Sure. First and most important thing for understanding Real World costs: one engineer is $20k per month in fully loaded costs (salary, benefits, taxes, overhead). One engineer-day costs you $1k. These go up for emergency response because a) on-call b) experts are even more expensive than generic engineers.
Github's first response to this would be pushing a Big Red Button that would get 4+ engineers to devote their Sunday to this. That's $4,000, cash money. The predictable second step after the bleeding stops is to do a line-by-line audit of their entire code base. My guesstimate for Github is that that would cost north of 50 man days ($50k).
But wait, there's more! As a result of this compromise, Github is likely going to hire external security firms to pentest them and make process recommendations. The caliber of firm they would consider employing will cost, bare minimum, five figures. Cost goes up pretty rapidly.
But wait there's more! Github will, as a result of this incident, have a number of people close accounts today (totally measurable) and an unknown number avoid creating accounts in the future. LTV for SaaS customers very quickly becomes motivational numbers. A single company moving its repo from Github to an internal system because Github Let Anyone See Any Repo (+) could easily cost $5k+ in LTV, and that scales horizontally across their entire client base. Scaring your customers' PHBs is never fun. This issue will be held against Github in a thousand internal conversations.
But wait there's more! Highly visible security problems will bring Fortune 500 lawyers out to play. "You just caused a security audit for us. It cost $250,000. Where should we send the invoice? Oh, you think that your Terms of Use says you don't owe us? Cool, let's run that by Legal: they're free this week."
Long story short: getting hacked is Very Bad News.
+ This is the key takeaway from the hack, not "Someone did a one-line defacement of an OSS project."