The Cost of an Incident

Amanda Draeger

ShmooCon XX (Final) · Day 1 · One Track Mind

Overview

In "The Cost of an Incident," Amanda Draeger, a Cyber Risk Engineer, dissects the multifaceted financial implications of cyber incidents, offering a critical perspective for security professionals struggling to justify investments to organizational leadership. Drawing from her unique vantage point within the cyber insurance industry, Draeger illuminates how incidents translate into tangible dollar figures, a language universally understood by business executives. The talk serves as a practical guide, empowering technical experts to articulate security risks not merely as abstract threats, but as concrete financial liabilities that can severely impact an organization's bottom line.

Watch on YouTube

Visual summary for The Cost of an Incident by Amanda Draeger
Visual summary for The Cost of an Incident by Amanda Draeger

Key moments

  1. 6:50 What is a cyber risk engineer?
  2. 9:00 Convincing leadership: talk in dollars
  3. 9:40 Direct incident costs breakdown
  4. 11:50 Cost of data breach notification
  5. 14:00 Long duration of business interruption

The Cost of an Incident

Speakers: Amanda Draeger

Conference: ShmooCon

YouTube: https://www.youtube.com/watch?v=wXbnUm88IJw

Overview

In "The Cost of an Incident," Amanda Draeger, a Cyber Risk Engineer, dissects the multifaceted financial implications of cyber incidents, offering a critical perspective for security professionals struggling to justify investments to organizational leadership. Drawing from her unique vantage point within the cyber insurance industry, Draeger illuminates how incidents translate into tangible dollar figures, a language universally understood by business executives. The talk serves as a practical guide, empowering technical experts to articulate security risks not merely as abstract threats, but as concrete financial liabilities that can severely impact an organization's bottom line.

Draeger's presentation underscores a fundamental challenge in cybersecurity: the disconnect between technical understanding and executive decision-making. By breaking down incident costs into direct, compliance, business interruption, regulatory, reputational, and betterment categories, she provides a comprehensive framework for assessing financial exposure. This holistic view is crucial for organizations to move beyond reactive incident response to proactive risk management, strategically allocating resources to mitigate the most impactful financial threats.

The talk is particularly relevant in today's increasingly complex threat landscape, where ransomware attacks, data breaches, and supply chain disruptions are commonplace. Draeger's insights are invaluable for any organization seeking to mature its security posture, emphasizing that effective cybersecurity is not just about preventing attacks, but also about building resilience and minimizing financial fallout when incidents inevitably occur. Her guidance helps bridge the communication gap, enabling security teams to present compelling, data-driven arguments for necessary security investments.

Background

▶ Watch: What is a cyber risk engineer? (6:50)

Amanda Draeger's role as a Cyber Risk Engineer provides a unique lens through which to examine the financial aftermath of cyber incidents. As she explains, her position involves acting as the cybersecurity expert who assists insurance underwriters—who are primarily insurance experts, not cyber experts—in understanding the technical nuances and actual risks associated with cyber policies and claims. This direct exposure to the claims process, observing what happens when companies experience a "bad day," forms the bedrock of her insights.

The core problem addressed by Draeger is the persistent difficulty security professionals face in convincing organizational leaders to invest adequately in cybersecurity. Often, security arguments are framed in technical terms, discussing "posture," "vulnerabilities," or specific "threat actors"—concepts that can be abstract or intimidating to those outside the technical domain. Leaders, conversely, are typically driven by financial metrics: revenue, profit, cost-efficiency, and return on investment. This communication gap often leads to underfunded security initiatives and a reactive approach to incidents, where investments are only made after a significant breach or financial loss has occurred.

Draeger argues that the most effective way to bridge this gap is to speak in the language of dollars. By translating the potential impact of security failures into quantifiable financial costs, security professionals can present a compelling business case for investment. This involves looking at peer organizations—companies with similar operations or within the same sector—and analyzing the financial consequences of their incidents. Learning from others' misfortunes, and explicitly detailing the financial toll, can be a powerful motivator for leadership to prioritize security. The talk aims to equip attendees with the framework and understanding to articulate these costs and advocate for proactive security measures.

Key Findings

▶ Watch: Convincing leadership: talk in dollars (9:00)

The central finding of Amanda Draeger's talk is that the financial cost of a cyber incident extends far beyond immediate remediation, encompassing a wide array of direct and indirect expenses that can severely impact an organization's long-term viability. She categorizes these costs into six distinct areas, emphasizing that many are often underestimated or overlooked until an incident occurs.

  1. Direct Incident Costs: These are the immediate expenses incurred to contain and eradicate the incident. They include hiring incident response (IR) firms, potentially paying a ransom payment (along with associated cryptocurrency conversion fees and professional negotiator fees), and the cost of replacing network asset loss if equipment is too damaged to recover.
  2. Required Incident Costs (Compliance): These costs stem from regulatory obligations following a data breach, such as notification of regulatory bodies and notification to affected individuals. Critically, these also involve extensive data mining to identify affected individuals and data types, a process often far more complex and time-consuming than anticipated, particularly with poorly organized or legacy data. Notification alone can cost approximately $1 per person for mail notifications in the U.S., plus the cost of credit monitoring.
  3. Business Interruption (BI): This represents the lost revenue or profit due to systems being offline or degraded. Draeger highlights that downtime often spans weeks or even months, with some severe cases extending over a year. The concept of contingent BI or dependent BI is also crucial, where an organization's operations are disrupted not by its own incident, but by an incident affecting a key supplier.
  4. Regulatory Costs: Beyond compliance notifications, these involve potential legal or regulatory investigations, requiring significant internal resources (pulling staff off mission), legal settlements, fines, and penalties. These costs can materialize years after an incident.
  5. Reputational Costs: While difficult to quantify and generally not covered by insurance, Draeger notes that organizations that are transparent about incidents tend to retain customer trust more effectively. A damaged reputation can lead to loss of customers and market share.
  6. Betterment: These are long-term upgrades or complete system overhauls often mandated by post-incident assessments or legal settlements. While improving future security, these significant investments are typically not covered by insurance, representing a substantial, self-funded cost.

Draeger stresses that the scale of these costs is significantly influenced by an organization's proactive measures. Factors like network complexity, data governance practices, the resilience and restorability of backups, the existence and practice of an incident response plan, and a pre-defined crisis communication strategy are paramount in minimizing financial exposure. The overarching finding is that investing in these foundational security practices is not merely a technical necessity but a critical financial imperative.

Technical Deep Dive

▶ Watch: Direct incident costs breakdown (9:40)

While "The Cost of an Incident" isn't a deep dive into exploit techniques, it provides a crucial technical perspective on how architectural decisions, operational processes, and data management directly influence the financial impact of cyber incidents. Draeger effectively translates technical best practices into their monetary consequences, offering actionable insights for security professionals.

Minimizing Direct Incident Costs through Network Hygiene:

The complexity of an organization's network architecture is a direct driver of incident response costs. Draeger emphasizes that complex networks suck to do incident response in. The more intricate and interconnected a network, the harder it is for IR teams to identify the scope of a breach, contain it, and eradicate threats. This highlights the importance of:

  • Network Segmentation: Strategically dividing the network into smaller, isolated segments. This limits the lateral movement of attackers, containing the "blast radius" of an incident and making remediation faster and less costly.
  • Simplification: Streamlining network architecture and reducing unnecessary interdependencies.
  • Professional Incident Response Training: While well-meaning IT staff may attempt to handle incidents, a lack of specialized IR training can exacerbate problems. Draeger cites the classic example of an IT person reformatting a "weird" computer, unknowingly destroying crucial forensic evidence from "patient zero." This underlines the need for dedicated IR teams or external experts.
  • Ransomware Negotiation Expertise: For ransomware incidents, professional negotiators are highly recommended. They understand how to interact with threat actors and, importantly, can decipher the nuances of insurance policies (as actors sometimes acquire these policies as bargaining chips). This expertise can significantly reduce the final ransom payment or even prevent payment by clarifying coverage limitations.

Data Governance as Financial Risk Management:

Draeger provocatively states, "data is nuclear waste." This analogy underscores that every piece of data an organization collects and retains represents a potential liability. The more data, especially sensitive data, the higher the risk and the greater the potential cost of a breach. Key technical and procedural aspects here include:

  • Data Minimization: Collecting and retaining only the absolute minimum data required for regulatory compliance and business operations.
  • Data Destruction Policies: Implementing robust processes for securely destroying data that is no longer needed.
  • Data Labeling and Classification: Accurately labeling all data, especially sensitive Personally Identifiable Information (PII) or protected health information. This is critical for efficient data mining post-breach to identify affected individuals, which is a significant cost driver. The challenge is immense, particularly with legacy data, such as "scanned in documents that were originally handwritten," which defy automated classification.
  • Discoverability: A legal term referring to information that must be produced during legal proceedings. Poor data governance increases discoverability risks and associated legal costs.

Minimizing Business Interruption through Operational Resilience:

Business interruption costs are directly tied to downtime. Technical and operational strategies to minimize this include:

  • Ransomware-Resistant Backups: This is paramount. While "completely offline" backups are ideal, good segmentation and ensuring backups are immutable or logically separated from the production network are crucial. The ability to actually rebuild the entire network from these backups is the ultimate test.
  • Practicing Backup Restoration: Simply having backups is insufficient; organizations must regularly practice restoring them to ensure their integrity and the efficiency of the restoration process.
  • Retaining Specialty IR Firms: For organizations in niche sectors (e.g., medical, manufacturing) with specialized operational technology (OT) or industrial control systems (ICS), having specialty incident response firms on retainer is critical. These firms have limited capacity and prioritize their contracted clients.
  • Paper-Based Incident Response Plans: A critical, often overlooked technical detail. When the entire network is down, digital plans are inaccessible. A literal paper copy of the IR plan, including critical phone numbers and contacts, ensures the organization can initiate response efforts.
  • Manual Operations for Critical Processes: Identifying and planning for the ability to run critical business processes manually, even on paper, during a network outage. This involves having physical forms, manual procedures, and trained staff ready to pivot.

Proving Due Care for Regulatory Compliance:

Regulatory costs are often influenced by an organization's ability to demonstrate due care. This goes beyond merely meeting minimum compliance checkboxes. Technically, it involves:

  • Logging and Monitoring: Comprehensive logging of system activities and robust monitoring capabilities can provide evidence of security controls in place and prompt response to anomalies, demonstrating due care.
  • Security Audits and Assessments: Regularly conducting technical audits and vulnerability assessments and acting on their findings demonstrates a proactive approach to security.
  • Documentation of Security Controls: Maintaining detailed documentation of security architectures, configurations, and policies supports the claim of due care.

In essence, Draeger’s technical deep dive isn't about specific vulnerabilities but about the pervasive impact of fundamental security engineering and operational discipline on an organization's financial resilience in the face of cyber adversity.

Demo / Proof of Concept

▶ Watch: Cost of data breach notification (11:50)

The talk "The Cost of an Incident" by Amanda Draeger is a conceptual and strategic presentation, focusing on financial frameworks and best practices rather than technical demonstrations. As such, there was no live demo or proof of concept presented during the session. The content relies on Draeger's extensive experience as a Cyber Risk Engineer and observations from real-world cyber insurance claims.

Defensive Implications

▶ Watch: Long duration of business interruption (14:00)

Amanda Draeger's talk provides a robust framework for defenders to not only understand the true cost of cyber incidents but also to strategically prioritize and communicate security investments. The defensive implications are clear and actionable, emphasizing proactive measures that directly mitigate financial risk.

  1. Simplify and Segment Networks Aggressively: Defenders must champion network simplification and segmentation. Complex, flat networks dramatically increase incident response costs and recovery times. By isolating critical assets and limiting lateral movement, organizations can reduce the "blast radius" of an attack, making containment and eradication significantly faster and cheaper. This involves implementing robust firewall rules, VLANs, and zero-trust principles to control traffic flow.
  2. Invest in Specialized Incident Response Capabilities: General IT staff are often not equipped for forensic-grade incident response. Organizations should invest in dedicated IR training for key personnel or, more commonly, establish retainers with professional incident response firms. For ransomware incidents, engaging professional negotiators is highly recommended to manage interactions with threat actors and potentially reduce ransom payments, leveraging their understanding of both cybercrime tactics and insurance coverage nuances.
  3. Implement Ransomware-Resistant Backups with Verified Restoration: The cornerstone of recovery is reliable backups. Defenders must ensure backups are truly ransomware-resistant—meaning they are immutable, offline, or logically isolated from the production network to prevent compromise. Crucially, organizations must regularly practice restoring backups to verify their integrity and the efficiency of the restoration process. This includes full system rebuilds to simulate worst-case scenarios and identify bottlenecks before a real incident.
  4. Enforce Strict Data Governance and Minimization: Data is a liability. Defenders should advocate for data minimization policies, ensuring the organization only collects and retains data absolutely necessary for business and regulatory compliance. Robust data classification and labeling are essential to quickly identify sensitive data post-breach, streamlining notification processes. Implementing aggressive data destruction policies for expired or unnecessary data reduces the overall attack surface and potential financial exposure.
  5. Develop and Practice a Comprehensive Incident Response Plan (on Paper): An IR plan is only effective if it's accessible and practiced. Defenders must create detailed plans that include roles, responsibilities, communication protocols, and escalation paths. Critically, this plan should exist in a physical, paper copy with essential contact information (e.g., phone numbers of key personnel, retained firms) so it remains usable when networks are completely down. Regular tabletop exercises and full-scale simulations are indispensable for identifying gaps and improving response efficiency.
  6. Plan for Manual Business Operations During Outages: For critical business processes, defenders should work with operational teams to develop manual fallback procedures. This means identifying core functions that can operate without the network, having physical forms or manual workarounds prepared, and training staff on these procedures. This reduces business interruption costs by allowing essential operations to continue, even in a degraded state.
  7. Prioritize "Due Care" Over Minimum Compliance: While compliance is necessary, defenders should aim for due care, demonstrating that the organization has gone beyond minimum requirements to implement reasonable and robust security measures. This involves continuous monitoring, proactive vulnerability management, and clear documentation of security controls, which can significantly reduce regulatory fines and legal liabilities post-incident.
  8. Proactive Crisis Communications Planning: Reputational damage is difficult to quantify but can be devastating. Defenders should collaborate with executive leadership and crisis communication professionals to develop a pre-approved communication plan for various incident scenarios. Transparency and clear, empathetic communication can help maintain customer trust and mitigate long-term reputational harm.

By adopting these defensive strategies, organizations can transform cybersecurity from a perceived cost center into a critical component of financial risk management, ultimately building greater resilience against the inevitable threats they face.

Key Takeaways

  • Communicate Security in Dollars: Translate technical security risks into quantifiable financial costs (e.g., direct, business interruption, regulatory fines) to effectively convince organizational leadership to invest in cybersecurity.
  • Minimize and Govern Data Rigorously: Treat data as "nuclear waste" by collecting only what is essential, destroying what is not needed, and accurately labeling all data to reduce liability and streamline breach notification costs.
  • Implement and Practice Ransomware-Resistant Backups: Ensure backups are isolated, immutable, and regularly practiced for restoration to minimize downtime and avoid catastrophic data loss from ransomware or other destructive attacks.
  • Develop and Rehearse Comprehensive Incident Response Plans: Create detailed, accessible (including paper copies) incident response plans, and conduct frequent drills and simulations to ensure preparedness and minimize the duration and cost of an incident.
  • Prioritize Network Segmentation and Simplification: Design networks with segmentation and simplicity in mind to limit the spread of attacks, making incident response faster, easier, and less expensive.
  • Plan for Manual Operations and Retain Specialized Expertise: Identify critical business processes that can run manually during a network outage and consider retaining specialty incident response firms for niche operational technology environments.

About the Speaker(s)

Amanda Draeger is a Cyber Risk Engineer, a specialized role within the cyber insurance sector. Her unique position involves serving as the dedicated cybersecurity expert who advises insurance underwriters, who are primarily insurance specialists rather than cyber experts. In this capacity, Draeger helps bridge the knowledge gap between complex cybersecurity concepts and the financial risk assessments required for insurance policies and claims. She is directly involved in reviewing cyber incidents and claims as they arise, allowing her to gain firsthand insights into the true financial costs and operational challenges organizations face during and after a breach. Her experience has made her adept at translating technical security issues into business-relevant financial terms, a skill she emphasizes as crucial for effective security advocacy.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This talk provides a clear, no-nonsense breakdown of the true financial costs associated with cyber incidents, drawing insights directly from an insurance cyber risk engineer's perspective. It effectively translates complex security risks into tangible dollar figures, offering actionable strategies for security professionals to communicate value and secure investment from non-technical leadership. It's a pragmatic, real-world look at the financial aftermath of a breach.

Heather Calloway (CISO) — MUST SEE

Amanda Draeger's "The Cost of an Incident" offers an essential framework for translating technical cybersecurity risks into the financial language understood by executive leadership. Drawing from her experience in cyber insurance, Draeger meticulously breaks down incident costs—from direct remediation to long-tail regulatory fines and betterment—providing a clear, unsentimental perspective on real-world business exposure. This presentation empowers security leaders to move beyond abstract threats, enabling them to articulate security as a critical financial imperative and drive evidence-based investment decisions that foster institutional accountability and resilience.

→ Top-rated talks at ShmooCon XX (Final)

All talks from ShmooCon XX (Final)