Cybersecurity Budgeting: A Cyber Risk Perspective
DOI:
https://doi.org/10.14738/tecs.1404.12106Keywords:
Cybersecurity, Budgeting, Cyber, RiskAbstract
Given the prominence of cyber risk, executives in organizations must address the following question: How much should be budgeted for cybersecurity? The primary objective of this paper is to provide a rigorous economic framework for analyzing and addressing the critical challenges associated with developing a cybersecurity budget, with particular emphasis on investments to prevent cyber breaches. The proposed framework is grounded in the Gordon–Loeb Model, which provides a theoretical basis for deriving the optimal level of investment in cybersecurity (Gordon and Loeb, 2002). The paper makes four contributions to the existing literature on cybersecurity budgeting. First, it identifies a comprehensive list of challenges associated with budgeting for cybersecurity activities within an organization. Second, it demonstrates that cybersecurity budgeting is best viewed from a cyber risk perspective and that this perspective is consistent with the U.S. Securities and Exchange Commission (SEC) rules concerning Cybersecurity Risk management, Strategy, and Governance (SEC, 2023). Third, it provides insight into the economic rationale for placing an upper-bound on initial cybersecurity budgets. Fourth, it examines the frequent misalignment between authority and responsibility for cybersecurity spending and proposes mechanisms to better align the incentives.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Lawrence A. Gordon, Martin P. Loeb, Lei Zhou

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
