Chapter 6

The Point of Diminishing Return on Cyber Risk Investment


This chapter begins with a literature review in the field of economics of information security, challenges for cyber risk management cost optimization, challenges in quantifying security costs, challenges in determining the optimal level of investment in security and risk, and game theory in security investment. It then presents current models for cyber risk cost optimization, cost models for projection, and cost models for investment, i.e., determining how much should be spent on cyber risk, including Return on Security Investment (ROSI), Net Present Value (NPV), and Internal Rate of Return (IRR). The chapter closes with decision models for optimal risk management strategies, ...

Get Digital Asset Valuation and Cyber Risk Measurement now with the O’Reilly learning platform.

O’Reilly members experience live online training, plus books, videos, and digital content from nearly 200 publishers.