Because even if you have an excellent disaster recovery system, typically they are 'snapshotting' hourly. However, you could get hit with ransomeware say at 2:10pm. But someone may not open a file that got encrypted for a few hours later. Plus, ransomeware can take hours to do its deed, it's not instant as it has to read all the files, encrypt them and write them back. That's alot of CPU and network traffic.
Then when people can't open one of the files, they may think its just the file, or 'I'll call IT in the morning'.
Long and short, it could be 3+ hours of work being done in the organization before somebody realizes what's really happening. Then calls a tech, they get there etc. Remote people may not have a clue and continue doing their work.
So now your disaster recovery system comes into play, and you do a restore from 2pm which is when your tech figured out was the last good backup. Say you have 50 employees and they worked for 4 hours after the attack.
50*4 is 200 manhours. Say an average loaded cost of $50/hour and wham, you just lost $10,000 bucks