Fighting for a departmental budget is never easy — and when your team is responsible for the company's cybersecurity, it feels all the more vital.
It can be hard for management to see the ROI when they budget for cybersecurity. It's much clearer to see the benefit of investments that have a direct impact on customer purchases, production, or inventory. Investments that focus on reducing costs and risks to the company, like cybersecurity, sometimes require more convincing.If you're the appointed person negotiating for your cybersecurity budget, you need to properly frame your argument. To do this, you must have the following:
In this article, we'll walk you through the steps to achieve both, so you can properly fight for your company's cybersecurity budget.
The Gordon-Loeb Model is straightforward to use, consisting of the following four steps:
From here, you can build your budget from the ground up. In a perfect world, you'd have sufficient budget to protect all of your company's information sets equally, but in reality, it's likely you'll have to pick and choose between them. Using this system as a guide, you can logically select the information sets to protect in the immediate term. If you have a ballpark estimate on the budget you'll need to work within, you can distribute the budget across your most valued (or most at-risk) information sets.The Gordon-Loeb Model has found that cybersecurity budgets shouldn't exceed 37% of total expected losses. This is because the security offered by a cybersecurity budget yields diminishing returns with increased spending.
It can be hard for management to see the ROI when they budget for cybersecurity. It's much clearer to see the benefit of investments that have a direct impact on customer purchases, production, or inventory. Investments that focus on reducing costs and risks to the company, like cybersecurity, sometimes require more convincing.If you're the appointed person negotiating for your cybersecurity budget, you need to properly frame your argument. To do this, you must have the following:
- A quantifiable budget.
- A case for why you need this budget.
Identifying How Much You Need
Quantifying your budget comes down to measuring one concept: risk. Cybersecurity expert Ilia Kolochenko recommends starting with a comprehensive risk assessment. Measuring your company's risk consists of two components: the probability of an event happening (e.g. a security breach), and the costs associated with that event happening.Use the Gordon-Loeb Model to Quantify Your Budget
Developed by researchers at the University of Maryland, the Gordon-Loeb Model contextualizes risk assessment specifically for cybersecurity. The model takes into account:- The potential loss from a cybersecurity breach.
- The probability of a breach.
- The way cybersecurity investments reduce this probability.
- Estimate the value of the information you're trying to protect (e.g. your company's sensitive data).
- Estimate the probability that each information set will be breached. Assign each information set a vulnerability score, based on its probability of being attacked.
- Prioritize the information sets by developing a grid, ranging from low value/low vulnerability to high value/high vulnerability. For each box inside the grid, calculate the potential loss by multiplying the information's value by its probability of a breach.
- With a completed grid laying out the potential loss values for each information set, you can identify which ones are most crucial to spend your money on.
