Editorial composite of a chain-secured smartphone and calculator with documents; representative photos Towfiqu barbhuiya and Hanna Pad/Pexels, cropped and combined by MBN.

Cybersecurity budget research puts expected losses ahead of spending targets

Written by Daniel Mercer

Published: 17:30, September 12, 2026

University of Maryland researchers are proposing a way to set cybersecurity budgets around the losses a business could suffer and the protection each investment buys, instead of treating the budget as an isolated technology expense.

The university’s Smith School of Business described the research on 10 September. Its authors, Lawrence A. Gordon, Martin P. Loeb and Lei Zhou, apply an established economic model to the decisions managers face when allocating money to prevent breaches.

The paper was published on 28 August in Transactions on Engineering and Computing Sciences. It is an economic framework, not a trial showing that companies adopting a particular budget subsequently suffered fewer attacks.

Start with the loss, then ask what spending reduces

The model starts with expected loss: the probability of a successful incident multiplied by the loss it would cause. A large possible loss and a highly likely loss are different inputs, and both affect the decision.

Managers then assess how additional security spending might reduce that probability. The aim is to balance the cost of protection against the expected loss left after protection is in place.

The difficult inputs are estimates. A prevented attack leaves no invoice showing what was saved, and a quiet year does not prove that every security purchase was effective. The university’s account also identifies uncertainty over breach likelihood and the productivity of security spending as persistent budgeting problems.

The 37% benchmark has conditions

The Gordon-Loeb model produces a much-discussed result: for two broad classes of assumptions about how investment reduces breach probability, the economically optimal investment does not exceed approximately 37% of expected loss.

That percentage is neither a share of revenue nor a share of the IT budget. It is also an upper bound within the model, not a recommendation to spend exactly that amount.

The calculation assumes diminishing returns: each additional amount spent reduces risk by less than the amount before it. A company cannot turn an uncertain loss estimate into a reliable spending limit simply by multiplying it by 37%.

The authors also discuss costs passed to customers and supply-chain partners. Ignoring those losses can make protection appear less worthwhile than it is for everyone affected.

Responsibility needs to follow the money

The research examines another obstacle: the executive controlling the budget may be different from the person held responsible for security. The authors argue for closer alignment between spending authority, incentives and cybersecurity performance.

For smaller firms, the US National Institute of Standards and Technology offers a business guide to managing cyber risk. It starts with identifying responsibilities, legal and contractual requirements, and the effect of losing important assets or operations.

Those obligations remain part of the decision even when a financial model points to a lower budget. NIST’s framework also covers detecting incidents, responding and recovering, alongside protective measures.

Our recent coverage of the EU’s new cyber reporting requirements explains why businesses need procedures as well as security software. For a budget to cover the work, someone must know which duties apply and who will carry them out.

Daniel Mercer Avatar

Other News

Iridium shareholders approve Rocket Lab takeover: what still has to happen

Sep 25, 2026

Akamai’s 11.6 billion dollar Anthropic deal ties cloud revenue to a 5.5 billion dollar buildout

Sep 25, 2026

Bentley completes 350 million pound Crewe investment as it unveils its first electric vehicle

Sep 25, 2026

Falling birth rates did not reduce total output in historical data, NBER study finds

Sep 25, 2026

Cheaper renewable power does not solve the capital problem for poorer countries

Sep 25, 2026

Facial payments may feel novel, but money worries can curb repeat use

Sep 24, 2026

Precision farming cuts water use while raising crop yields, study finds

Sep 24, 2026

EU allocates €505m to Lebanon for recovery, reforms and basic services

Sep 23, 2026

Alcoa raises $2.6bn in notes to fund South32 aluminium-assets deal

Sep 23, 2026

UK workplace health plan targets preventable exits from employment

Sep 23, 2026

IMF says Sri Lanka’s recovery is holding, but the next review is still unresolved

Sep 23, 2026

OECD sees global growth holding up after energy shock, but forecasts higher inflation

Sep 23, 2026

QAD and Redzone plan NVIDIA-powered AI for factory data and production planning

Sep 22, 2026

World Cup pitchside sponsorship raised a cross-border advertising problem

Sep 22, 2026

Hollywood’s biggest budgets still favour male-only teams, study finds

Sep 22, 2026

Why more companies are becoming their own insurers

Sep 22, 2026

EU publishes data-centre rating rules and opens consultation on minimum standards

Sep 21, 2026

ABB launches Infinitus DC portfolio for AI data centers, with first full sites expected in two to three years

Sep 21, 2026

Starbucks selects Chennai for a technology hub, with work set to move in-house over time

Sep 21, 2026

CXMT says its G5 memory platform has entered mass production with more dies per wafer

Sep 21, 2026