Editorial composite of a chain-secured smartphone and calculator with documents; representative photos Towfiqu barbhuiya and Hanna Pad/Pexels, cropped and combined by MBN.

Cybersecurity budget research puts expected losses ahead of spending targets

Written by Daniel Mercer

Published: 17:30, September 12, 2026

University of Maryland researchers are proposing a way to set cybersecurity budgets around the losses a business could suffer and the protection each investment buys, instead of treating the budget as an isolated technology expense.

The university’s Smith School of Business described the research on 10 September. Its authors, Lawrence A. Gordon, Martin P. Loeb and Lei Zhou, apply an established economic model to the decisions managers face when allocating money to prevent breaches.

The paper was published on 28 August in Transactions on Engineering and Computing Sciences. It is an economic framework, not a trial showing that companies adopting a particular budget subsequently suffered fewer attacks.

Start with the loss, then ask what spending reduces

The model starts with expected loss: the probability of a successful incident multiplied by the loss it would cause. A large possible loss and a highly likely loss are different inputs, and both affect the decision.

Managers then assess how additional security spending might reduce that probability. The aim is to balance the cost of protection against the expected loss left after protection is in place.

The difficult inputs are estimates. A prevented attack leaves no invoice showing what was saved, and a quiet year does not prove that every security purchase was effective. The university’s account also identifies uncertainty over breach likelihood and the productivity of security spending as persistent budgeting problems.

The 37% benchmark has conditions

The Gordon-Loeb model produces a much-discussed result: for two broad classes of assumptions about how investment reduces breach probability, the economically optimal investment does not exceed approximately 37% of expected loss.

That percentage is neither a share of revenue nor a share of the IT budget. It is also an upper bound within the model, not a recommendation to spend exactly that amount.

The calculation assumes diminishing returns: each additional amount spent reduces risk by less than the amount before it. A company cannot turn an uncertain loss estimate into a reliable spending limit simply by multiplying it by 37%.

The authors also discuss costs passed to customers and supply-chain partners. Ignoring those losses can make protection appear less worthwhile than it is for everyone affected.

Responsibility needs to follow the money

The research examines another obstacle: the executive controlling the budget may be different from the person held responsible for security. The authors argue for closer alignment between spending authority, incentives and cybersecurity performance.

For smaller firms, the US National Institute of Standards and Technology offers a business guide to managing cyber risk. It starts with identifying responsibilities, legal and contractual requirements, and the effect of losing important assets or operations.

Those obligations remain part of the decision even when a financial model points to a lower budget. NIST’s framework also covers detecting incidents, responding and recovering, alongside protective measures.

Our recent coverage of the EU’s new cyber reporting requirements explains why businesses need procedures as well as security software. For a budget to cover the work, someone must know which duties apply and who will carry them out.

Daniel Mercer Avatar

Other News

UK trade deficit narrows to £9 billion over three months

Sep 12, 2026

Munters expands Virginia factory to make data center chillers locally

Sep 12, 2026

Digital literacy report calls for skills training beyond network coverage

Sep 12, 2026

Berkeley’s healthy checkout rule linked to lower soda sales, study finds

Sep 12, 2026

France cuts growth forecast to 0.5% and announces fresh budget measures

Sep 12, 2026

Kroger cuts sales outlook as online growth helps support earnings

Sep 12, 2026

Gasoline pushes US monthly inflation higher ahead of Fed meeting

Sep 12, 2026

How AI is changing the pharmaceutical industry

Sep 11, 2026

UK economy grows 0.4% in July as business services lead gains

Sep 11, 2026

Corporate tax cuts helped firms grow, but income gains favored top earners

Sep 11, 2026

Ayar Labs adds $150 million to bring optical links closer to AI chips

Sep 11, 2026

Quantum study points to 1,000-fold speed gain for state preparation

Sep 11, 2026

AI safety warnings put the pace of development under scrutiny

Sep 11, 2026

Antidepressant study finds a sensitive drug target in fish

Sep 10, 2026

ECB raises deposit rate to 2.50% as energy costs lift inflation

Sep 10, 2026

Adobe revenue rises 13% as its AI subscription business expands

Sep 10, 2026

EU cyber-reporting rules start September 11: what manufacturers must report

Sep 10, 2026

Malaysia’s palm oil stocks rise 7.5% as August exports fall

Sep 10, 2026

TSMC’s August revenue jumps 53.3% as chip sales accelerate

Sep 10, 2026

Bank of Japan’s Masu warns inflation could force faster rate hikes

Sep 10, 2026