Can cybersecurity offer value for money?

Internet cybersecurity

(Markus Spiske, Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Paul Stokes, Co-founder, Managed Security Forum, Prevalent AI


Cybersecurity looks like a waste of money. Companies set new global records with $37 billion invested in security in 2018, with spending expected to surpass $42 billion by 2020. Gartner research found that security spending per employee doubled between 2012 and 2018. And yet the bad guys are still gaining the upper hand. Cybercrime cost the world economy $600 billion in 2017, up from $500 billion in 2014. People are starting to question whether increasing budgets actually reduce cyber incidents.

Nor is the problem is a lack of awareness. UK government research found that the perceived importance of cyber-risk among FTSE350 companies has almost tripled in five years, proving that the most powerful decision-makers in UK business are concerned about security. The UK is no outlier, either, as the 2019 WEF Global Risk Report has cyberattacks occupying the fourth and fifth spots for international risks most likely to increase.

When we rule out investment and intent as the reasons behind our collective failure at security, we are left with implementation. Is there something wrong with the way that well-meaning professionals invest growing security budgets that prevents us from improving our cyber-resilience?

The first thing to consider is how cyberdefences are formed. A company’s security apparatus typically grows iteratively, with employees, tools and procedures added in response to changing budgets, threats and regulations. It is easier in the short-term to deal with emergent threats reactively rather than revisit the entire security strategy. Over time, this has led to an excessive number of tools, many of them point solutions, and this progresses into security teams that are overwhelmed by alerts, lacking a cohesive strategy and in a constant state of firefighting.

Addressing this vicious circle requires an adaptive framework that is agreed by a company’s senior management and implemented across the organisation. The most effective approach is a structured cyber-risk management framework, where security threats are expressed in terms of financial risk to a business and the cost of mitigation. When used correctly, it leads to security spending being informed by risk specialists in the C-suite such as the CFO, CRO and even CEO. The next progression to make spending more efficient is to track the return on investment in cyberdefences, to allow companies to better prioritize investment and provide more accurate reporting on their security posture.

From risk management to ROI

Cyber-risk management stems from a philosophy of oversight that demands metrics to inform decisions as well as to assess them in retrospect. Security has historically struggled with this concept, as chief information security officers (CISOs) who have not suffered major incidents are unable to make the case for greater investment, and those who weathered breaches and attacks are forced to pay “security penance” and overspend in the aftermath. Measuring return on investment resolves both situations.

The first step to measuring ROI is to quantify security risks. One approach to this is to use a Value at Risk (VaR) approach, such as the FAIR framework. The results of the quantification can then be represented in a loss exceedance curve. These plot the likelihood of sustaining a loss in a given year against the financial cost that would be sustained. In other words, the loss exceeded by an event compared with the chances of that event taking place.

The second step is to compare the forecast losses against a company’s agreed risk appetite, enabling the organisation to decide where to invest in mitigations to reduce the risk to an acceptable level. Finally, once these mitigations have been implemented, the same risks are then quantified again using the VaR approach, comparing before and after, in order to assess the return on investing in the mitigations. This is best illustrated using a loss exceedance curve:

The above example can be used to determine ROI on an investment in security. This is done by plotting the inherent risk before the investment took place, using a VaR model to quantify it, and then comparing it with the agreed risk tolerance. If the risk is above the tolerance, then after any mitigations are in place, the risk is calculated again. The before and after curves are then compared to determine ROI.

Only a quantitative approach such as this can ensure budgets are spent in the most effective way, with the highest impact investments. It prevents reactive spending by building oversight into the investment process, and taps into senior expertise by presenting security in the language of business and risk. This approach can then be used to continuously monitor security projects as they progress, both through implementation and then over time once they are live.

ROI requires continuous quantitative data

Most organizations rely heavily on static tests such as vulnerability scans and penetration tests to determine cyber-risk. These are useful exercises, but are not enough in themselves.

Qualitative assessments based on subjective factors, another common approach, often do more harm than good when measuring ROI. Some CISOs protest that quantitative data is not always available, and soft scoring can provide a “feel” for security posture, but these methods rarely alleviate a lack of data in a highly complex field, while they can often obscure it.

Dynamic, quantitative data is required to provide boards and executives with the information needed to make informed decisions about security investment. This quantitative data needs to be up to date. As ESG’s Jon Oltsik explains in Oltsik’s Law, you cannot measure a dynamic environment with static data. Risk scoring, and resulting Return on Investment analysis, need to be based on continuously updated data.

Risk in real terms

UK government research shows that just one in three FTSE350 companies has even agreed security risk appetite and communicated it to staff. And that is based on self-reporting; the real number is likely to be lower. There is still a lot more waste than measurement in security. Yet it is clear that change is under way, with Gartner naming risk appetite statements as one of its top seven security and risk management trends for 2019.

Cyber-resilience is a moving target, and sometimes it can be hard to tell if a company is even moving in the right direction. Determining ROI allows for tangible, clearly defined measurement of progress that is understood throughout the organisation. For some companies this means demanding continuous risk reporting on security initiatives with full board oversight, while others might start by progressing from qualitative heat maps to quantifiable risk metrics.

The ultimate goal of cyber ROI is to maximize investment and reduce risk. This includes tapping into the expertise of the board and building towards a shared language of risk and ROI, which can only be done when risk and ROI are accurately and continuously measured. When done correctly, the value of security investment is plain to see.


Trending now:


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

UN Photo/Manuel Elías Ramiz Alakbarov (on screen), Deputy Special Coordinator for the Middle East Peace Process, briefs the Security Council meeting on the situation in the Middle East.

Potential turning point for Gaza as peace plan enters second phase: UN envoy

This article is published in association with United Nations. The start of a second phase of a stabilisation plan for Gaza offers a potential turning point for the war-ravaged enclave, a senior UN official told the Security Council on Wednesday. Ramiz Alakbarov warned that risks of violence escalating again remain high, while the situation in the […]

This article is published in association with United Nations.

Gaza ceasefire improves aid access, but children still face deadly conditions

The fragile ceasefire in the Gaza Strip is making a difference to the lives of over a million children, and improving overall access to food – but more aid still needs to enter.  That’s the assessment of two senior officials from the UN Children’s Fund (UNICEF) and the World Food Programme (WFP), speaking on Monday to journalists in New York following a […]

A new blow for UNRWA as headquarters in East Jerusalem ‘set on fire’

© UNRWA Destruction at UNRWA headquarters in East Jerusalem after Israeli authorities sent in bulldozers on 20 January. This article is published in association with United Nations. The head of embattled UN relief agency for Palestinians, UNRWA, has condemned reports that its headquarters in East Jerusalem have been set alight deliberately. It comes after Israeli authorities […]

© UNHCR/Yevheniia Kozun This cinema in Saltivka, Kharkiv, was hit during an earlier strike (file Jan 2026).

‘Cycle of attacks must end’: Lead UN official in Ukraine

This article is published in association with United Nations. The senior UN official in Ukraine, Matthias Schmale, has issued a condemnation of the massive overnight Russian drone and missile strike on several major Ukrainian cities, killing and injuring civilians, and knocking out energy infrastructure amid sub-zero temperatures. The attacks on some of Ukraine’s most important population […]

WHO/P. Virot The flag of the UN World Health Organization (WHO) flies at its headquarters in Geneva, Switzerland.

US withdrawal from WHO ‘risks global safety’, agency says in detailed rebuttal

This article is published in association with United Nations. The World Health Organization (WHO) has issued a detailed statement regretting the United States decision to leave the UN agency, and declaring that it will leave both the US and the world less safe as a result. The statement, released on Saturday, also includes a rebuttal of […]

© UNOCHA/Ximena Borrazas Kateryna and her two children warm up at a heating point and use rhe available electricity to charge their devices.

Keeping people warm amid hostilities and harsh winter weather in Ukraine

This article is published in association with United Nations. As people in war-torn Ukraine face the coldest winter in more than a decade, authorities and humanitarians are working to help them stay warm, particularly the most vulnerable residents.  Russian forces continue to attack Ukraine’s energy grid, leaving families without electricity and heating as temperatures plummet to -20° Celsius.  Since 2022, the Government has established so-called “Invincibility Points” – located in tents or public […]

UN News A UN emergency shelter set up amid the ruins of Gaza.

Gaza: War crimes probe pledges to continue work for justice and accountability

This article is published in association with United Nations. As President Trump launched the international Board of Peace plan for Gaza on Thursday, top independent rights experts tasked by the UN Human Rights Council with investigating grave abuses linked to the Hamas-Israel war pledged to continue their work seeking justice and accountability for all. “The Board […]

© WFP/Maxime Le Lijour Children wait for a hot meal at a kitchen in Khan Younis, Gaza, supported by the World Food Programme.

Cold kills another infant in Gaza as West Bank displacement intensifies

This article is published in association with United Nations. Another child in the Gaza Strip has died from hypothermia as winter weather continues to whip the enclave, the UN said on Wednesday, citing information from the health authorities.  The baby girl – just three months old – was found frozen to death on Tuesday morning at her home in […]

Critical medicines: EU measures to boost competitiveness and tackle shortages 

Critical medicines: EU measures to boost competitiveness and tackle shortages 

This article is brought to you in association with the European Parliament. On Tuesday, Parliament adopted proposals to enhance the availability and supply of essential medicines in the EU. The report, adopted with 503 votes in favour, 57 against and 108 abstentions, aims to ensure a high level of public health protection for EU citizens by […]

Europe Was Warned: Why the Next Pandemic Could Be  Worse 

This article was exclusively written for The European Sting by one of our passionate readers, Dr Taimoor Ahmed Shumail , MD | Dr Ahmed Bilal , MD , Vice  President Global Health and Diplomacy Wing – Pakistan International Medical Students  Association. The opinions expressed within reflect only the writer’s views and not necessarily The European Sting’s position […]

UN News Many Palestinian families are living in poorly equipped shelters that are highly vulnerable to flooding, leaving people inevitably exposed to harsh, stormy weather..

Gaza humanitarian crisis ‘far from being over,’ UN aid coordination office warns

This article is published in association with United Nations. Three months into the ceasefire in the Gaza Strip, the UN and partners have delivered tonnes of assistance items and carried out critical repairs, but this is only a temporary “Band-Aid” solution, a veteran aid worker has warned. “The humanitarian situation and crisis in Gaza is far […]

This article is published in association with European Investment Bank.

Will AI kickstart a new age of nuclear power?

This article is published in association with United Nations. The rapidly expanding use of artificial intelligence worldwide is putting electrical grids under huge pressure and many believe that, to meet that need without contributing to the climate crisis, a full-scale expansion of nuclear energy is essential. The global demand for electricity is growing at a vertiginous […]

UN Photo/Loey Felipe Martha Ama Akyaa Pobee, Assistant Secretary-General for Political Affairs briefs the Security Council meeting on the situation in Iran.

Iran: UN urges ‘maximum restraint’ to avert more death, wider escalation

This article is published in association with United Nations. As nationwide protests in Iran appear to ease after nearly three weeks of unrest and bloodshed, a senior UN official called on Thursday for action to prevent further escalation.  Assistant Secretary-General Martha Pobee briefed an emergency meeting of the Security Council in New York called by the […]

UNRWA UNRWA Headquarters in East Jerusalem

East Jerusalem: Forced shutdown of UN clinic signals escalating disregard for international law

This article is published in association with United Nations. The temporary closure of a UN-run health centre in East Jerusalem is the latest phase in “a pattern of deliberate disregard” for international law, the head of the UN agency that assists Palestine refugees, UNRWA, said on Wednesday.  Israeli forces stormed the UNRWA-operated health centre on Monday and ordered it […]

Unsplash

Iran: ‘The killing of peaceful demonstrators must stop,’ UN rights chief says

This article is published in association with United Nations.  As anti-government demonstrations continue across Iran, the UN human rights chief said on Tuesday that he was horrified at the mounting violence directed by security forces against protestors, with reports of hundreds killed and thousands arrested.  Volker Türk urged the authorities to immediately halt all forms of violence and repression against peaceful […]

© UNHCR/Yevheniia Kozun The bombing of residential buildings in Saltivka, Kharkiv, has left many Ukrainians without power.

Ukraine: Deadly Russian strikes push civilians deeper into winter crisis

This article is published in association with United Nations. Ukraine has entered the new year under intensifying and deadly Russian attacks which have crippled energy systems and left millions without heating, electricity or water amid freezing temperatures, senior UN officials told the Security Council on Monday. Under-Secretary-General for Political Affairs Rosemary DiCarlo told ambassadors the start […]

UN Photo/Eskinder Debebe UN Secretary-General António Guterres. (file photo)

UN chief ‘shocked’ by reports of excessive force against protesters in Iran

This article is published in association with United Nations. The UN Secretary-General is shocked by reports of violence and excessive use of force by Iranian authorities against protesters across the country, urging restraint and the immediate restoration of communications as unrest enters its third week. “All Iranians must be able to express their grievances peacefully and […]

Ukraine: New strikes disrupt basic services for millions

Ukraine: New strikes disrupt basic services for millions

This article is published in association with United Nations. Several parts of Ukraine were hit by a new wave of Russian strikes between Wednesday and Thursday morning. The attacks over the last 24 hours left civilians reportedly killed and injured in the port city of Odesa, interrupting power and water supplies there, as well as in […]

©WFP/Sayed Asif Mahmud Oleg Kemin from the UN World Food Programme (WFP) stands in front of his vehicle in Kherson, Ukraine.

Drones, fear and exhaustion: The daily reality of providing aid to Ukraine

This article is published in association with United Nations. Almost four years since Russia’s full-scale invasion of Ukraine, aid teams continue to adapt to the lethal reality of working in a modern war zone.  For frontline workers like Oleg Kemin from the UN World Food Programme (WFP), this involves travelling deep into disputed territory along the […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading