It's been over a year since the NotPetya ransomware made it's way around the world, with a primary focus on Europe. Since that time, the companies who were directly effected (those whose networks were shutdown and were unable to do business) have faced costs of well over $1B. That doesn't include the costs they've incurred due to the PR nightmare they faced, or the cost of longterm business lost to the competition. It also doesn't consider the cost to the downstream businesses who were effected through no fault of their own. Shipping giant Maersk claims to have lost somewhere in the vicinty of $300M in lost revenues, remdiation costs, and payments to business partners; but what about the trucking companies who lost business while Maersk was shut down? Clearly, $1.2 billion is only a part of the total cost of NotPetya.
Wired recently published a very detailed article looking at the global effects of NotPetya (with a specific focus on Maersk), how the virus spread, and the cybercriminals' links to the Russian government. You can read the article here, but if it falls under the category of TL;DR (too long; didn't read), you can take away a handful of reminders...
Hardware and Networking
Direct Costs Associated
Indirect Costs Associated
While the Wired article talks about all of the negatives associated with a ransomware outbreak, there's also a way to benefit from taking the proper measures (aside from not having to pay all of the costs); having a properly secured and backed up network can be a HUGE marketing tool. For a prospect considering your company and your competition down the street, if you are able to lay out every defensive measure you have in place, and allay any fears that prospect may have, you have a huge competitive advantage. Make the most of that advantage, and learn from others' mistakes. Secure your network and back your data up (with an easily recoverable solution) on a regular basis.