We tend to see cyber threats measured in economic terms. Dollar amounts become shorthand for societal, political, and even human harm. Policymakers and other officials set the price tag set high enough to justify massive investments in remediation and protection, pushing the tally into the trillions of dollars. In the end, society is left feeling exposed, afraid, and overwhelmed. And we shouldn’t.
The gap between the economic harm we fear and the levels we’ve experienced are vastly different. And that gap continues to widen. The effects of cyber attacks and activity – from crime to war – remain well under $1 trillion annually, even as the “attack surface” is said to be growing rapidly. The numbers don’t add up, and that’s because they aren’t supposed to. What we fear is fundamentally misaligned from how we measure it.
Cyber is not a systemic problem on an economic basis. Four decades of empirical evidence and lived experience have shown this again and again. Doubtless, there are economic effects from cyber attacks, from theft and fraud to temporary disruption. The impacts can be severe for individual targets and perhaps their immediate trading partners, but that is much different from the tales of widespread carnage often peddled as hypothetical worst-case scenarios.
Instead of fearing the big-ticket economic consequences – for which there has never been much in the way of justification – we should remember that threats to election integrity, compromises of elected officials, and espionage have the potential to shape government behavior and perhaps even reshape the very institutions on which we rely. Security strategy is thus crucial to defending the homeland – and we won’t get there by counting the nickels and dimes of economic effect.
The cost of “carnage”
The cyber domain has been called a “field of confrontation” for good reason. Adversaries engage in a wide range of cyber operations, and the potential for mayhem is indeed significant. In the early days of the internet, the economic losses from major catastrophe events topped out at approximately $120 billion in 2003 and remained high in 2004 at around $70 billion. While it is fair to question whether the losses from past events may have been exaggerated upward, the losses from early activity still remain higher than the decades that followed.

Source: Author, updated from Journal of Strategic Competition
Even when taken in aggregate – at north of $350 billion, indexed for inflation – cyber catastrophe economic losses still fall far short of the scenarios imagined. For example, a 2025 study commissioned by Lloyd’s of London, proposed that a single systemic cyber event affecting the global financial system could lead to economic losses of $3.5 trillion. The threat feared is clearly completely detached from four decades of reality and likely relies on a view of unimpeded contagion reminiscent of the 1988 Morris Worm. Meanwhile, back-to-back state-actor cyber attacks in 2017 resulted in economic losses at the time of only $14 billion, with the economic losses from all subsequent cyber attacks failing to reach half that amount. Over time, as the attack surface has reportedly grown, the economic losses from catastrophic cyber events have shrunk – significantly.
It’s not just major events that don’t lead to significant losses – small events fail to accumulate, as well. Cyber crime has been touted as potentially exceeding $23.84 trillion, a level that has even attained a certain level of acceptance, given the amplification it has received from credible actors. More recent – and more disciplined – studies, though, put the estimated economic effects of cyber crime at $500 billion annually. Within cyber crime, ransomware has been called a multi-trillion-dollar problem, although annual revenues to ransomware actors are under $1 billion and falling. Even adding the cost of defense doesn’t bring the total to $1 trillion: It’s currently below $40 billion and not expected to approach $150 billion until 2035.
The math just doesn’t work. Even assuming that there’s a worst-case scenario looming in the background doesn’t move the needle sufficiently. If NotPetya was a near miss at $10 billion in economic harm, what would the realistic worst case have been? $20 billion? $50 billion? $100 billion? Finding a realistic answer and the relevant evidence to support it would still fail to address the fundamental problem – and across state-actor cyber catastrophes more broadly – the mismatch between motivation and impact.
Follow the motivation
To understand the limited economic effects of cyber attacks and operations, Will Lyne and Jamie MacColl wisely suggest that we “follow the money.” While they emphasize the hunt for cash over the use of technology, their nod to motivation is far more interesting. Even beyond ransomware gangs and up through the most sophisticated state actors, consideration of motivation gets overrun by talk of trillions and trillions of dollars in economic (and societal) carnage. Motivation matters, though. In fact, it’s crucial to understanding how attacks are conceived and conducted, let alone whether or not they are successful or impactful.
Cyber crime actors want to make money, but they aren’t aiming for trillions of dollars. The Lazaraus Group’s $2 billion haul last year brought the all-time total theft of crypto assets to $6.75 billion. The FBI puts U.S. cyber crime losses at $21 billion, a far cry from the $10.5 trillion once forecasted. Even in the extreme, estimates that Chinese advanced persistent threats (APTs) caused $225-600 billion in economic impact in 2017 only begin to add scale. Even that estimate is dubious (and not just because of the extremely generous range).
For state actors, it’s a bit more nuanced. Only three direct action-style cyber attacks have caused economic losses of above $1 billion (adjusted for inflation): Yaha in 2003 ($22 billion), WannaCry in 2017 ($5.2 billion), and NotPetya in 2017 ($13 billion). Plenty more have been attempted and achieved limited local impact, but scale generally has been elusive. When states want to cause impact, cyber doesn’t top the list. It can be useful in coercive diplomacy (as was the case with Stuxnet), but the reality that the “cyber war will not take place” has sunk in.
There are some seeming exceptions to this view. China’s “Volt Typhoon” breach was largely seen as prepositioning for the purpose of potential future activation. The breach itself should be seen as hostile, and activation would be more so. However, gauging the potential impact requires some thoughtfulness. Although the scale of the penetration was indeed profound, historical attacks on critical infrastructure have been manageable (if not disappointing). Even the 2015 attack on Ukraine’s energy grid, long used as the reference point for critical infrastructure cyber attacks, affected only 230,000 people for up to six hours. The U.S. Texas and midwestern winter storms of 2021 had a proportionally greater impact in terms of population, with outages lasting 29 hours.
Again, while it would be possible to imagine a more potent attack from Volt Typhoon – and acknowledging the ease of imagination relative to the reality of execution – the question of quantum arises. We’re back to guessing a multiple of a “near miss” and all too often not asked to back it up.
Whether from criminals, state actors, or other parties, there is the risk of unintended consequences. A bad bounce can go a long way. Arguably, that’s exactly what we saw with NotPetya and Yaha. A ransomware actor inadvertently loses control of their tool and causes a systemic effect, or a state actor seeks to disrupt its adversary but hits a global company. This also takes us back to the issue of aggregate economic impact, and to get from Yaha’s $20 billion to the trillions bandied about requires far more justification than we’ve been offered.
Nature of the threat
The numbers don’t tell the real story. The prospect of cyber operations targeting government data (as with SolarWinds), trade secrets (China and Chimera APT Group), government institutions, or election integrity, defies quantification but comes with immense danger. While there are a wide range of cyber attacks and operations that do cause economic impact, they are smaller and more manageable problems that generally can be hedged through business activity (e.g., insurance) and absorbed through commercial activity. Even “catastrophic” cases are far smaller than other widespread drivers of loss (like natural disasters).
This is not to say that security, defense, and even offense are not important considerations. Quite the contrary – we would not be able to absorb and manage the current collection of threats without the investments that have been made, their effectiveness evident at least in part in the decline in economic impacts from cyber catastrophes. Without a doubt, there are sectors and assets that could be more secure, but the runaway worms of 20 or more years ago don’t carry the same weight today that they did then. And as we plan for the next 20 years (and more), we should resist the temptation to hyperbolize. Distracting policymakers with big dollar amounts won’t get us the strategy we need – understanding how to characterize the risk will be far more productive.
Tom Johansmeyer is the Director of the Irregular Warfare Initiative's Journal of Strategic Competition and co-director of the Economic and Legal Warfare Focus Area. He completed his Ph.D. in international conflict analysis at the University of Kent, Canterbury, where his research focused on economic and cyber security. Based in Bermuda, where he also works in the reinsurance industry, Tom has written and spoken extensively on natural and man-made disaster events and their economic consequences. He has an M.A. in global diplomacy from the University of London’s School of Oriental and African Studies, an M.B.A. in accounting from Suffolk University (Boston), and a B.A. in philosophy and history from Ripon College. Tom proudly pushed paper in the U.S. Army in the late 1990s, and if you were in the 2nd Infantry Division in 1998, you might have bugged him for your reassignment orders.