One of the most quoted numbers in cybersecurity — Maersk's $300 million NotPetya bill — was a forecast made six weeks in, copied verbatim into the next three reports and never checked again.

Pairs with the Crisis Response Playbook — a ready-to-use strategy tool. Included in the Crisis Response Casebook →

On the morning of 27 June 2017, screens across the world's largest shipping company went dark in minutes. A worm called NotPetya, loosed on Ukraine and spreading with no regard for borders, tore through Maersk's network and encrypted everything it touched. By the next day the company was confirming, in the flattest possible language, that 'IT systems are down across multiple sites and select business units.'8 The company that moves a fifth of the world's container trade suddenly could not tell a truck driver which box to load. And then it did something remarkable: it rebuilt almost the entire estate in ten days, and later told the world what it cost.

The official story is a triumph — a heroic recovery capped by an honest, precise price tag of $200-300 million. The recovery is real and well-corroborated. The price tag is where the story quietly turns, because that number was never actually settled. It was a forecast made six weeks after the attack, then copied forward and never audited.

We expect that the cyber-attack will impact results negatively by USD 200-300m.1
Søren SkouCEO of A.P. Møller - Mærsk, Q2 2017 interim report, August 2017

Ten days to rebuild what would normally take six months: the recovery half of the story is the part that holds up under scrutiny

Start with what is genuinely documented, because it is genuinely impressive. Speaking on a cybersecurity panel at Davos in January 2018, chairman Jim Hagemann Snabe described the scale of the reinstall: 4,000 new servers, 45,000 new PCs, and 2,500 applications, put back over what he called a heroic effort of about ten days — a job he said would normally take roughly six months.4 During that window the company kept cargo moving by hand, absorbing an estimated 20% drop in volume rather than stopping altogether.4 Maersk's own contemporaneous account lines up with the timeline: Maersk Line was taking bookings from existing customers two days after the attack, with operations gradually returning to normal over the following week.5 Compress six months of work into ten days while running a global logistics network on paper and phone calls, and you have earned the story.

The rebuild, as described at Davos
45,000
PCs reinstalled4
4,000
servers rebuilt4
2,500
applications restored4
~10 days
for a normally six-month job4

One detail carries the drama, and it deserves a careful label. Journalist Andy Greenberg reported, from interviews with more than a dozen Maersk IT staff, that NotPetya wiped all of the company's roughly 150 domain controllers — the machines that hold the keys to the whole network — and that administrators eventually found the one surviving copy on a single machine in a Ghana office, offline during a power blackout when the malware struck, its data then physically relayed via Nigeria to the UK to begin the rebuild.6 It is the kind of story that gets repeated as confirmed corporate history. It is not. It comes from one investigative source and has never been confirmed by any Maersk filing or release. Believe it if you like — but know that you are believing a reporter's sources, not the company's books.

The $300 million that was guessed once and never checked again: a preliminary estimate hardened into a settled fact through sheer repetition

Here is the part that gets read backwards. The famous cost figure did not arrive at the end of the ordeal as an audited reckoning. It arrived at the start, as guidance. In the Q2 2017 interim report — issued 16 August, barely six weeks after the attack — Skou told investors Maersk expected a negative impact of $200-300 million.1 That was a preliminary business-interruption estimate, the sort of range a company gives while the dust is still settling. What happened next is the tell: in the Q3 2017 report, the figure reappeared as a $250-300 million impact in Transport & Logistics, carried forward essentially unchanged.2 And in the 2017 annual report's risk-management section, it appeared a third time — 'losses in the order of USD 250-300m' covering lost revenue, IT restoration and extraordinary operating costs.3 Three filings, one number, never revised. Maersk never trued that estimate up to an audited final cost in its public disclosures. It simply repeated its first guess until repetition made it look like a conclusion.

What it was presented asWhat it actually was
Q2 2017 report$200-300m impactForward guidance, six weeks after the attack
Q3 2017 report$250-300m impactThe same range, carried forward unchanged
2017 annual reportLosses 'in the order of' $250-300mRepeated a third time, still not audited
Later coverageThe final cost of NotPetya to MaerskA settled total that was never actually settled
How a forecast became 'the cost'
3 filings
carried the same $200-300m estimate — issued once as forward guidance and never revised into an audited final number in Maersk's own public disclosures3

Why does the mechanism matter? Because a business-interruption estimate and a total cost of damage are two different animals wearing the same suit. The early range was built to answer investors' immediate question — how much will this dent this year's results? — and it was framed around lost revenue and restoration costs the company could see coming. It was never designed to be the last word on what a network-wide wipe costs an organization over years: the deferred capital, the customer relationships strained, the second-order operational drag. When a placeholder number gets no successor, it doesn't stay a placeholder. It becomes the record. The transparency everyone praises Maersk for was real about the recovery and oddly incomplete about the bill.

But wasn't Maersk unusually honest for even telling us?: the openness was genuine, which is exactly why the missing follow-up is worth naming

The fair objection is that Maersk deserves credit, not scrutiny. Most companies hit this hard say as little as legally possible; Maersk put its chairman on a public stage to walk through the wreckage in specifics.4 That is true, and the openness was a real service — it turned a private catastrophe into an industry case study. But candor about the heroics does not settle the arithmetic. The honest counter cuts deeper: in his book Sandworm, Greenberg reported that most of the Maersk staffers he spoke with privately suspected the company's accountants had lowballed the publicized figure.7 That is an attributed claim from anonymous insiders, not a documented fact, and it should be held at exactly that arm's length. But it points at the real gap. The problem was never that Maersk lied. It is that a company praised for transparency put a preliminary estimate into the world, repeated it three times, and let the market treat a forecast as a final accounting — and then never issued the accounting.

A first estimate is a story you'll be forced to keep telling

The instinct in a crisis is to quantify fast — a range calms investors, feeds the press, and buys time. But an early number issued under pressure has a way of outliving the uncertainty that produced it. Repeat it unchanged across a few reporting cycles and it stops reading as a guess and starts reading as the truth, inside the company and out. Two disciplines follow. First, label a preliminary estimate as preliminary every single time you repeat it, or it will quietly promote itself. Second, budget for the true-up: schedule the moment where you replace the placeholder with an audited figure, even if the audited figure is worse. The reputational risk isn't in the first number being rough. It's in never having a second one.

Maersk's ten days are the part that will keep getting told, and they should — a company that rebuilt 45,000 machines while moving cargo by hand did something almost nobody has matched.4 But the more instructive half of the story is the number that never grew up. A $200-300 million estimate was born as a forecast, wore three sets of clothes, and walked into history as a fact.13 The recovery proved Maersk could rebuild an entire network in ten days. The bill proved something quieter and harder: that the hardest thing to restore after a disaster isn't the servers — it's an honest count of what the disaster actually cost.

Take it with you — Crisis Response
Playbook

Crisis Response Playbook

A playbook for a crisis already in motion: who decides, which plays fire on which trigger, and what gets said to whom. It replaces panic and the all-hands meeting with a pre-agreed sequence each person can run alone. Blank to pre-load before a crisis hits; filled as the worked example reconstructing the plays the story's team ran — and the ones they should have.

Blank template

Included, filled and blank, in the Crisis Response Casebook. See the set → · Preview the blank →

Sources

Where this comes from — the filings, records, and reporting behind it.

  1. 1
    Primary · Company recordDocumented
    In its Q2 2017 interim report (issued 16 August 2017), CEO Søren Skou stated Maersk was hit by a cyber-attack in the last week of the quarter mainly impacting Maersk Line, APM Terminals and Damco, and that 'We expect that the cyber-attack will impact results negatively by USD 200-300m.'
  2. 2
    Primary · Company recordDocumented
    Maersk's Q3 2017 interim report confirms underlying profit improved despite a 'negative impact from the cyber-attack of USD 250-300m in Transport & Logistics,' showing the cost estimate carried forward unchanged from Q2 guidance.
  3. 3
    Primary · Company recordDocumented
    Maersk's 2017 Annual Report risk-management disclosure states the company 'suffered losses in the order of USD 250-300m covering, among other things, loss of revenue, IT restoration costs and extraordinary costs related to operations,' and that cyber insurance was subsequently purchased to mitigate future incidents.
  4. 4
    PublishedWidely reported
    Speaking on a cybersecurity panel at the World Economic Forum in Davos (January 2018), Maersk chairman Jim Hagemann Snabe said the NotPetya attack forced the company to reinstall '4,000 new servers, 45,000 new PCs, and 2,500 applications' over 'a heroic effort over ten days,' a job he said would normally take about six months, during which the company managed an estimated 20% drop in volume handled manually.
  5. 5
    PublishedAttributed to source
    Maersk's own August 2017 statement, reported contemporaneously, said Maersk Line was able to take bookings from existing customers two days after the attack and that operations 'gradually got back to normal over the following week' — an account roughly consistent with the later 'ten days' framing.
  6. 6
    PublishedAttributed to source
    Based on interviews with more than a dozen Maersk IT staff, journalist Andy Greenberg reported that after NotPetya wiped all of Maersk's roughly 150 domain controllers, administrators located the company's only surviving copy on a single machine in a Ghana office that happened to be offline due to a power blackout when the malware hit, and that data was physically relayed via Nigeria to the UK to begin rebuilding the network.
  7. 7
    PublishedAttributed to source
    In his book Sandworm, Greenberg wrote that Snabe's Davos figure of $250-300 million was the total damage estimate, but noted that 'most of the staffers' he spoke with privately suspected the company's accountants had lowballed that figure.
    Doubleday, Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers · 2019
  8. 8
    Primary · Company recordDocumented
    Maersk's own investor-relations statement issued the day after the attack confirms the date and scope: 'We can confirm that Maersk has been hit as part of a global cyber attack named Petya on the 27 June 2017. IT systems are down across multiple sites and select business units.'

More like this — beyond Maersk

New Strategically analyses as they publish: the defining moves in business, checked against the record. No noise, and one click to leave.