Major new study estimates $600 billion annual hit from unplanned downtime
Unplanned IT outages are inflicting growing damage on the world’s largest companies, according to fresh research from Splunk in partnership with Oxford Economics. The study estimates that the Global 2000 now face an aggregate annual cost from downtime of roughly $600 billion, a 50 percent increase in two years. That translates to an average of about $15,000 lost per minute during an outage and material impacts on revenue, customer retention and market value.
Where the impact is concentrated
The report highlights regional and sector concentrations in the damage. Organizations across EMEA reported the highest average downtime-related costs, at about $354 million per organization annually. Within that mix, information services and technology firms face the heaviest per-company toll—roughly $402 million—followed by energy and utilities ($364 million), retail and consumer goods ($357 million), and financial services ($309 million).
Those sectors are central to Gulf economies and other markets that are rapidly digitizing. The study links rising costs to the growing reliance on cloud platforms, AI-driven operations and third-party digital services, all of which increase systemic complexity and the potential for cascading failures.
Hidden costs extend beyond lost revenue
Downtime produces a chain of downstream impacts that extend beyond immediate revenue loss. The Splunk-Oxford analysis documents several recurring consequences:
- Market erosion: On average, firms experience a 3.4 percent decline in stock price following a single downtime incident.
- Customer churn: Eighty-one percent of technology leaders cited customer loss as a consequence of outages, and nearly half said customers are often the first to detect degradation.
- Ransomware and fines: Average ransomware payouts have nearly tripled since 2024 to about $40 million, and average regulatory fines tied to incidents are reported near $51 million per organization.
- Operational drag: Most respondents noted heavy personnel demands to resolve incidents, with widespread increases in customer support activity and cross-functional pressure on finance and marketing teams.
- Brand recovery: Almost one in five marketing professionals said it takes about a quarter to restore brand health after remediation.
Security and third-party complexity create new exposure
The survey finds a rising share of security-related downtime is linked to SaaS and other third-party applications, with more than half of security leaders now reporting frequent incidents tied to external providers. One-third of security leaders acknowledged downtime is often misclassified as an IT problem, which can slow detection and give attackers an advantage. Only 38 percent of technology executives said they consistently identify root causes for downtime, underscoring gaps in visibility and incident response.
AI is both a tool and a new source of risk
Organizations are investing heavily in AI to detect and triage incidents, with a median annual spend on AI tools aimed at preventing and responding to downtime of $24.5 million. The research suggests that teams defined as “AI workflow and triage experts” achieve better outcomes: they were more likely to avoid public breach disclosures and retain customers after incidents.
At the same time, AI introduces novel failure modes. While more than half of users reported AI reduced overall risk, every technology leader surveyed acknowledged some form of AI-related downtime. Concerns about unpredictable agent behavior are widespread, and respondents emphasized the need for governance and human oversight to contain AI-driven incidents.
What executives are prioritizing
Faced with steep and rising costs, technology leaders are shifting investment priorities toward resilience measures that address complexity and human error. Key priorities cited in the report include:
- End-to-end observability: Three-quarters of ITOps and engineering leaders place observability ahead of traditional infrastructure upgrades, and among the lowest-cost organizations, 98 percent said comprehensive visibility is essential.
- Automation to reduce human error: Two-thirds of respondents flagged automation as a priority for removing manual failure points.
- Targeted AI investments: 85 percent prioritized AI-driven security automation and 65 percent prioritized AI-powered observability to improve real-time detection.
Implications for enterprise leaders
The findings signal a recalibration for boards and C-suite teams. Outages are no longer primarily operational nuisances; they are enterprise risks with balance sheet and reputational consequences. For companies accelerating digital transformation, the study suggests three practical takeaways:
- Invest in full-stack observability and cross-domain telemetry so teams can rapidly pinpoint causes and reduce mean time to resolution.
- Focus automation on repeatable, high-risk human tasks while establishing robust governance for AI agents and human-in-the-loop controls.
- Embed third-party risk management into resilience planning, including contractual SLAs, continuous monitoring and incident playbooks for SaaS dependencies.
Splunk and Oxford Economics gathered responses from 2,000 executives at Global 2000 companies across 20 countries and nine industry groups. The results add to a growing industry consensus that complexity from cloud, AI and external services requires not just new tooling, but changes in operating model and accountability.
Methodology note: The study used a hybrid survey approach and represents perspectives from technology, finance and marketing functions among large global firms. For full details, see the Splunk report.







