
Blog Post
The Cyber Outage That Ends Before the Recovery Does
September 29, 2026
An interruption model measures the time from failure to restoration. Systems down, systems back, multiply by revenue per hour.
In an airline the outage ends well before the recovery does, and the ratio between the two is large enough to make a model keyed to restoration wrong rather than imprecise. One carrier restored connectivity in under an hour and the resulting displacement ran into the following morning.
How Far Apart Are the Two Clocks?
Between ten and a hundred times, based on the public record of recent events.
A carrier restored connectivity forty-eight minutes after a failure froze dispatch, weight and balance and crew scheduling across its hubs, and one hub remained under separate restrictions working through the backlog afterward. Another suffered a data center failure in mid-afternoon, lifted its ground stop the same evening, and canceled more than three hundred and sixty flights across that day and into the next.
The Carrier Names the Reason
The second airline said so in its own statement that further disruption was likely as it repositioned aircraft and crews throughout its network. The technical fault was resolved. The aeroplanes and the people were in the wrong places.
What Sets the Second Clock?
Constraints that do not yield to effort, which is why it cannot be shortened the way the first one can.

Crew duty time limits are statutory and cannot be waived for a recovery. Aircraft maintenance windows fall due regardless. Gate availability at a hub is fixed. Overnight curfews at some airports close the window entirely. Recovery is a matching problem, requiring an aircraft and a legally available crew in the same place at the same time, and each additional hour of outage displaces more pairs.
Which Makes It a Physical Constraint Rather Than an Effort One
Adding people to a restoration shortens the first clock. Nothing added shortens a duty limit or opens a curfew, so the second clock runs at the pace the network's own topology permits. The structure resembles a production line that cannot be restored from backup, where recovery is bounded by something other than the restore through a different mechanism.
Why Does the Time of Day Matter?
Because it determines how much of the network is displaced, and this is the input no model carries.
An outage beginning mid-afternoon interrupts evening rotations and the overnight positioning that sets up the next morning, so the recovery runs into the following day by construction. An outage of identical duration beginning at two in the morning displaces very little, since most aircraft are already where they need to be for the first wave.
Duration Alone Underdetermines the Loss
Two eight-hour outages can differ by an order of magnitude in operational consequence depending only on when they started. So the model needs a start time distribution rather than a duration distribution alone, and the start time is not uniform, since an attack or a change window is more likely at some hours than others.
How Large Is the Second-Order Effect?
Comparable to the first, on the available evidence, so a model capturing only the outage window captures roughly half the event.

In one widely reported reservations failure, flight tracking estimated roughly nine hundred delays from the resumption itself and around a further eight hundred that evening, arising because aircraft and crews were out of position. The displacement produced almost as much disruption as the outage did.
Which Argues for Two Terms Rather Than a Multiplier
Applying a factor to the outage duration hides the mechanism and gets the shape wrong, since the two stages have different drivers. Modeling them separately lets each be estimated from whatever governs it, and interruption modeled as its own distribution sets out why duration does not convert linearly.
Does Faster Technical Recovery Help?
Up to a point, and the point arrives sooner than an investment case usually assumes.
The carrier that restored connectivity in forty-eight minutes had contingency planning tools and trained procedures, and the displacement cascade still ran into the next morning. So halving an already short technical recovery had limited effect on the total, because the binding constraint had moved to the second stage.
Which Reorders the Investment Case
Where technical recovery is already measured in minutes, further reduction buys little. Where it is measured in hours, reduction buys a great deal, since it prevents displacement rather than merely shortening it. Knowing which regime you are in requires measuring both clocks, which almost nobody does.
What Shortens the Second Clock?
Decisions made outside the technology function, which is why they rarely appear in a resilience program.
Spare aircraft and reserve crew positioned at hubs absorb displacement rather than propagating it. Pre-computed recovery sequences, worked out before an event, remove decision time from the critical path. Automated crew repositioning handles mass displacement in a scale of minutes rather than hours. All three are commercial and operational investments with a security payoff.
Which Makes the Figure the Argument
A reserve aircraft is expensive and its resilience value is invisible without a figure for what displacement costs. Quantifying the second stage is what lets an operations investment be justified against a security scenario, and cyber risk quantification built as two stages is what produces that number.
Where Else Does the Pattern Appear?
Anywhere the operation depends on physical assets being in specific places, which is more sectors than the aviation framing suggests.
Rail has the same structure, with rolling stock and drivers subject to route knowledge and duty limits. Shipping has it at longer timescales, since a vessel out of position takes days to correct. Field service, logistics and any scheduled workforce operation share it, because the schedule is a matching of people and equipment to locations and times.
What Do They Have in Common?
A schedule that was optimized before the outage and is invalid afterward. Restoring the system that holds the schedule does not restore the schedule, because the world moved while the system was down and the plan it holds describes a state that no longer exists.
Which Identifies the Real Question
How long it takes to compute and execute a new plan rather than how long it takes to restore the old one. It is a capability question about recovery planning rather than about infrastructure, and choosing an indicator that leads rather than lags applies to measuring it before an event rather than after.
What Should Be Established?
Four things, and operations can answer all four.
Historic recovery duration from the last several disruptions, separated into restoration and full schedule recovery. The relationship between outage start time and recovery length, which the same records contain. Which constraint bound the recovery each time, since duty limits, gates and maintenance produce different remedies. Reversing the direction where consequence data is better than loss data is the same method applied elsewhere. Then what a reserve of one additional aircraft and crew would have changed, which is the investment question the figure has to answer.
Model the Repositioning, Not the Restoration
One carrier restored connectivity in forty-eight minutes and the displacement ran to the next morning, while another lifted a ground stop the same evening and canceled flights into the following day, saying in its own words that it was repositioning aircraft and crews. The second clock is set by duty time limits, maintenance windows, gate availability and curfews, none of which yield to effort, so it runs at the pace the network permits rather than the pace a recovery team works. Time of day determines how much is displaced, so two outages of equal duration can differ by an order of magnitude. The second-order effect has been comparable to the first in the public record. Where technical recovery is already short, further reduction buys little because the binding constraint has moved. Kovrr's cyber risk quantification models duration as its own distribution.
To see outage exposure modeled as restoration and schedule recovery separately, book a demo with our risk experts.
Positional Recovery FAQs
Speak to an ExpertWhy do flight cancellations continue after systems are restored?
Because aircraft and crews are in the wrong places. One carrier that suffered a data center failure in mid-afternoon lifted its ground stop the same evening, canceled more than three hundred and sixty flights across that day and into the next, and stated in its own update that further disruption was likely as it repositioned aircraft and crews throughout its network. The technical fault was resolved while the network was still displaced.
What limits airline operational recovery after an IT outage?
Constraints that do not yield to effort. Crew duty time limits are statutory and cannot be waived for a recovery, aircraft maintenance windows fall due regardless, gate availability at a hub is fixed, and overnight curfews at some airports close the window entirely. Recovery is a matching problem requiring an aircraft and a legally available crew in the same place at the same time, and each additional hour of outage displaces more pairs.
Does the time of day affect outage recovery length?
Substantially, and it is the input most models omit. An outage beginning mid-afternoon interrupts evening rotations and the overnight positioning that sets up the next morning, so recovery runs into the following day by construction. An outage of identical duration beginning at two in the morning displaces very little, so two eight-hour outages can differ by an order of magnitude in operational consequence depending only on when they started.
How large is the knock-on effect of an airline IT outage?
Comparable to the outage itself on the available evidence. In one widely reported reservations failure, flight tracking estimated roughly nine hundred delays from the resumption and around a further eight hundred that evening arising because aircraft and crews were out of position. A model capturing only the outage window therefore captures roughly half the event, which argues for two terms rather than applying a multiplier.
Does faster IT recovery reduce the total loss?
Up to a point that arrives sooner than most investment cases assume. The carrier that restored connectivity in forty-eight minutes had contingency planning tools and trained procedures, and the displacement cascade still ran into the next morning, so halving an already short technical recovery had limited effect because the binding constraint had moved to the second stage. Where technical recovery is measured in hours rather than minutes, reduction buys a great deal.
What shortens the operational recovery clock?
Decisions made outside the technology function. Spare aircraft and reserve crew positioned at hubs absorb displacement rather than propagating it, pre-computed recovery sequences remove decision time from the critical path, and automated crew repositioning handles mass displacement in minutes rather than hours. All three are commercial and operational investments whose resilience value is invisible without a figure for what displacement costs.




