Ransomware Is a Liquidity Crisis: Why Boards Need to Treat Cyber Recovery as a Cashflow Event
Ransomware is usually treated as an IT, legal, data, or reputational crisis. It is all of those things. But for boards and executive teams, it is also something more immediate: a liquidity crisis.
The attacker does not need to bankrupt the organisation directly. They only need to interrupt cash conversion, confidence, and operating capacity long enough for leadership to make bad decisions under pressure. This understanding is missing in too many ransomware plans.
Commonly, those plans are myopically focused on technology: whether systems are being backed up, whether those backups are immutable, and whether the backups are vaulted.
These are all sensible questions, and form part of the best practices I look for in an organization when I’m assessing their operational readiness to handle a destructive cyberattack. More mature organisations will ask questions about responsibilities: is legal counsel retained and is a digital forensics and incident response firm on call. They will ask questions about workflows: how do security hand off what they’ve found to IT for attack surface and threat remediation?
But, the question for the board is sharper: “Can the organisation fund the recovery while revenue, trust, and operational throughput are impaired?”
That is not a theoretical question. In a serious ransomware or wiper event, the recovery cost curve can move faster than the recovery curve itself.
Ransomware Breaks Cashflow Before It Breaks the Balance Sheet
A ransomware attack can turn a profitable organisation into a cash-constrained organisation in days.
The balance sheet may still look healthy. The annual report may still look respectable. The organisation may still have customers, demand, assets, and a viable business model. None of that matters if the operational machinery that converts the organisation’s activity into cash is offline or degraded.
Billing may stop. Claims may not be processed. Orders may not be fulfilled. Bookings may not be taken. Customers may be unable to pay. Suppliers may refuse to ship. Logistics cannot be organised. Contact centres may be overwhelmed. Digital channels may be unavailable. Manual workarounds may keep the lights on, albeit barely compared with the responsiveness customers have become accustomed to, but they will not keep the cash moving at normal Business-as-Usual speed.
At the same time, the cost base does not politely pause while the response and recovery teams work out what happened and take corrective action: staff still need to be paid. Rent will need to be paid. Debt requires servicing. Suppliers and contractors need to be paid.
In addition, costs related to incident response firms, lawyers, recovery engineers, crisis communications advisers, identity specialists, cloud capacity, replacement hardware, emergency licences, overtime, travel, and expenses will all start appearing at precisely the moment the organisation is least operationally efficient.
This is why ransomware is not only a question of technical recoverability, it is also a question of financial endurance.
The Cost Curve Moves Faster Than the Recovery Curve
Most organisations underestimate the speed at which recovery spending accelerates.
In the first 24 to 72 hours, the organisation may need to engage external counsel, DFIR support, recovery engineering, communications advisers, identity specialists, cloud services, forensic tooling, emergency infrastructure and possibly ransom negotiation support. It may need to bring in contractors, extend support arrangements, replace devices, rebuild environments, ship hardware, acquire storage, uplift network capacity,and pay for emergency travel.
Those costs are not evenly distributed over the incident's lifetime; they arrive early. They arrive while facts are incomplete. They arrive while the authority is unclear. They arrive while the organisation is still arguing about who owns which decision. This creates a dangerous mismatch.
The business may need to spend quickly to recover safely, but its normal financial controls may be designed for ordinary trading conditions. Procurement processes, approval thresholds, purchase order requirements, vendor onboarding rules, and legal review cycles may all become friction or unachievable at the worst possible moment.
Good governance is essential. Bureaucracy masquerading as governance is lethal during a destructive cyberattack.
The organisations that cope best are not reckless with money; they have decided in advance what can be authorised, by whom, under what conditions, and with what evidential trail.
Insurance Is Not Operational Liquidity
Cyber insurance can be valuable. It can provide access to expertise, though across the several hundred incidents I’ve dealt with, I’ve seen the quality of insurer-supplied incident responders vary hugely! It can help offset financial loss and impose useful discipline and experience before an incident. But insurance is not the same thing as operational liquidity.
Insurance does not automatically put cash in the bank on day one. It does not remove the need to make decisions. It does not guarantee every cost is covered. It does not always eliminate consent requirements, panel-provider constraints, coverage questions, exclusions, waiting periods, claim validation, or reimbursement delays.
A board that treats insurance as the recovery funding plan is confusing a financial risk transfer mechanism with an operating model.
The question should not simply be, “Are we insured?”;it should be, “Can we pay for what needs to happen before the insurer reimburses, disputes, approves, or excludes it?”
That is a conversation among the CFO, treasurer, general counsel, CISO, and the board. It should happen before the incident, not during one of the worst days of their career.
Financial Pressure Drives Bad Cyber Decisions
One of the reasons ransomware works so well is that it compresses decision-making.
The attacker creates simultaneous pressure across operations, finance, legal, reputation, customer confidence, regulatory exposure, and executive accountability. The more the business feels cash bleeding out of the organisation, the more attractive bad decisions can start to look.
That is when organisations start restoring too early, reconnecting too quickly, skipping validation, relying on untrusted credentials, accepting vague assurances, paying for speed rather than assurance, or presenting a recovery narrative that is more confident than the evidence supports.
Sometimes, early restoration is necessary. That is reality. The risk is not restoring early, the risk is restoring early while pretending the organisation has achieved trusted recovery.
Financial stress changes the psychology of recovery. It can make a leadership team more willing to accept fragile assumptions because every additional day of disruption feels unaffordable.
That is why the financial model of recovery must be part of the cyber resilience model. If the business does not know how long it can absorb degraded revenue, increased recovery burn, and delayed cash conversion, it does not really understand its ransomware exposure.
The Minimum Viable Company Needs a Minimum Viable Cashflow
I have written before about the Minimum Viable Company: the smallest set of services, systems, people, suppliers, data, identities, processes, and facilities required to keep the organisation alive during a destructive cyberattack. The Minimum Viable Company concept should also include cashflow.
A Minimum Viable Company is not just the minimum set of systems required to operate: it is the minimum set of capabilities required to preserve customer trust, deliver essential services, meet critical obligations, and restart the conversion of work into cash.
For some organisations, that may mean prioritising billing, claims, payments, dispatch, order management or customer service over systems that look more technically interesting. For others, it may mean restoring the ability to evidence regulated activity, issue invoices, collect direct debits, pay staff, maintain trading, manage inventory, or support high-value customers.
This is where business impact analysis often falls short. It asks what is important to the business, but not always what is essential to financial survival under cyber-disrupted conditions.
So, the question is not merely “Which applications are critical?”, but “Which services restart cash conversion, preserve trust and buy the organisation time?”
Boards Should Pre-Authorise the Financial Mechanics of Response and Recovery
A ransomware plan that requires the executive team to invent emergency financial governance during the incident is not a plan; it is a hope with a contact list attached.
Boards should insist that the financial mechanics of response and recovery are pre-agreed and tested.
That means knowing:
Who can approve emergency cyber recovery spending?
What thresholds apply during a declared cyber crisis?
Which suppliers are already contracted and onboarded?
Which retainers exist, and what they cover?
What egress costs are there from archived snapshots?
Whether emergency purchase orders can be raised quickly.
Whether legal, procurement, and finance teams have cyber crisis procedures.
Whether critical vendors will work before paperwork catches up.
Whether the organisation can access emergency liquidity under degraded operating conditions.
Whether bank mandates, approvals, and payment processes still work if identity systems are compromised.
Whether manual payment procedures are documented, authorised and tested.
This is not glamorous work, it will not make an impressive conference demo, and it is unlikely to appear in a vendor magic quadrant.
But when the organisation is trying to recover from a destructive cyberattack, this is the plumbing that determines whether the leadership team can act at the speed of the crisis.
Cyber Recovery Has a Burn Rate
Technology teams think in terms of RTO and RPO, and boards should also think in terms of burn rate.
A serious destructive cyberattack creates a response and recovery burn rate: the rate at which cash, executive attention, customer confidence, operational capacity, and supplier goodwill are consumed while the organisation works to restore trusted services.
Some of that burn rate is financial and measurable, while some of it is reputational and harder to quantify. After an incident, but matter.
This is why in the ransomware exercise scenarios my team builds, we consider:
How much revenue is delayed or lost per day by service line?
Which cash collection mechanisms fail if core platforms are unavailable?
How long can payroll, suppliers, and critical contractors be funded under degraded conditions?
Which customers have contractual termination or service credit rights triggered by outage duration?
Which suppliers can tighten credit terms or pause fulfillment?
How quickly can emergency spending be authorised?
What is the expected external advisory and recovery cost for the first week?
Which recovery choices increase cost but reduce risk?
Which shortcuts reduce costs but increase the risk of reinfection or regulatory or litigation risk?
During our exercises we run with customers, I’m looking to gauge at what point financial pressure begins to distort an organisation’s recovery decision-making.This is the difference between a generic tabletop that performs confidence and a tabletop that exposes reality.
Do Not Let the Ransom Become the Only Financial Scenario
Many ransomware discussions still orbit around the ransom demand. Will the organisation pay? Can it pay? Should it pay? Is payment lawful? Do I need to disclose the payment? Will insurance respond? Will the attacker provide a working decryptor? How much data will I lose during decryption?
These questions distort the conversation. The ransom demand is only one financial variable. In many incidents, the larger financial impact comes from business interruption, recovery labour, customer churn, contractual penalties, regulatory consequences, litigation, emergency infrastructure, communications, security uplift, and the long tail of restoring confidence.
A board that models only the ransom demand is missing the broader economic picture. A better model asks what the organisation needs to spend, preserve, and prioritise to survive the period between disruption and trusted recovery.
That is a much more useful conversation than debating a ransom number in isolation.
What Good Looks Like
What I look for when assessing an organisation’s operational ransomware resilience is a programme that treats financial endurance as part of its overall operational resilience. That means the board can answer the following questions before the incident:
What is our minimum viable operating model under ransomware conditions?
Which services are required to restart cash conversion?
How much liquidity do we need to fund the first 30 days of recovery?
Who can authorise emergency spend and under what trigger?
Which suppliers are pre-contracted for response and recovery?
What does cyber insurance cover, what does it not cover, and how quickly does cash flow?
Which payment and banking processes survive identity compromise?
How do we preserve payroll, supplier confidence, and customer trust during degraded operations?
Which recovery decisions are we willing to fund because they reduce long-term risk?
How do we evidence to regulators, insurers, and customers that recovery decisions were controlled, proportionate, and risk-informed?
This is not solely the CISO’s responsibility. In fact, if the CISO is the only executive thinking about these questions, the organisation has already misunderstood the nature of the crisis.
Ransomware resilience is a board, CEO, CFO, COO, CIO, CISO, general counsel, and communications problem. It lives at the intersection of money, trust, and operational control.
The Board-Level Test
The next time a board reviews ransomware readiness, it should resist the temptation to stop at the usual assurance questions.
Immutable backups? Tick.
Vaulted backups? Tick.
Incident response retainer? Tick.
Cyber insurance? Tick.
Tabletop exercise? Tick.
But not sufficient, instead the board should ask: “If ransomware materially disrupts revenue-generating operations on Monday morning, can we fund, govern, and sustain a trusted recovery by Friday without making unsafe decisions?”
That question shifts the conversation by forcing the organisation to connect cyber recovery with treasury, procurement, delegated authority, supplier management, customer obligations, insurance, crisis communications, and business prioritisation.
It also exposes the comforting fiction that ransomware recovery is mainly a technical restoration problem; it is not. Restoring systems is hard; restoring trust is harder; funding while the business is impaired is harder still.
The Bottom Line
Ransomware does not just encrypt data; it attacks the organisation’s ability to make rational decisions while cash, confidence, and operational capacity are under pressure.
That is why leadership teams need to treat cyber recovery as both a financial endurance problem and a technical recovery problem.
The organisations that recover best will not be the ones with the neatest PowerPoint diagram. They will be the ones who know what must come back first, what it costs to bring it back safely, who can authorise the spend, how long they can operate under degraded conditions and which decisions they will refuse to take even when the pressure is ugly.
The question is not just whether you can recover; the question is whether you can afford to recover properly.
In ransomware, the most dangerous recovery decision is often made when the organisation is running out of money, patience, or confidence.