top of page

How Much Cybersecurity Is Enough?

  • Neil Hare-Brown
  • Jul 16
  • 3 min read

Twenty years ago, I had the privilege of working with the eminent Jack Jones during the early development of the FAIR cyber risk quantification methodology.


At the time, I was working on risk modelling and the inspirational Chris Carlson, then Head of Cyber Risk at Boeing, who knew of my work, graciously put me in touch with Jack. I flew to Columbus, Ohio


One day, Jack told me the story that ultimately led him to develop FAIR.


He had been dis

cussing the need to purchase a new cybersecurity solution when his manager asked a deceptively simple question.

"If we don't fund this purchase, how much risk will we have?".


Like many CISOs then, as now, Jack answered as honestly as he could, "A lot."


Of course, he could have added flowery tones to this statement to the effect it is critical, red, or any other subjective, perhaps even emotive description.


His manager paused for a moment before asking a second question.

"So, if we do fund this solution, how much less risk will we have?"


Again, Jack answered as honestly as he could. "A bit less."


That exchange exposed a problem that still exists today. Cybersecurity professionals are frequently asked to justify investment decisions, yet many of the answers remain subjective.


We've become very good at describing threats. Very good at describing vulnerabilities. Very good at describing controls.


Sometimes cyber folks (I use the term 'professionals' sparingly at this point), use the complexity fashioned by our industry almost as a badge of honor which - if they can just angle it right, can be used to focus the glare of cyberattack concern directly into the eyes of financial decision-makers. Hell, vendors even help them by buffing that badge good. Yes. That's how budgets are obtained! Ring any bells?


However, the stone cold reality is that Boards aren't making decisions about threats, vulnerabilities or controls. They're making investment decisions.


Every year, organisations collectively invest hundreds of billions in cybersecurity. Yet one deceptively simple question continues to challenge Boards, CEOs, CFOs and CISOs alike.


How much cybersecurity is enough?


It sounds like a technical question. It isn't. It's an investment question.


Every cent invested in cybersecurity is a cent that cannot be invested elsewhere. Every decision therefore requires a judgement about value. Not just security. Value.


That is where many organisations struggle. Some benchmark against peers. Some increase last year's budget. Some respond to regulatory pressure. Some estimate according to recent incidents or perhaps even what their vendors or insurers tell them. Some simply approve whatever the security team requests.


None of those approaches necessarily answers the underlying question. How much financial risk does the organisation actually face? How much of that risk should be reduced? How much should be transferred? How much can reasonably be accepted? Should we even avoid certain risks altogether?

These are Board-level decisions.


Yet many organisations still rely on subjective judgement rather than objective evidence to support them.


Over the coming weeks I'd like to explore that challenge.


Not because existing frameworks are wrong - they have advanced our profession enormously - but because I believe there is still an opportunity to improve how organisations make cyber investment decisions.


We'll explore questions such as:

  • Why do cyber budgets remain so difficult to justify?

  • Why does more information often lead to poorer decisions?

  • What should organisations really be measuring?

  • How should cyber insurance fit into the discussion?

  • And ultimately...How much cybersecurity is enough?


Thought for the week

"Every cybersecurity budget is an investment decision. The question is not whether to invest, but how much to invest and how to justify the amount."

 
 

Speak with a cybersecurity specialist

Contact the team at STORM Guidance:

UK/Europe: +44-203-693-7480

Africa: +230-434-1277

India: 0008001004277

USA: +1-703-232-9015

Your contact details will only be used in connection with this enquiry.

Please read our Privacy Policy.

I'm enquiring as
bottom of page