University of Maryland researchers are proposing a way to set cybersecurity budgets around the losses a business could suffer and the protection each investment buys, instead of treating the budget as an isolated technology expense.
The university’s Smith School of Business described the research on 10 September. Its authors, Lawrence A. Gordon, Martin P. Loeb and Lei Zhou, apply an established economic model to the decisions managers face when allocating money to prevent breaches.
The paper was published on 28 August in Transactions on Engineering and Computing Sciences. It is an economic framework, not a trial showing that companies adopting a particular budget subsequently suffered fewer attacks.
Start with the loss, then ask what spending reduces
The model starts with expected loss: the probability of a successful incident multiplied by the loss it would cause. A large possible loss and a highly likely loss are different inputs, and both affect the decision.
Managers then assess how additional security spending might reduce that probability. The aim is to balance the cost of protection against the expected loss left after protection is in place.
The difficult inputs are estimates. A prevented attack leaves no invoice showing what was saved, and a quiet year does not prove that every security purchase was effective. The university’s account also identifies uncertainty over breach likelihood and the productivity of security spending as persistent budgeting problems.
The 37% benchmark has conditions
The Gordon-Loeb model produces a much-discussed result: for two broad classes of assumptions about how investment reduces breach probability, the economically optimal investment does not exceed approximately 37% of expected loss.
That percentage is neither a share of revenue nor a share of the IT budget. It is also an upper bound within the model, not a recommendation to spend exactly that amount.
The calculation assumes diminishing returns: each additional amount spent reduces risk by less than the amount before it. A company cannot turn an uncertain loss estimate into a reliable spending limit simply by multiplying it by 37%.
The authors also discuss costs passed to customers and supply-chain partners. Ignoring those losses can make protection appear less worthwhile than it is for everyone affected.
Responsibility needs to follow the money
The research examines another obstacle: the executive controlling the budget may be different from the person held responsible for security. The authors argue for closer alignment between spending authority, incentives and cybersecurity performance.
For smaller firms, the US National Institute of Standards and Technology offers a business guide to managing cyber risk. It starts with identifying responsibilities, legal and contractual requirements, and the effect of losing important assets or operations.
Those obligations remain part of the decision even when a financial model points to a lower budget. NIST’s framework also covers detecting incidents, responding and recovering, alongside protective measures.
Our recent coverage of the EU’s new cyber reporting requirements explains why businesses need procedures as well as security software. For a budget to cover the work, someone must know which duties apply and who will carry them out.