Pricing Risk — The Economics of Security Leadership
Security is a spending decision under uncertainty, and the executive who can say what a control is worth is worth more than the one who can only say it is necessary.
Learning objectives
- Explain the Gordon–Loeb logic — security spending as a function of expected loss — and state its limits before quoting its bound.
- Summarize what breach-cost research does and does not show, and why a market reaction is not your invoice.
- Distinguish proactive from reactive investment and symbolic from substantive adoption, and treat both as multipliers on the same dollar.
- Run a budget conversation as risk pricing rather than fear, using the Risk Corollary, and price a single control in numbers a non-technical CEO can argue with.
Core lesson
Most security budget conversations fail the same way. The technology executive arrives with a threat, a headline and a number; the CEO hears a request to buy peace of mind at an unspecified price. The executive reads the resulting cut as the business not taking security seriously. The business reads the ask as an unpriced demand from a function that has never once said "that one isn't worth buying."
This module teaches the alternative: treating security as a spending decision under uncertainty, which is what it is. The economics of information security investment is nearly a quarter-century old, and its central result is uncomfortable for both sides of that meeting — the optimal spend is well above zero and well below everything, and it depends on numbers you can only estimate. The evidence on what breaches cost says less than it is usually claimed to. And when you spend, and how deeply you integrate what you buy, matter more than the amount.
The payoff is an instrument — the Risk Corollary, used as the structure of a budget conversation rather than as a slogan — and a worked example: one control, priced so a non-technical CEO can argue with it. In the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module changes the Behaviors term. Pricing is a behavior, and it is learnable.
The big idea
A control you cannot price is a control you cannot defend — and a risk you cannot price is a risk you are accepting by accident.
Your authority does not come from being right about threats; everyone in the room believes threats are real. It comes from being the only person who can say what a control buys, what it costs, and what happens if it is not bought — in the units the CFO already uses. The moment you can also say "this one isn't worth it," the other three asks become credible.
What the research says
How much is rational to spend
RESEARCH FINDING Gordon and Loeb (2002) built an economic model in which optimal security investment for a given information set depends on its value, its vulnerability, and the productivity of security spending. For the breach-probability functions they assume, optimal investment "does not exceed 37% of the expected loss from a breach" — the 1/e bound — and it can be rational to invest less in the most vulnerable assets, because the marginal dollar buys less there. What it supports: spending as a function of expected loss, and a formal argument that "spend until safe" is not a coherent target. What it cannot support: a budget. This is an analytical model, not an empirical study; the bound holds only for the two classes of breach functions the authors assume, and later papers show other functions can justify 50% or more.
What breaches cost — and what the studies measure
RESEARCH FINDING Campbell, Gordon, Loeb and Zhou (2003), in an event study of newspaper-reported breaches at US public firms, found "limited evidence of an overall negative stock market reaction," but "a highly significant negative market reaction for information security breaches involving unauthorized access to confidential data" and "no significant reaction when the breach does not involve confidential information." Pre-2003 newspaper sample, short windows, the authors' own classification of "confidential." Investors price the type of breach, not the fact of one. RESEARCH FINDING Cavusoglu, Mishra and Raghunathan (2004) put an average on it — about 2.1% of market value, or "$1.65 billion per breach," over two days — while security vendors gained (1.36%, about $1.06 billion). Those dollar figures reflect a pre-2004 large-cap sample and do not generalize.
RESEARCH FINDING Kamiya, Kang, Kim, Milidonis and Stulz (2021) tested a model of optimal cyber-risk exposure on successful attacks against US firms. Attacks involving loss of personal financial information caused "significant shareholder wealth loss, which is much larger than the attack's out-of-pocket costs," consistent with reputational damage; losses spilled over to industry peers; firms whose boards had attended to risk management before the attack suffered smaller excess losses. Archival, disclosed attacks only, board attention proxied, associations. Kashmiri, Nicol and Hsu (2017) found the same neighbourhood effect at 168 US retailers around the December 2013 Target breach.
RESEARCH FINDING Amir, Levi and Livne (2018) compared attacks firms disclosed with attacks they withheld that outsiders later revealed: "withheld cyber-attacks are associated with a decline of approximately 3.6% in equity values in the month the attack is discovered, and disclosed attacks with a substantially lower decline of 0.7%." Attacks never discovered are unobservable by construction, and the period predates the SEC rules. Concealment is priced when discovered — a cost line, not a moral aside.
When you spend, and how deeply you adopt
RESEARCH FINDING Kwon and Johnson (2014), using a Cox proportional-hazard model on US healthcare organizations, found "proactive security investments are associated with lower security failure rates," that proactive investment was more cost-effective than reactive, and that "external pressure decreases the effect of proactive investments on security performance." One sector, disclosed breaches, associations. The same dollar buys more before the failure than after — and regulatory pressure can crowd out the benefit of getting ahead.
RESEARCH FINDING Angst, Block, D'Arcy and Kelley (2017), in a matched panel of over 5,000 US hospitals and 938 breaches from 2005 to 2013, classified hospitals as symbolic or substantive adopters and found "symbolic adoption diminishes the effectiveness of IT security investments, resulting in an increased likelihood of breach," while deeper integration of security into IT routines was associated with fewer breaches. Adoption depth was inferred from an institutional profile rather than observed; reported breaches only. This is the most important qualifier on any security budget number.
Practitioner base rates — Tier 3, descriptive only
RESEARCH FINDING (Tier 3). The Verizon 2025 Data Breach Investigations Report analyzed 22,052 incidents, of which 12,195 were confirmed breaches, and reports third-party involvement in 30% of breaches (up from 15%), ransomware in 44% and in 88% of SMB breaches, credential abuse as the most common initial vector at 22%, the human element in roughly 60%, and a median ransom payment of $115,000 with 64% of victims not paying. RESEARCH FINDING (Tier 3). IBM and the Ponemon Institute (2025), from about 600 breached organizations, put the global average breach cost at $4.44 million, down 9% from $4.88 million, with mean time to identify and contain at 241 days. Neither is peer-reviewed. The DBIR is a non-random contributor sample whose visibility depends on regional disclosure laws; IBM's figures come from self-selected participants, use estimated rather than audited costs, and are published by a company that sells security products. Use them for orders of magnitude. Never use them causally — no line in either establishes that any control reduced any cost.
Where the evidence is weak
Nearly all of it concerns large public companies, and the breach-cost studies price investor expectations rather than cash out the door. Nothing here gives an SMB, MSP or private mid-market firm a defensible loss distribution — the population that most needs one is the least studied. And no study in this library shows that a particular control, framework or spending level reduces breaches at your company. Everything the module says about how to price is FRAMEWORK; the worked example's numbers are fictional.
Explanation
What Gordon–Loeb actually gives you
FRAMEWORK Strip the mathematics and the model says three things a CEO accepts immediately. Spending should be a function of what you would lose, not of what a threat report says exists. The return on the marginal dollar falls as you spend, so there is a level beyond which more spending destroys value. And the most vulnerable asset is not automatically the one deserving the most money, because where protection is very hard the marginal dollar buys less.
INTERPRETATION Use the 37% bound as a sanity check, never an allowance: if you are asking for more than roughly a third of what the thing is worth losing, either your loss estimate is too low or your proposal is wrong. Anyone quoting it without its assumptions is quoting a number they have not read.
What breach-cost research does not show
Two misuses get technology executives caught in front of a CFO. The first is treating someone else's average as your cost. Campbell et al. (2003) and Cavusoglu et al. (2004) measure abnormal returns over days — investor expectations, re-priced — in pre-2004 samples of very large firms, and the IBM/Ponemon $4.44 million is a mean across self-selected organizations of wildly different sizes. Quote either to a private mid-market CFO as their exposure and you have handed the room a reason to distrust every other number you brought.
The second is ignoring type: the significant reactions in both Campbell et al. and Kamiya et al. concentrate in breaches of confidential and personal financial data. INTERPRETATION The question is never "what does a breach cost" but "what does this breach, of this data, at this firm cost" — which your business can help answer and a threat report cannot.
The two multipliers on every dollar
INTERPRETATION Timing (Kwon & Johnson, 2014): the same control is a different purchase before and after an incident. Bought before, it is a priced choice; bought after, it is bought at the worst price, under duress, alongside a public-relations budget nobody planned.
Depth (Angst et al., 2017): bring this to the meeting where the CFO offers to fund the tool but not the engineers who would operate it. Half a control is not half a benefit; it may be no benefit and a line item. If you cannot integrate it this year, do not buy it this year — and say so, because saying it is what makes your other asks credible.
Enablement with institutional paranoia, as a budget behavior
FRAMEWORK "Enablement with institutional paranoia" is a description of a disposition, not a diagnosis. In a budget conversation it takes one form: you arrive as someone trying to make the business's plan work, carrying a quantified, unsentimental view of how that plan could kill the company.
The instrument is the Risk Corollary. "Yes — and here is the risk we are accepting, priced" is what makes you an executive rather than a control. It requires a loss estimate, a probability estimate, and a named person who signs the acceptance; a "yes" without those three is abdication with a pleasant tone. "No — and here is what would change my answer" stops "no" from becoming your identity. The second clause is not politeness but a trade the business can execute: "No, unless the vendor completes SOC 2 Type II or we scope them to a segregated tenant" is a decision; "No, it's too risky" is a mood.
Both require a price, which is why pricing precedes influence — and it gives you something to do with the pressure the role carries. In the IANS and Artico Search (2026) survey of more than 600 security leaders, 52% said their responsibilities were "not manageable given current resources" (self-selected; base rate only). An unmanageable mandate is easier to renegotiate with a priced list than with an appeal.
Pricing one control, in numbers a CEO will follow
Illustrative and fictional; the arithmetic is real, the inputs are estimates. A 300-person managed-services firm administers 190 client environments through a remote-administration path. The proposal: phishing-resistant multi-factor authentication plus a privileged-access broker on every administrative session.
1. What are we protecting? Not "the network." The administrative path into 190 client environments — the mechanism by which one compromised technician becomes 190 compromised clients.
2. How likely per year, without the control? Call it 8%, about one year in twelve, from three years of the firm's own attempted-intrusion logs plus the fact that credential abuse is the most common initial vector in the DBIR's 2025 sample at 22% (Tier 3, non-random). This is the weakest number in the model.
3. If it happens, what does it cost? A range, not a point. Response, forensics and counsel $250,000–$600,000; client credits, remediation and re-attestation $400,000–$1.5 million; two or three lost clients at roughly $250,000 of recurring revenue each. Central estimate $3.4 million; high case above $9 million if several regulated clients are hit at once. Expected annual loss today: 8% × $3.4 million = $272,000.
4. What does the control cost? Year one $95,000 ($38,000 licences, $22,000 implementation, $35,000 internal engineering). Steady state $46,000 a year.
5. What does it do to the probability? It does not remove the risk; it removes a class of it. Estimate 8% down to 2%. Expected annual loss falls from $272,000 to $68,000 — $204,000 avoided for $46,000, about $4.40 per dollar spent.
6. The sentence the CEO can argue with. "This pays for itself if it moves the annual probability of a credential-driven client compromise by more than about 1.4 percentage points" — $46,000 divided by $3.4 million is 1.35 points. A non-technical CEO can contest that without knowing what a security key is, and contesting it is the point.
7. The Gordon–Loeb sanity check. Expected loss $272,000; 37% is about $100,000. Year-one spend of $95,000 sits just under, steady state well under. Had the proposal been $400,000 against the same exposure, the model says it is wrong even though the threat is real.
8. The honesty clause. Say which numbers are quotes and which are guesses: the 8% is a guess informed by logs, the $3.4 million a modeled range, the 2% an engineering judgment, only the $46,000 a quote. INTERPRETATION Executives lose credibility by presenting all four with equal confidence, not by admitting three are soft.
FRAMEWORK Pricing moves the aggression↔caution and optimism↔skepticism dials by decision rather than temperament. Graham, Harvey and Puri (2013, from the CEO library) found CEOs scored substantially more risk-tolerant and optimistic than the general population — self-reported, associations only. That is the room you price into: your estimates read as pessimistic by default, which argues for showing arithmetic rather than conclusions.
Example
Fictional composite. Charter Oak Business Services is a business-process and managed-services firm in Hartford, Connecticut: $41 million in revenue, 310 employees, 190 clients across registered investment advisers and broker-dealers, two hospital-affiliated physician groups, several law firms and a regional specialty retailer. Ruth Alvarez has been VP of Technology and Security for three years and holds both mandates. Security spend last year was $780,000; her ask for the coming year is $1.14 million.
The CEO, a former operations partner who reads a P&L faster than anyone in the building, asks the question the module exists for: "What does this buy us?"
She has brought three asks, priced, ranked by expected loss avoided per dollar.
Privileged access and phishing-resistant MFA on the administrative path — the control priced above. $95,000 in year one, roughly $4.40 avoided per dollar, break-even at 1.4 percentage points. She names the 8% as the soft number before anyone asks.
Two security engineers to operate the detection stack bought eighteen months ago — $340,000 fully loaded, framed with Angst et al. (2017): across 5,000-plus hospitals, the same investment was associated with fewer breaches only where adoption was substantive. "We already spend $210,000 a year on a tool nobody is paid to tune. That is a symbolic adoption. The engineers are not an addition to the tool; they are what makes it a control instead of a receipt."
A deception and honeypot platform — $180,000. Here Alvarez does the thing that makes the meeting work. She withdraws it. "I asked for this two months ago and I still cannot price it. I cannot tell you what it moves. The others I can. Take it out."
The CFO offers the predictable compromise: renew the tool, defer the engineers, add one contractor. Alvarez says no, and says the second half. "No — one contractor gets tuning but not on-call coverage, and we would still pay $210,000 a year for an untuned control. What would change my answer is a second contractor, or a co-managed detection contract at about $190,000 that comes with coverage."
Then the first sentence. "Yes — we can run one more year without the engineers, and here is the risk we are accepting, priced. Our mean time to notice an intrusion in a client environment is measured in weeks. If it happens, my central estimate is $3.4 million. If we accept that, I need you or the CEO to sign the acceptance in my words, not yours."
Charter Oak funds the access control and the co-managed contract; the deception platform never returns, and the signed acceptance goes into an exception log that someone other than its author reads in April. When the board's audit chair asks about the withdrawn item, the CEO gives the module's thesis in one line: "She took one off the list herself. That's why I believed the other two."
Leader Contrast
Same three asks, same CEO, four archetypes in Alvarez's chair.
The Technical CISO brings the threat, not the price. The presentation is excellent on mechanism and silent on worth. Asked "what does this buy us," the honest internal answer is "safety," which converts in the CEO's head to "an unbounded ask." The cost is that the budget is then set by whoever can price — the CFO — whose model of security value is the invoice. This archetype's dominant risk, "no" as identity, starts here: unable to say what a control is worth, and therefore never able to say one is not worth buying.
The Business-Risk CISO prices all three and wins all three, because the pricing was built to win. The 8% becomes 15%, the high case becomes the central case, and the deception platform acquires a story. The gain is a funded program; the cost arrives in eighteen months when nothing has happened, the CFO recalculates, and every future number carries a discount. INTERPRETATION The failure is not dishonesty; it is a pricing model with no downside case, built by someone unaware they are advocating.
The SMB / MSP Technology Leader (Player) gets no budget meeting — just a conversation with an owner about whether $95,000 is affordable this quarter. The arithmetic is scale-free and still works; the estimates are thinner and nobody checks them. The danger is a loss estimate produced by the same person who wants the control. The mitigation is cheap: send the one-page pricing to the insurance broker, the outside accountant or a peer vCISO first, and ask only "which of these four numbers would you argue with?"
The Regulated-Industry CIO/CISO, imagine Charter Oak as a broker-dealer rather than its service provider, has an easier meeting and a subtler problem. Regulatory expectation carries the ask across the line without pricing, which is faster and worse: Kwon and Johnson (2014) found external pressure decreased the effect of proactive investment on security performance. INTERPRETATION When the regulator is the argument, nobody learns what anything is worth. Price it anyway, in private, and notice which items survive only because an examiner will ask.
Failure mode
Pricing has two opposite overuse paths and one that pretends to be neither.
INTERPRETATION The first is rigor → bureaucracy. Pricing becomes a program: a quantification workstream, a consultant, a model with sixty inputs, and decisions due in March still open in September. The tell is that the model's outputs never change anyone's mind, because the decision was made by default while it was being built. Treat any model that cannot produce a recommendation in a week as a control that failed its own cost-benefit test.
The second is confidence → arrogance, wearing a spreadsheet. False precision is more dangerous than admitted ignorance, because a number invites a decision. Present the 8% as confidently as the $46,000 quote and a guess has been laundered into a fact — and the first time the guess is visibly wrong, the method is discredited with it.
The third looks like neither: optimism → delusion in the direction of the business. This is the executive who prices everything to the answer the CEO wants, calls it enablement, and signs the risk acceptances themselves. Every "yes" is priced, none honestly, and the business never learns what it is carrying.
Early warning signs, for the executive or the CEO watching:
- The security function has never once said "that control isn't worth buying," in any budget cycle.
- Every ask is justified by a threat report or a peer's breach, none by a loss estimate for this company.
- Loss estimates always land just above the cost of the thing requested, and nobody can say which number is weakest.
- A tool bought last year still has no named operator, and this year's ask is a different tool.
Personal reflection
- Take the largest control in your stack. Write four lines: what it protects, the annual probability it addresses, the loss if that event happens, its annual cost. Which is a quote and which is a guess?
- When did you last recommend against buying a control you had asked for? If never, what does your CEO conclude from that?
- What is the highest-value asset you are deliberately under-protecting because the marginal dollar buys more elsewhere? Can you defend that in Gordon–Loeb terms, or have you simply not looked?
- Name one purchase from the last two years that is a symbolic adoption — funded, installed, untouched by any routine. What would substantive adoption cost, and is it worth more than the next new thing on your list?
- Write both Risk Corollary sentences for the biggest open decision on your desk. If the second clause of the "No" sentence is empty, what does that tell you?
- Who signed your last risk acceptance? If the honest answer is that you did, whose risk was it — and what would it have cost to ask for the signature?
Tell Me What We Stop Protecting
Harrowgate Diagnostics · Clinical laboratory network — 22 patient-service centers across New Jersey and eastern Pennsylvania · $310M · Mature · Family-owned
One week to answer. The $3.2 million is permanent, not a timing problem. Two client contracts name specific control families and are audited annually, and your personal attestation to the audit committee is the instrument that says the program operates as described.
Take the decision →Knowledge check
Pick an answer to reveal the explanation. Nothing is scored or stored.
1The Gordon–Loeb (2002) result that optimal security investment "does not exceed 37% of the expected loss from a breach" should be presented as:
A model result, not an empirical or regulatory one; the bound is conditional on assumptions that must be stated whenever it is quoted.
2Angst, Block, D'Arcy and Kelley (2017), across more than 5,000 US hospitals and 938 breaches, found that:
The same dollar bought protection only where adoption was substantive — the reason "fund the tool but not the operator" is not half a control.
3Which use of the Verizon DBIR (2025) or the IBM/Ponemon report (2025) fits this curriculum's evidence rules?
Both are Tier 3 and self-selected: usable for base rates, never causally or as a firm's loss forecast.
4Kwon and Johnson (2014), studying US healthcare organizations, found that:
Timing is a multiplier on the same dollar, and the external-pressure result warns against spending that exists to satisfy an examiner.
5A CEO asks what a proposed $46,000-a-year control buys. Name the four inputs the method needs and the sentence you should end on.
Model answer. The specific asset or path being protected; the annual probability without the control; the loss if it happens, as a range with a central estimate; and the control's effect on that probability. End on a break-even claim — "this pays for itself if it moves the annual probability by more than X percentage points" — and say which numbers are quotes and which are guesses.
Expected loss before minus after, against cost; the break-even framing turns an unfalsifiable ask into a claim the business can contest.
Key takeaways
- Security is a spending decision under uncertainty. Gordon and Loeb (2002) give the discipline — spending as a function of expected loss, with falling marginal returns and a bound conditional on the model's assumptions — not a budget.
- Breach-cost research prices investor expectations at large public firms, and prices the type of breach rather than the fact of one (Campbell et al., 2003; Cavusoglu et al., 2004; Kamiya et al., 2021). It is not your invoice.
- Two multipliers sit on every dollar: timing (Kwon & Johnson, 2014) and depth (Angst et al., 2017). Funding a tool without its operator is not half a control; it may be no control and a line item.
- Practitioner reports — DBIR 2025, IBM/Ponemon 2025 — are Tier 3, non-random and vendor-adjacent. Use them for base rates; never causally, never as your firm's exposure.
- The Risk Corollary is the budget instrument: "Yes — and here is the risk, priced," with a named signatory, and "No — and here is what would change my answer," with a trade the business can execute. Both require arithmetic — and the ask you withdraw is what makes the rest credible.
Research cited in this module
- Gordon & Loeb (2002)The economics of information security investment. ACM Transactions on Information and System Security · tier 1 · verified
- Campbell et al. (2003)The economic cost of publicly announced information security breaches: Empirical evidence from the stock market. Journal of Computer Security · tier 1 · verified
- Cavusoglu et al. (2004)The effect of internet security breach announcements on market value: Capital market reactions for breached firms and internet security developers. International Journal of Electronic Commerce · tier 1 · verified
- Kamiya et al. (2021)Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics · tier 1 · verified
- Kashmiri et al. (2017)Birds of a feather: Intra-industry spillover of the Target customer data breach and the shielding role of IT, marketing, and CSR. Journal of the Academy of Marketing Science · tier 1 · verified
- Amir et al. (2018)Do firms underreport information on cyber-attacks? Evidence from capital markets. Review of Accounting Studies · tier 1 · verified
- Kwon & Johnson (2014)Proactive versus reactive security investments in the healthcare sector. MIS Quarterly · tier 1 · verified
- Angst et al. (2017)When do IT security investments matter? Accounting for the influence of institutional factors in the context of healthcare data breaches. MIS Quarterly · tier 1 · verified
- verizon2025 (2025). 2025 Data Breach Investigations Report · tier 1 · verified
- ibm2025 (2025). Cost of a Data Breach Report 2025 · tier 1 · verified
- Weill & Ross (2004). IT Governance: How Top Performers Manage IT Decision Rights for Superior Results · tier 1 · verified
- ians2026 (2026). State of the CISO 2026 Benchmark Report · tier 1 · verified
- Graham et al. (2013)Managerial attitudes and corporate actions. Journal of Financial Economics · tier 2 · verified
Each entry opens the research card with method, limitations and the usable claim.