# What Website Downtime Really Costs a Small Business in 2026

> The scary per-hour downtime figures are enterprise numbers. Here is how to calculate your real cost, why small business sites go down, and how to prevent it.
>
> Source: https://rankshield.co/resources/cost-of-website-downtime-small-business/ · RankShield (the verifiable, quantum-safe AI security platform)

Resources   /   Edge & Hosting
# What Website Downtime Actually Costs a Small Business (and How to Prevent It)

The scary per-hour downtime figures come from enterprise surveys. Here is how to calculate your real number, why small sites go down, and how to keep yours up.
    August 27, 2026   · 12 min read   · cost of website downtime small business            Jamie Kloncz  Founder & CEO, RankShield        Share
If you search what website downtime costs, you get numbers designed to frighten a Fortune 500 CFO: thousands of dollars a minute, six figures an hour. Those figures are real, but they come from enterprise surveys and describe large companies with call centers, SLAs, and revenue measured in the millions per day. They tell a small business owner almost nothing useful, because your real cost of an outage depends entirely on your own revenue, and it is both smaller than the scary headline and larger than you would guess once you count everything. This guide does three honest things: it shows you how to calculate your actual downtime cost from your own numbers, it explains why small business websites go down in the first place, and it covers how to keep yours up. The context worth knowing before you start is that the web your small site sits on is now more automated than human. Automated traffic made up more than half of all web traffic in 2025, and bad bots alone account for roughly 37 percent of everything on the internet ([Imperva Bad Bot Report 2026](https://www.imperva.com/blog/bad-bot-report-2026-bots-agentic-age/) 1 ). A small, unprotected origin server is exactly what that traffic knocks over. One honest note first: no tool can promise zero downtime, and anyone who does is selling you something. The goal is to make outages rare, short, and cheap, not to claim they will never happen.
       Key takeaways
- The widely quoted per-hour downtime figures (thousands per minute, six figures per hour) come from enterprise surveys and do not describe a small business.
- Your real cost of an outage is your average hourly online revenue times the hours you are down, plus staff time, recovery, and the search-ranking and trust damage that stack on top.
- Automated traffic is now the majority of the web, and bad bots make up about 37 percent of all internet traffic, which is what overwhelms small, unprotected origin servers.
- Most small business outages are not dramatic: they are bot floods, resource exhaustion on shared hosting, plugin exploits, and DDoS traffic hitting an origin with nothing in front of it.
- Monitoring tells you the site is down; edge filtering and static edge hosting are what keep it up, by absorbing the junk before it reaches your origin.

## What does website downtime actually cost a small business?

There is no single honest per-hour figure, because the answer is your revenue, not an industry average. The dramatic numbers you see quoted, thousands of dollars a minute or six figures an hour, come from surveys of large enterprises, and applying them to a small store is like pricing your car insurance off a fleet of delivery trucks. For a small business, the direct cost of an outage is simple to reason about: take your average online revenue per hour and multiply it by the hours you are down. A store doing 40,000 dollars a month online earns roughly 55 dollars an hour on average, so a six-hour outage is a few hundred dollars in lost sales, not a hundred thousand.

That direct number is the floor, not the full cost, because an outage bills you in four ways. There is the lost revenue while the site is down. There is the staff time spent scrambling to diagnose and fix it, often at the worst possible moment. There is the recovery work afterward, restoring backups, patching whatever caused it, and reassuring customers. And there is the hardest bucket to see: the trust and search damage, customers who bounced to a competitor and did not come back, and search engines that crawled your site while it was returning errors. Add those and the fully loaded cost of an outage is commonly several times the direct lost-sales figure.

So the honest framing is not "downtime costs X per hour." It is "here is your direct exposure, and here is what stacks on top." The calculator below gives you the direct number from your own revenue, which is the part you can defend to the dollar, and then names what to add. Use it to replace the scary generic figure with a real one you can actually plan around.
         DOWNTIME COST CALCULATOR
### What would an outage actually cost your store?

- Monthly online revenue ($)
- Hours down in a typical outage
- Outages like this per year
- Direct lost sales for one outage

## How do you calculate your own downtime cost?

Start with the one number you can defend, then add the three you have to estimate. The defensible number is direct lost sales: your monthly online revenue divided by about 730 hours in a month gives your average revenue per hour, and multiplying that by the length of an outage gives the sales you did not make. It is an average, so an outage during your busiest hours costs more and one at 3 a.m. costs less, but it is a real, arguable figure rather than a borrowed enterprise statistic.

Then add the three stacking costs. Staff time is your people, or you, dropping paid work to firefight the outage, valued at what that time is worth. Recovery is the cleanup after the site is back: restoring data, applying the fix, and any developer or host support you pay for. Trust and search is the slowest and often largest bucket, the customers who hit a dead site and bought elsewhere, plus the ranking risk when search engines repeatedly crawl a site returning server errors during an outage. None of these three is precise, but leaving them at zero is the mistake that makes downtime look cheaper than it is.

The reason this math matters is that it changes the prevention decision. If an outage costs you 300 dollars in direct sales but 1,500 dollars fully loaded, and you have three a year, that is 4,500 dollars annually in avoidable cost, which reframes what you should be willing to spend to prevent it. The table below breaks the four buckets down so you can fill in your own figures, and the point is not to land on a perfect total but to see that the true cost lives mostly in the parts the scary headline never mentions.
          THE FOUR COST BUCKETS
### Where the real cost of an outage hides

| Cost bucket | What it is | How to estimate it |
| --- | --- | --- |
| Direct lost sales | Revenue you miss while down | Monthly online revenue ÷ 730 × hours down |
| Staff time | People pulled off work to fix it | Hours spent × loaded hourly cost |
| Recovery | Cleanup, restores, paid support | Backup + patch time + any host/dev fees |
| Trust & search | Lost customers and ranking risk | Hardest to measure, often the largest |

Only the first bucket is precise. The other three are why fully loaded outage cost is commonly several times the direct figure.

## Why do small business websites actually go down?

Rarely for dramatic reasons, and usually because there is nothing between the open internet and your origin server. The Hollywood version of downtime is a targeted hacker, but the common causes for a small site are mundane and traffic-driven: a flood of bots crawling or scraping the site faster than a small server can answer, resource exhaustion on cheap shared hosting where one busy neighbor or one bad plugin exhausts the memory, an exploit against an out-of-date plugin or theme, and distributed denial-of-service traffic that simply overwhelms the origin with volume. All four share a root cause, which is that the requests reach your server at all.

The scale of the automated traffic is the part owners underestimate. Bad bots make up roughly 37 percent of all internet traffic, and total automated traffic passed human traffic in 2025 ([Imperva Bad Bot Report 2026](https://www.imperva.com/blog/bad-bot-report-2026-bots-agentic-age/) 1 ). On the network level, Cloudflare reported that 3.3 percent of all the traffic it saw was mitigated as a DDoS attack or by managed security rules, and that hyper-volumetric attacks kept growing through the year ([Cloudflare Radar 2025 Year in Review](https://blog.cloudflare.com/radar-2025-year-in-review/) 2 ). Those attacks are not all aimed at banks; automated tooling sprays across the web, and a small origin with no filtering is an easy target precisely because it falls over with so little effort.

This is why the fix is structural rather than a matter of buying a bigger server. If the reason your site goes down is that junk traffic reaches an origin that cannot absorb it, then upgrading the origin just raises the threshold slightly; the next flood still finds it. The durable fix is to stop the junk before it reaches the origin at all, which is a hosting and edge question, not a plugin question. The diagram below shows the difference between an origin taking the full hit and one sitting behind a filtering edge.
         DOWNLOADABLE INFOGRAPHIC
### Why one site stays up and the other falls over
      Junk traffic hitting a bare origin is what takes small sites down. A filtering edge absorbs it first. Free to share with attribution.
## How do you prevent downtime, and is monitoring enough?

Monitoring is necessary but it is not prevention: it tells you the site is down, it does not keep it up. An uptime monitor pinging your site every minute is worth having, because knowing fast matters, but by the time it alerts you the outage has already started billing you in every bucket above. Prevention is a different job. It means making sure the traffic that causes outages either never reaches your origin or has nothing to overwhelm, and that is a hosting and edge decision.

There are two structural levers. The first is putting a filtering edge in front of your origin so that bot floods, scrapers, and DDoS volume are absorbed and dropped at the network edge, and only legitimate requests reach your server. The second, and the strongest for a small business, is static edge hosting, where your site is served as fast static files from the edge with no traditional origin server to exhaust in the first place. You cannot crash a database that is not in the request path, and you cannot exhaust the memory of a server that is not being hit. This is the difference between hardening a fragile origin and removing the fragility.

For most small businesses this is also the cheaper path once you count the true cost of outages. Managed WordPress hosting built to survive traffic spikes typically runs 30 to 150 dollars a month and still leaves you with an origin to defend, while [RankShield edge hosting](https://rankshield.co/edge/) serves your site from the edge with filtering in front for 39 dollars a month. Set that against a fully loaded outage cost of a few thousand dollars a year and the prevention pays for itself the first time it keeps you up through a flood that would have taken a bare origin down. As we covered in the comparison of [static edge hosting versus WordPress](https://rankshield.co/resources/static-edge-hosting-vs-wordpress/), the uptime difference is structural, not a matter of buying a bigger box. Keep the monitor so you know; move to the edge so there is less to know about.
         EXPOSURE CHECK
### How exposed is your site to a downtime event?

- What is your site running on?
- Is there any filtering in front of your origin?
- How current are your plugins, themes, and software?
- Have you had an outage in the last year?
- Would you know within minutes if the site went down?

## What does downtime really cost you, and what should you do about it?

Not the scary headline, and not zero. The per-hour figures that dominate search come from enterprise surveys and describe companies nothing like a small business, so the first honest step is to replace them with your own number: your average hourly online revenue times the hours you are down, plus the staff time, recovery, and trust-and-search damage that stack on top and usually add up to several times the direct figure. That real number, not a borrowed statistic, is what tells you how much your uptime is worth. For most small stores it lands at a few thousand dollars a year of avoidable cost, spread across a handful of outages that felt minor at the time.

The causes are mundane and the fix is structural. Small sites go down because bot floods, DDoS traffic, resource exhaustion, and plugin exploits reach an origin with nothing in front of it, on a web that is now more automated than human. Monitoring will tell you it happened; it will not prevent it. Prevention means keeping that traffic off your origin, or removing the origin from the request path entirely with static edge hosting, which is both the most reliable and, once you count the true cost of outages, usually the cheapest option a small business has. To see how RankShield keeps small sites up by serving them from the edge with filtering in front for 39 dollars a month, see [RankShield edge hosting](https://rankshield.co/edge/).
         FREQUENTLY ASKED
## Questions, answered.
            Jamie Kloncz  CEO, RankShield · online
How much does website downtime cost a small business per hour?

There is no single credible per-hour figure for a small business, and any source that gives you one without asking about your revenue is quoting an enterprise average. The honest way to calculate it is from your own numbers: divide your monthly online revenue by about 730 hours to get your average revenue per hour, then multiply by the length of an outage. A store doing 40,000 dollars a month online earns roughly 55 dollars an hour on average, so a six-hour outage costs a few hundred dollars in direct lost sales, not the six-figure numbers you see quoted for large enterprises. That direct figure is only the floor, though. A full accounting adds the staff time spent fixing the outage, the recovery work afterward, and the hardest bucket to measure, the customers who left for a competitor and the search-ranking risk from a site returning errors while search engines crawl it. Fully loaded, the cost of an outage is commonly several times the direct lost-sales figure, which is why the honest answer is a calculation on your own revenue rather than a scary industry statistic.

Why do small business websites go down?

Usually for mundane, traffic-driven reasons rather than targeted attacks, and almost always because there is nothing filtering the traffic before it reaches the origin server. The common causes are bot floods, where automated crawlers and scrapers hit the site faster than a small server can respond; resource exhaustion on cheap shared hosting, where one busy neighbor or one badly behaved plugin uses up the available memory; exploits against out-of-date plugins, themes, or software; and distributed denial-of-service traffic that overwhelms the origin with sheer volume. What these share is that the requests reach your server at all. The scale of automated traffic is the part owners underestimate: automated traffic passed human traffic in 2025, and bad bots alone make up roughly 37 percent of all internet traffic, per Imperva. A small origin with no filtering in front of it falls over with very little effort, which is exactly why it becomes a target. The fix is structural, keeping the junk off the origin, rather than simply buying a bigger server, which just raises the threshold slightly before the next flood finds it.

Is an uptime monitoring service enough to prevent downtime?

No. Monitoring is worth having, but it is a smoke detector, not a sprinkler: it tells you the site is down, it does not keep it up. An uptime monitor that pings your site every minute means you find out quickly, and finding out quickly genuinely matters, but by the time it alerts you the outage has already started, and it is already costing you in lost sales, staff time, and customer trust. Prevention is a separate job from detection. It means making sure the traffic that causes outages either never reaches your origin, by putting a filtering edge in front of it, or has nothing to overwhelm, by serving your site as static files from the edge with no traditional origin server in the request path. The right setup is both: keep the monitor so you always know the true state of your site, and fix the structure so there is far less to be alerted about. Relying on monitoring alone leaves you very well informed about outages you did nothing to prevent.

How does edge hosting prevent website downtime?

Edge hosting prevents downtime by changing where your site is served and what traffic can reach it. There are two mechanisms. The first is filtering: a network edge in front of your site absorbs and drops bot floods, scrapers, and DDoS volume before they reach your origin, so only legitimate requests get through and your server is never asked to answer the junk that would overwhelm it. The second, and the stronger one for a small business, is static edge hosting, where your site is delivered as fast static files from servers distributed around the world with no traditional origin server behind them. You cannot exhaust the memory of a server that is not being hit, and you cannot crash a database that is not in the request path, so the failure modes that take small sites down simply do not exist. This is different from buying a bigger or more managed origin, which only raises the threshold at which the same fragile setup falls over. Edge hosting removes the fragility rather than hardening it, which is why it is the most reliable option available to a small site, and often the cheapest once you count the true cost of outages.

Is edge hosting cheaper than dealing with downtime?

For most small businesses, yes, once you count the full cost of outages rather than only the direct lost sales. Work out your real number first: a fully loaded outage, including staff time, recovery, and lost customers and ranking, commonly runs several times the direct lost-sales figure, and a few of those a year adds up to a few thousand dollars of avoidable annual cost for a typical small store. Set that against the prevention cost. Managed WordPress hosting built to survive traffic spikes usually runs 30 to 150 dollars a month and still leaves you with an origin server to defend and patch. Static edge hosting with filtering in front, such as RankShield edge hosting at 39 dollars a month, removes the exposed origin entirely. When the prevention costs a few hundred dollars a year and the outages it prevents cost a few thousand, the math favors prevention the first time it keeps you online through a flood that would have taken a bare origin down. The point is not that outages become impossible, since no honest provider promises that, but that they become rare, short, and cheap instead of routine and expensive.

Does website downtime hurt my Google rankings?

It can, though a single short outage usually will not. Search engines crawl your site continuously, and if their crawler repeatedly hits server errors during an outage, the effect depends on how long and how often it happens. A brief, occasional outage is generally tolerated: crawlers back off, return later, and your rankings are unaffected. Repeated or prolonged downtime is the real risk, because a site that is frequently unreachable signals unreliability, wastes the crawl budget search engines allocate to it, and in the worst case can see pages temporarily drop from the index if they cannot be fetched over an extended period. Beyond the direct ranking mechanics, there is the user-behavior signal: visitors who arrive from search to a dead site bounce straight back, and a pattern of that does your visibility no favors. This is part of why the trust-and-search bucket is often the largest hidden cost of downtime, and why prevention is worth more than the direct lost-sales figure alone suggests. Keeping the site up reliably protects both the customers you have and the search visibility that brings you new ones.

## References

- [Imperva (Thales). Bad Bot Report 2026: Bots in the Agentic Age (automated traffic exceeded 53% of web traffic in 2025; bad bots ~37% of all internet traffic).](https://www.imperva.com/blog/bad-bot-report-2026-bots-agentic-age/)
- [Cloudflare. Radar 2025 Year in Review (3.3% of traffic mitigated as a DDoS attack or by managed rules; hyper-volumetric DDoS attack sizes grew through 2025; dated December 2, 2025).](https://blog.cloudflare.com/radar-2025-year-in-review/)

              WRITTEN BY
## [Jamie Kloncz](https://rankshield.co/author/jamie-kloncz/)

Founder & CEO, RankShield

Jamie Kloncz is the founder and CEO of RankShield, the verifiable AI and quantum security platform. He started the company after two attacks landed in a single week: his phone was cloned, and his business was hit by a click-fraud campaign. One targeted him as a person, the other his livelihood, and no single tool defended both. That experience, together with surviving an AI voice-clone scam, shaped RankShield’s core belief: the threats of the AI age are personal first, and trust should be something you can check, not just extend.
    More from Jamie →
## Make every AI action provable.

RankShield is the verifiable, quantum-safe AI security platform — protection you can check, not just trust.
   Explore the platform  →   Get started
## More from Resources
      Security   Static Edge Hosting vs WordPress: Faster, Safer, and Less to Maintain?   Static edge hosting serves your site from the network with no PHP or plugins. Here is how it compares with WordPress on speed, security, and upkeep, and when each one wins.      Security   Can a Security Plugin Stop a DDoS or Bot Flood?   A security plugin runs on your server, so a flood reaches it before the plugin can act. Here is why that fails, and what filtering traffic before your origin actually changes.      WordPress Security   Why We Moved a Repeatedly Hacked WordPress Site to Edge Hosting   A site was cleaned and reinfected for years. Instead of another security plugin, we rebuilt it as a static site on edge hosting, and the surface attackers kept exploiting was simply gone.
