments might also impose direct fines or issue penalties or directives requiring the implementation of specific security controls, incurring further costs.
Reputational Costs:
These are challenging to quantify, as stock prices often show an initial dip post-incident but can rebound, sometimes even higher. However, customer perception is critical, especially for business-to-consumer (B2C) organizations. Transparency in communication can significantly mitigate these costs. This is where crisis communications teams become invaluable, as their expertise differs from standard marketing or public affairs, helping organizations navigate media interactions and rebuild trust without inadvertently exposing further liabilities.
Betterment:
Distinct from immediate recovery, betterment costs are long-term upgrades implemented after an incident to prevent future occurrences. An incident response might involve disabling a compromised device or upgrading existing software licenses. Betterment, however, entails purchasing new, more secure hardware with longer support lifecycles, or entirely new, more robust licensing. While traditionally not covered by insurance, Draeger notes that this is becoming a more common coverage.
In summary, this deep dive reveals that the financial impact of a cyber incident is a complex web of direct, indirect, and future-looking costs, with business interruption and data-related liabilities often being the most significant and least understood. Understanding these mechanisms is crucial for any organization aiming to build a financially defensible cybersecurity posture.
Demo / Proof of Concept
▶ Watch: Compliance costs: regulatory and individual notifications. (6:30)
Amanda Draeger's talk, "The Cost of an Incident," is a strategic and analytical presentation focused on the financial implications of cyber events and the business case for cybersecurity investments. As such, it does not include a traditional technical demonstration or a proof of concept of an exploit or defensive tool. Instead, the "proof" is delivered through the comprehensive categorization of incident costs, real-world examples (e.g., the gate control system scenario), and the speaker's expert insights drawn from her role as a cyber risk engineer and insurance claims data. The talk itself serves as a conceptual framework for understanding and mitigating financial risk, rather than showcasing technical capabilities.
Defensive Implications
▶ Watch: Hard numbers: The high cost of data breach notification. (7:59)
The detailed breakdown of incident costs provides a clear roadmap for defenders to prioritize and justify security investments. Draeger outlines several critical defensive implications:
- Data Minimization and Management: Recognizing that data is nuclear waste and a significant liability, organizations must prioritize data minimization. This means legally destroying data at the earliest opportunity if it's no longer needed. If data must be retained, moving it to cold storage or offline storage reduces its attack surface. Defenders should champion policies that limit data collection, retention, and accessibility, reminding leadership: "what you collect, you must protect."
- Robust Backup Strategy: Backups are paramount, but threat actors actively target them. Defenders must implement and regularly test a 3-2-1 backup rule (3 copies, 2 different media, 1 offsite/offline). Crucially, one copy must be truly offline to be viable against ransomware. Beyond data, full system backups are essential, including original build media, licensing, and expertise to restore legacy systems or hypervisors from scratch. Regular practice of restoration processes is key.
- Comprehensive, Accessible Incident Response and Business Continuity Plans:
- Retainer for IR Firms: Large or complex organizations should have an incident response firm on retainer, especially for specialized needs like operational technology (OT). This ensures faster response and firms already familiar with the environment.
- Paper Plans and Out-of-Band Communications: Critical plans (IR, DR, BC) and emergency contact lists must be available on literal paper and stored out-of-band (e.g., a separate cloud instance, physical binders) so they are accessible even if the primary network is compromised.
- Practice, Practice, Practice: Regular tabletop exercises and actual system restoration drills (practicing restoring from scratch, data from backup) are non-negotiable. This builds muscle memory, identifies gaps, and speeds up recovery, reducing downtime and associated costs.
- Manual Controls and Business Impact Analysis (BIA): Defenders need to conduct a thorough Business Impact Analysis to understand critical business processes and their technological dependencies. For essential functions, the ability to operate under manual controls (e.g., paper charting in a hospital, physical processes) is a vital interim measure.
- Foundational Security Controls: While not explicitly a "technical deep dive" in terms of code, Draeger emphasizes that foundational security practices are crucial, especially in the context of emerging technologies like Generative AI (GenAI) and agentic systems. These systems exacerbate existing weaknesses:
- Asset Inventory: Knowing what assets an organization has is fundamental.
- Access Management: Properly controlling who has access to what, and under what conditions.
- Identity Management: Draeger calls identity "arguably the hard problem in cyber security today." Strong identity management, including MFA, is critical to preventing initial compromise and lateral movement. GenAI agents, if not properly managed, can exploit poor identity and access controls.
- Break Glass Procedures: For critical systems, break glass accounts with highly monitored access are essential. These should have a clear, documented process for activation, including two-person integrity (e.g., split credentials in separate physical safes), immediate alerts, and a robust post-incident cleanup process (credential rotation, alarm resets).
- Strategic Communication: Defenders should advocate for engaging crisis communications teams for public-facing organizations. This helps manage reputational costs by ensuring transparent, trust-building communication with customers and the media, avoiding the pitfalls of overly cautious, uninformative legal-led statements.
- Resource Utilization for Smaller Entities: For small businesses or underfunded nonprofits, Draeger recommends leveraging free resources from national cybersecurity bodies like CISA (Cybersecurity and Infrastructure Security Agency), ASD (Australian Signals Directorate), and NCSC (National Cyber Security Centre). Basic, foundational steps include: ubiquitous MFA, simple but effective backups (even a removable hard drive), regular system updates, and default endpoint protection (like Windows Defender).
Ultimately, the defensive implications underscore that effective cybersecurity is not just about technology; it's about integrating security into the fabric of business operations, understanding its financial value, and building resilience through comprehensive planning and relentless practice.
Key Takeaways
- Data is a Liability, Not Just an Asset: Organizations must minimize the data they collect and retain. Any data held is a potential financial and legal burden, akin to "nuclear waste." Implement strong data minimization policies and leverage cold/offline storage.
- Business Interruption is the Largest Cost Driver: Direct incident response costs are often dwarfed by the financial impact of business interruption, which can last for months and cost orders of magnitude more in lost profits. Focus on minimizing downtime through preparedness.
- Comprehensive Plans are Essential and Must Be Accessible: Develop detailed Incident Response, Disaster Recovery, and Business Continuity plans. Crucially, these plans, including emergency contact lists, must be available on paper and through out-of-band communication channels, independent of the compromised network.
- Practice Makes Perfect (or at Least Faster): Regular tabletop exercises and actual system restoration drills are vital. Practicing how to recover from scratch, restore data, and operate under manual controls significantly reduces errors, speeds recovery, and ultimately lowers incident costs.
- Speak the Language of Dollars and Business Risk: To secure executive buy-in and funding, security professionals must translate technical controls into their financial impact. Use Business Impact Analysis (BIA) to connect security measures to the organization's ability to make money and mitigate costly risks.
- Foundational Security is Paramount, Especially with New Tech: Basic controls like robust asset inventory, effective access management, and strong identity management (including MFA) are more critical than ever, as emerging technologies like Generative AI can exacerbate existing weaknesses.
About the Speaker(s)
Amanda Draeger is a Cyber Risk Engineer at Liberty Mutual, a role she describes as bridging the gap between technical security and the financial realities of cyber insurance. She is a self-proclaimed "chronic overachiever" with numerous credentials, including being a GX Security Expert. Draeger is a retired Army veteran and identifies as a "recovering fed," bringing a wealth of experience from her time in public service. Beyond her professional life, she is an avid fiber artist, famously creating a cross-stitch TCP header, demonstrating her unique blend of technical acumen and creative pursuits. Her diverse background provides a practical and grounded perspective on cybersecurity challenges and their real-world implications.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent primer on incident cost categories that delivers exactly what it promises: a framework for translating security spend into business language. Useful for practitioners who haven't had to justify budgets to a CFO before, but nothing here will surprise anyone who's read an IBM breach report or sat through an insurance renewal.
Heather Calloway (CISO) — SOLID
Competent primer on incident cost categories that would serve a security manager preparing their first board presentation. For experienced practitioners, the framework is familiar territory — useful validation, not new ground.