In July 2024, a faulty CrowdStrike update disrupted the operation of around 8.5 million Windows devices. Technically, the issue affected less than 1 per cent of the global installed base of devices running this operating system. From a business perspective, however, the scale was entirely different. Delta Air Lines cancelled around 7,000 flights within five days. The airline estimated lost revenue at $380 million, additional operating costs at $170 million, and the impact of the incident on the quarter’s operating margin at 2.3 percentage points.
This clearly illustrates the problem CIOs face today. The board does not need to be told that ‘the system is critical’ or that its availability stands at 99.9 per cent. It needs to know how much an hour of downtime costs, which processes will cease to function, how long the company can operate manually, and where the point of dependency on an external supplier lies.
This distinction is becoming increasingly significant in financial terms. According to the Uptime Institute, 57 per cent of respondents who had experienced a major outage estimated the cost of their most recent such incident at over $100,000. One in five cited a figure of over $1 million. At the same time, around two-thirds of publicly reported outages over the last nine years were linked to external IT, data centre, telecoms or cloud service providers.
This changes the economics of resilience. A company may have its own environment well secured and still suffer significant losses due to a failure by a single technology partner. The problem is therefore no longer solely the quality of the infrastructure. It has become the concentration of business dependencies.
System failures hit the bottom line
The cyberattack on Marks & Spencer in 2025 provides an even clearer example. The company took some of its systems offline, suspended online orders and, for a time, managed parts of its warehousing, ordering and logistics processes manually. Initially, it estimated the impact of the incident on its operating profit for the 2025/26 financial year at around £300 million, before taking into account insurance and loss-mitigation measures.
In its full-year results, M&S ultimately reported £131.3 million in direct costs related to the incident, including £109.3 million for the response and system restoration, and £22 million for external specialists, including legal and professional support. The company received £100 million from its insurance policy. In the same year, its adjusted pre-tax profit fell by 23.8 per cent, and sales in the Fashion, Home & Beauty segment by 7.7 per cent; the company cited the suspension of online trading and problems with stock flow as significant consequences of the incident.
This is where the discussion of the ‘IT problem’ ends. A disruption to technology affects sales figures, logistics costs, stock levels, customer service and cash flow. In regulated sectors, reporting obligations and the risk of sanctions also come into play.
Technology risk reaches board level
In Poland, this takes on added significance following the entry into force on 3 April 2026 of the amendment to the Act on the National Cybersecurity System implementing NIS2. The Ministry of Digital Affairs estimates that the new regulations may apply to around 38,000 entities. The Act introduces liability for the managers of critical and important entities for the implementation of cybersecurity tasks. Companies meeting the criteria must, amongst other things, implement an information security management system, manage risk and report incidents. For some businesses, the nearest deadline is 3 October 2026, when the deadline for submitting an application for inclusion on the KSC register expires.
At the same time, business exposure itself is increasing. In the Allianz Risk Barometer 2026, cyber incidents rank first among global business risks, at 42 per cent. AI has risen from tenth to second place, reaching 32 per cent, whilst business interruptions took third place.
Consequently, the value of the CIO at board level depends less and less on the number of reported vulnerabilities or infrastructure metrics. Far more important is the ability to quantify exposure: revenue at risk per hour of downtime, the maximum acceptable downtime for a process, the cost of restoring operations, and dependencies that the company is unable to replace quickly.
Only then does technical risk become the basis on which to decide how much resilience the company actually wishes to purchase.

