Optimal Level and Allocation of Cybersecurity Spending: Model and Formula

12 Pages Posted: 31 Jul 2017 Last revised: 28 Oct 2017

See all articles by Shaun Wang

Shaun Wang

Nanyang Technological University

Date Written: October 27, 2017

Abstract

This paper presents mathematical models for cyber breach probability as function of security spending in protecting a firm’s ICT systems. We derive optimal level of security investment as percentage of value-at-risk. We show that the upper bound of optimal investment can be 1/e, 1/√2π or other percentages of value-at-risk, depending on the cyber breach probability model. We apply the models to derive optimal security budget allocation for protecting ICT systems with multiple areas of vulnerability and multiple data assets. Our analysis highlights the importance of security measures to cover the full spectrum of areas of vulnerability; neglecting one area of vulnerability can render the security investment ineffective and wasteful. Moreover, optimal economic value can be achieved by differential treatment of a firm’s high-value data assets.

Keywords: Economics of Information Security; Cyber Breach Probability; Security Budget Allocation

JEL Classification: C61

Suggested Citation

Wang, Shaun, Optimal Level and Allocation of Cybersecurity Spending: Model and Formula (October 27, 2017). Available at SSRN: https://ssrn.com/abstract=3010029 or http://dx.doi.org/10.2139/ssrn.3010029

Shaun Wang (Contact Author)

Nanyang Technological University ( email )

Nanyang Avenue
Singapore, Singapore 639798
Singapore

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Downloads
427
Abstract Views
1,385
Rank
146,712
PlumX Metrics