How Much Cybersecurity Is Enough? A Risk-Based Investment Framework
Cybersecurity presents business leaders with an awkward budgeting problem.
Spend too little and the organisation can be left exposed to disruption, data loss, fraud or recovery costs that dwarf the saving. Spend indiscriminately, however, and money can disappear into controls, products and services without anyone being able to explain which business risk they materially reduce.
Neither the NIST Cybersecurity Framework nor NCSC guidance prescribes a universal percentage of revenue that tells every company what it should spend. Nor does a larger security budget automatically mean a better-protected business.
The more useful question is different:
Which cyber risks could materially affect the business, and what level of investment is justified to change those risks?
For a growing business, “enough” cybersecurity is the level of investment that meets non-discretionary requirements, brings unacceptable risks within the organisation’s tolerance and makes clear which residual risks remain.
The budget then becomes a business decision about exposure, consequence, resilience and acceptable risk rather than an open-ended technical expense.
Key Points: Deciding Where Cybersecurity Investment Actually Matters
Cybersecurity spending makes more sense when leaders start with business consequences rather than a catalogue of possible threats or security products.
Key points include:
- There Is No Universal Cybersecurity Budget: The appropriate level of investment depends on what the business relies on, the information it holds and the consequences of disruption or compromise.
- Impact Matters Alongside Likelihood: A relatively unlikely event can still justify substantial protection if its consequences would threaten a critical operation or obligation.
- Prevention Is Only Part of the Investment Decision: Detection, response and recovery can sometimes reduce business risk more effectively than adding another preventative control.
- Not Every Risk Needs Another Control: Some risks can be mitigated, avoided, shared or transferred in part, or knowingly accepted when the residual exposure is understood.
- Baseline Controls Still Matter: Risk-based investment should not become an excuse to ignore binding requirements or relatively straightforward protections with strong risk-reduction value.
- Buy Capability, Not a Longer Product List: Leaders should identify the capability gap first and then decide whether it is best filled internally, externally or through a combination of both.
Proof Point: The UK National Cyber Security Centre says one purpose of cyber-risk management is to improve decisions about how much time and money an organisation spends protecting its technology and services, while helping ensure resources and investment are directed to the right areas.
The Bottom Line: Cybersecurity spending is justified by the business risk it changes, not by the number of controls, products or services it buys.
Start With the Business Consequence, Not the Cyber Threat
Threat lists can become almost endless.
Ransomware, credential theft, phishing, software vulnerabilities, supplier compromise, insider activity and emerging AI-enabled attacks may all deserve attention. But an organisation cannot sensibly fund itself against every imaginable scenario to the same degree.
The starting point should therefore be the business operation.
Which systems, information, suppliers and processes does the organisation depend on to generate revenue, serve customers, meet legal or contractual obligations and continue operating?
Then ask what failure would mean.
A two-hour outage affecting an internal administrative application may be inconvenient but recoverable. Losing access to the platform that takes customer orders, controls a production line or stores time-critical client information could produce a very different decision.
The NCSC’s board guidance makes the same connection between cyber risk and wider organisational risk: boards are expected to understand how cyber incidents could affect delivery of business strategy and to manage that exposure in line with the organisation’s risk appetite.
The same logic applies to downtime costs. Fundz has previously examined how businesses should set recovery priorities when IT downtime occurs.
The systems that deserve the greatest attention are not necessarily the most technically sophisticated. They are often the ones whose failure creates the greatest operational or commercial consequence.
A Large Potential Loss Does Not Automatically Set the Budget
Headline breach figures are useful for demonstrating that cyber incidents can be expensive, but they are dangerous when turned into budgeting formulas.
IBM’s 2026 Cost of a Data Breach Report puts the global average cost of a data breach at $4.99 million, up 12% from the previous year. The study covered 602 organisations affected by breaches.
A growing company should not construct its security budget around that $4.99 million figure.
An average drawn from hundreds of organisations that experienced breaches cannot tell an individual business what its own exposure would be. The relevant question is what a meaningful incident would do to that particular organisation: whether revenue could stop, obligations could be missed, sensitive information could be affected, restoration could become expensive or customer relationships could be damaged.
The point of estimating impact is not to predict an incident cost to the nearest pound or dollar. It is to distinguish risks that could genuinely alter the company’s position from those that can be tolerated and recovered from.
Likelihood and Consequence Need to Be Considered Together
Businesses routinely make investment decisions by balancing probability against impact. Cyber risk should not be treated differently merely because the underlying technology is less familiar to the board.
A high-frequency, low-impact problem may justify a relatively inexpensive operational fix. A lower-frequency event capable of shutting down a critical service for several days may justify greater investment even though it occurs less often.
This is where risk appetite becomes useful.
Risk appetite does not mean deciding that cyber incidents are acceptable. It helps define how much risk the organisation is prepared to carry while pursuing its objectives. The exposure that remains after existing controls are considered is commonly described as residual risk.
The NCSC recommends setting a cyber-risk appetite because it can improve decisions about resource allocation and help organisations establish what level of risk they are prepared to manage. Its guidance also warns against reducing complex cyber decisions to isolated risk scores without the business context behind them.
For leadership, that is more useful than labelling cybersecurity simply high, medium or low risk.
Risk-Based Does Not Mean Starting From Zero
There is an important qualification to risk-based security spending.
It should not result in every basic safeguard becoming the subject of a bespoke cost-benefit exercise. Nor does an organisation’s preferred risk appetite override requirements it is obliged to meet.
Legal, regulatory and contractual requirements can establish cybersecurity outcomes that are not simply optional spending choices. The NIST Cybersecurity Framework 2.0 includes understanding and managing legal, regulatory and contractual cybersecurity requirements within its Govern function.
Beyond those obligations, some broadly applicable safeguards can provide enough risk-reduction value that they make sense as a baseline rather than as competing investment projects.
CISA’s Cross-Sector Cybersecurity Performance Goals illustrate the principle. They are a voluntary baseline developed for critical-infrastructure organisations, with particular attention to making high-impact actions accessible to smaller and medium-sized entities. CISA says the goals were selected in part because they significantly reduce commonly observed risk and are reasonably straightforward and not cost-prohibitive even for smaller organisations.
The point is not for every business to copy the CISA list. It is that risk-based investment still benefits from a sensible baseline.
The deeper prioritisation problem begins when that baseline and any binding requirements have been addressed. Leaders can then ask whether additional spending is targeting the organisation’s most important remaining exposures or simply adding more protection to areas that are already comparatively well controlled.
Not Every Cyber Risk Needs Another Control
Identifying a cyber risk does not automatically mean buying another security product.
Established risk-management practice recognises several possible responses. NIST uses the terms accept, avoid, mitigate, share and transfer, depending on the context and framework.
A business might mitigate a risk by introducing additional safeguards or reducing its potential impact. It might avoid the activity creating the exposure altogether. It might knowingly accept residual risk that falls within its tolerance. In some circumstances, part of the consequence can also be shared or transferred to another party.
Transfer is the easiest of those terms to misunderstand.
Cyber insurance, for example, can help transfer some financial consequences of an incident. It does not transfer every consequence. NIST notes that losses such as damage to customer trust may remain with the organisation even where some financial exposure has been transferred.
The same distinction matters when activities are outsourced. Moving responsibility for performing a task does not necessarily remove the business exposure associated with failure.
Risk acceptance only works when it is actually a decision.
There is a substantial difference between saying, “We understand this exposure, have considered the consequences and have decided that further mitigation is not proportionate,” and discovering later that nobody realised the exposure existed.
The first can be legitimate risk acceptance. The second is simply an unidentified exposure.
Sometimes Recovery Deserves the Next Pound Before Prevention
Risk treatment does not always mean adding another layer of prevention.
No organisation can reasonably assume that every preventative control will work every time, so the investment decision also needs to consider what happens when prevention fails.
Suppose two businesses face similar ransomware exposure. One has tested backups, defined recovery priorities, clear incident authority and the ability to restore critical operations. The other has added more preventative products but has never established how it would recover its most important systems.
The second organisation may have spent more while remaining less resilient.
NIST’s Cybersecurity Framework 2.0 presents cybersecurity through six functions: Govern, Identify, Protect, Detect, Respond and Recover, rather than defining security solely through preventative controls. The framework is designed to help organisations understand, assess and prioritise cybersecurity outcomes according to their circumstances.
This is why Fundz’s earlier ransomware-readiness analysis focused on limiting business disruption, not just blocking attacks.
A business with a finite budget should therefore ask where the next investment would reduce the most consequential exposure: prevention, earlier detection, faster response, stronger recovery or another capability entirely.
How Should Leaders Prioritise Cybersecurity Spending?
Leaders can prioritise cybersecurity spending by following the decision in sequence:
Business consequence → existing controls → residual risk → capability gap → investment choice → verification
Each stage answers a different question.
What matters to the business? What is already protecting it? What meaningful exposure remains? What can the organisation currently not do well enough? What response deserves resources? And, after the money has been spent, did it actually alter the intended risk?
A practical leadership review can then cover the following:
| Business consideration | Decision question |
|---|---|
| Operational dependence | What stops if this system, supplier or information becomes unavailable? |
| Financial exposure | What costs or lost revenue could arise during a meaningful disruption? |
| Data sensitivity | What would disclosure, alteration or loss of this information mean? |
| Recovery capability | How quickly and reliably could an acceptable level of service be restored? |
| Customer and contractual impact | Could failure prevent the business meeting obligations to customers or partners? |
| Existing controls | Which parts of this risk are already reasonably controlled? |
| Residual risk | What important exposure remains after those controls are considered? |
| Capability gap | Is the weakness primarily prevention, visibility, response, recovery or specialist expertise? |
| Investment choice | Should the organisation mitigate, avoid, transfer or share part of the exposure, or knowingly accept the residual risk? |
| Verification | How will leadership know that the investment produced the intended risk outcome? |
The final question prevents cybersecurity investment becoming self-justifying.
Buying a product, appointing a specialist or signing a service contract demonstrates that money has been spent. It does not, by itself, demonstrate that the business is materially safer.
The investment should therefore be traceable back to the exposure that justified it.
When a Security Gap Becomes a Sourcing Decision
Once the organisation has decided that a capability deserves funding, another decision follows: should that capability be built internally or obtained externally?
That sourcing question should come after the risk decision, not before it.
A company might discover that it needs better monitoring, faster incident response, stronger recovery capability, additional security expertise or more reliable day-to-day support. The appropriate sourcing model will depend on the skills already available internally, how continuously the capability is required and what it would cost to maintain.
For a business assessing external provision, reaching out to InfoTECH Solutions could provide one view of how those capabilities are packaged and delivered through a managed provider. Its current Baton Rouge offering includes proactive monitoring, 24/7 support, security assessments, employee training, managed cybersecurity, backup and disaster recovery, alongside broader managed and consulting services.
A broad service catalogue does not mean the business needs all of those capabilities.
The buyer should first know which gap it is attempting to close and what risk that gap creates. Only then can the economics of internal provision, external provision or a combined approach be compared properly.
The practical discipline is to define the gap first, then compare ways of supplying it rather than allowing a provider’s service catalogue to define the problem.
Judge Security Services by the Risk They Need to Address
Choosing external provision does not end the investment analysis. It changes the next question from whether capability is required to whether the proposed service actually addresses it.
Provider comparisons can easily become feature comparisons.
One supplier includes a monitoring service. Another adds advisory support. A third bundles backup, cybersecurity and helpdesk coverage. The resulting comparison can become a contest over which package contains the greatest number of services.
Once the risk is defined, that kind of feature count is largely beside the point.
Inspirica IT's website, for example, presents several distinct ways of obtaining technology capability, including managed IT, cybersecurity, project-based services and strategic advisory functions. Inspirica also distinguishes ongoing managed services from professional or project services according to factors including business impact, internal capacity and the type of work required.
For the buyer, the relevant question is not which provider offers the longest list. It is which service addresses the capability gap the organisation has already decided matters.
A business that needs periodic specialist assessment may not require continuous outsourced operation. Another that lacks continuous monitoring or recovery capability may reach a different conclusion.
The service model should follow the risk decision.
Accountability also remains with the organisation. The NCSC states that board accountability for cyber risk remains even when cyber activities are outsourced.
What happens after a provider is appointed, governance, reporting, accountability and exit readiness, is a separate management question.
Revisit Cybersecurity Spending When the Business Changes
The appropriate level of security investment cannot be fixed permanently because the business itself keeps changing.
A company may take on more sensitive customer data, enter a regulated market, sign a contract with stricter security requirements, acquire another company, expand internationally or become dependent on systems that previously played only a supporting role.
Any of those changes can alter the consequence of failure, the organisation’s obligations or the adequacy of existing controls.
Security investment should therefore be revisited when the business changes rather than increased each year automatically by a budget percentage.
The NCSC recommends regularly reviewing cyber risk and integrating it with wider operational and organisational risk because changes in business and technology can change what deserves attention.
The annual question should not simply be, “Should we spend more on cybersecurity this year?”
A better question is, “Which important risks have changed, which remain outside our appetite, and where would additional investment improve the outcome?”
Enough Cybersecurity Means Knowing What Risk You Are Choosing to Carry
“Enough” is not a fixed level of cybersecurity.
By that point, leadership understands the important exposures, has met its non-discretionary requirements, has funded the capabilities needed to bring unacceptable risks within tolerance and knows what residual risk remains.
That position can change as the business changes, which is why the answer has to be reviewed rather than permanently calculated.
Some reviews will justify more investment. Others may show that existing controls are sufficient, that recovery deserves priority over additional prevention or that retaining a limited exposure is commercially rational.
The objective is not maximum cybersecurity at any cost.
It is enough security and resilience to support the organisation’s objectives without carrying risks that leadership would reject if they were properly understood.
Questions Business Leaders Ask About Cybersecurity Investment
Is there a recommended percentage of revenue to spend on cybersecurity?
Neither the NIST Cybersecurity Framework nor NCSC guidance prescribes a universal percentage of revenue that every organisation should spend on cybersecurity. The appropriate level depends on factors including business dependence on technology, data sensitivity, legal and contractual requirements, existing controls, recovery capability and the organisation’s risk appetite.
How can a business tell whether it is underspending on cybersecurity?
A useful warning sign is the presence of important risks outside the organisation’s accepted tolerance without a funded plan to mitigate, avoid, share, transfer or consciously accept them. Leaders should focus on business consequences and capability gaps rather than simply comparing their spending with another company’s budget.
Can a company spend too much on cybersecurity?
Yes. Additional spending can produce diminishing value if it concentrates resources on risks that are already well controlled while more important gaps remain elsewhere. Risk-based prioritisation is intended to direct resources toward the outcomes that matter most.
Should cybersecurity budgets prioritise prevention or recovery?
Neither should automatically dominate. Prevention, detection, response and recovery address different parts of cyber risk. The appropriate balance depends on the consequences of failure, existing controls and how quickly the organisation could restore critical operations.
When does outsourcing cybersecurity make financial sense?
External capability can make sense when the organisation needs expertise, coverage or scale that would be inefficient to build internally. The decision should start with the business risk and capability requirement rather than with the provider or service package.