# What are the Costs of Unpreparedness > By Johnathan Belcher — March 4, 2026 — 6 min read Organizations that are unprepared for cyberattacks often suffer the hardest from the consequences, and the effects can be felt by more than just the targeted business. One notable example is the Colonial Pipeline attack in 2021 that shut down the largest oil pipeline in the United States. The attack occurred in May 2021 when a group of hackers known as "DarkSide" obtained access to Colonial Pipeline's network via a compromised VPN password. It took only 120 minutes for the hackers to steal 100GB of data before hitting the company's computers with ransomware. Colonial Pipeline, unprepared for the attack, had to shut down its entire pipeline, cutting off an important fuel line for millions of Americans. The organization brought in an outside security firm to investigate, and still paid a 75 BTC ransom (worth around $4.4 million at the time). ## Lessons - Depending on ransom payments for recovery is risky. The CEO said they paid because they lacked clear recovery timelines, highlighting the importance of having an Incident Response Plan in place before an attack occurs. - The compromised VPN password had no multi-factor authentication in place — simple security hygiene like MFA could have prevented the breach, underscoring the importance of securing all potential threat vectors. - Experts believe DarkSide was not a state-sponsored group and later claimed no intent to cause social disruption, raising the question of whether financially motivated attacks are more dangerous than state-sponsored ones because of their unpredictability. ## Reference INSURICA. (2024). [Cyber case study: Colonial Pipeline ransomware attack](https://insurica.com/blog/colonial-pipeline-ransomware-attack/).