Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.

Sep 02 2026
Security

FAIR for Hospitals: What a Ransomware Shutdown Really Costs

The FAIR framework provides guidance to health systems on how much to invest in cybersecurity to protect against ransomware attacks.

A ransomware shutdown in healthcare could cost $1.9 million per day on average, according to one 2024 report. The good news is that the average cost for healthcare providers to rebound from a ransomware incident dropped from $2.6 million in 2024 to just over $1 million in 2025, according to the “State of Ransomware in Healthcare 2025” report from Sophos.

Still, given how serious ransomware threats are, health systems face challenges to build the right budget to protect against these attacks. Frameworks such as Factor Analysis of Information Risk (FAIR) provide a model for how to gauge the risk of ransomware attacks and what they will cost. In 2021, Jack Jones, then a CISO at Nationwide Insurance, established FAIR when the company needed to quantify risk for cybersecurity attacks. Today, Jones is the chairman of the FAIR Institute, which teaches organizations how to quantify the risk of attacks through the FAIR model and how to conduct a risk analysis.

The methodology allows CISOs to learn how to communicate to their board like a chief revenue officer, says Bernadette Dunn, director of business operations and development at the FAIR Institute. It teaches that a company should allocate budget for cybersecurity if the probability of an attack is higher than an organization’s risk tolerance, Dunn says.

“We communicate risk and the likelihood of a ransomware event happening, and if it happens, how much it’s going to cost the organization,” she explains.

Dunn also notes the role of AI in ransomware attacks.

“The bad folks are always attacking now, with AI especially, so we’re constantly trying to make sure we have the right controls in place,” Dunn says. “It’s this constant whack-a-mole scenario.”

Click the banner below to read CDW's new 2026 Cybersecurity Research Report.

 

Liat Hayun, senior vice president of product management at cybersecurity firm Tenable, says the FAIR framework provides the healthcare industry with the discipline it needs more than most industries to keep it accountable.

“For too long, the sector has relied on subjective heat maps and severity scores that fail to communicate actual business exposure to executives,” Hayun says.

The framework assigns a dollar amount to potential losses based on the frequency and financial magnitude of potential cyberattacks. Hayun explains that health systems face difficulties in convincing finance teams to invest in cybersecurity because of the organizations’ standard vulnerability ratings.

“FAIR gives healthcare security teams a common unit for comparing risks that otherwise look completely unrelated, like a ransomware scenario versus a third-party vendor breach,” Hayun says. “By evaluating the likelihood of an attack and its financial magnitude, a CISO can prioritize budget requests in the context of actual impact instead of simply reacting to whichever finding is loudest.”

Why Ransomware Attacks in Healthcare Are So Expensive

Ransomware is particularly costly in healthcare because health providers cannot shut down their systems during an attack. Disconnected electronic health record (EHR) software, imaging tools and medical devices directly affect patient care. Shutdowns from ransomware attacks also lead to canceled procedures, diverted ambulances and stalled billing cycles, Hayun says.

“Because an IT outage in healthcare directly impacts patient safety, connected infrastructure and immediate cash flow, ransomware becomes exponentially more damaging than in almost any other sector,” she explains.

Not only is ransomware costly in dollars, but these incidents increase in-hospital mortality by up to 38%, according to a February 2026 study in American Economic Journal: Economic Policy. Ransomware at hospitals also drives up cardiac arrests at these facilities by 81% per an April 2024 study by University of California, San Diego researchers in Critical Care Explorations.

READ MORE: Quantify cyber risk to justify strategic cybersecurity investments.

HIPAA exposure from ransomware attacks, along with an aging device fleet, also puts healthcare systems at financial risk. Compromised patient data leads to mandatory breach notifications as well as credit monitoring, regulatory fines and legal fallout, Hayun notes.

“Ultimately, the ransom demand is just the down payment,” she says. “The true fee is the combined burden of weeks of operational downtime, infrastructure restoration and the lasting legal consequences.”

Healthcare is targeted because it is a highly regulated industry with sensitive protected health information (PHI), Dunn says.

“Criminals know this, so they go where they’re going to make the most money,” Dunn says.

Liat Hayun
This turns FAIR from a static spreadsheet exercise into a live, defensible metric, allowing health systems to measure and report ongoing risk reduction in actual dollars instead of arbitrary vulnerability counts.”

Liat Hayun Senior Vice President of Product Management, Tenable

How Healthcare Organizations Can Justify Cybersecurity Investments

Cybersecurity staff at health systems can justify investments by noting which actions offer the greatest risk, according to Hayun.

FAIR has a structured, repeatable model that can allow health systems to maintain regulatory compliance, which helps CISOs justify the costs to leadership.

“This clear communication bridges the gap between technical teams, finance experts and executive leadership, producing numbers that hold up in board and cyber insurance conversations in a way qualitative labels like ‘high risk’ never do,” Hayun says.

Here are some tips from experts on how to use the FAIR methodology:

Show a tangible financial benefit: A key way to secure funding from a hospital board is to show clear financial ROI for cybersecurity efforts, according to Hayun. Ask for investment in specific instead of general terms, she advises.

“Instead of asking a hospital board for funding to patch a list of abstract findings, a CISO can translate technical severity into clear financial ROI,” Hayun says. “That turns ‘we found critical vulnerabilities’ into ‘this control cuts expected annual loss by $X and pays for itself in under a year,’ which is a far easier ask.”

Start small with concrete loss scenarios: Lead a conversation on cybersecurity investment with two or three specific examples, such as ransomware shutdowns impacting EHR systems, rather than trying to quantify the cost to the entire organization, Hayun suggests.

Dunn recommends practicing cyber-risk analysis on less high-stakes decisions so healthcare teams become familiar with finding the risk analysis data. A less critical decision could include the frequency of when to change a password, she says.

Populate the model with existing data: “Feed the model with data already obtained from asset and vulnerability management tools instead of relying on guesswork, and pull in finance and clinical operations early to validate the loss estimates,” Hayun advises.

Work with tech partners to identify risk: Exposure management platforms allow health systems to map vulnerabilities and misconfigurations as well as identify risk while creating pathways to PHI or life-critical systems, says Hayun.

“This turns FAIR from a static spreadsheet exercise into a live, defensible metric, allowing health systems to measure and report ongoing risk reduction in actual dollars instead of arbitrary vulnerability counts,” Hayun says.

Partners such as CDW can provide guidance on how to justify strategic cybersecurity investments and implement the FAIR framework.

BraunS/Getty Images