As cyberattacks grow in frequency, sophistication and financial impact—accelerated further by advances in AI—organizations face a deceptively simple but increasingly urgent question: How much should they spend on cybersecurity?
New research co-authored at the University of Maryland offers a clear answer: Optimal cybersecurity spending generally should not exceed 37% of the expected loss from a potential breach.
The study, published in the journal Transactions on Engineering and Computing Sciences, updates and expands on the Gordon-Loeb Model—the foundational framework for cybersecurity investment created more than two decades ago by UMD’s Lawrence Gordon and Martin Loeb, who both currently hold affiliate appointments in the University of Maryland Institute for Advanced Computer Studies (UMIACS).
The study was co-authored by Gordon, a professor of managerial accounting and information assurance; Loeb, a professor emeritus of accounting and information assurance; and Lei Zhou, a research scholar and academic director of the Robert H. Smith School of Business’ Master of Science in Accounting program. The new work addresses how their economic model must evolve alongside modern threat vectors and U.S. Securities and Exchange Commission disclosure rules.
Gordon said the rapid proliferation of AI has made establishing clear budget benchmarks far more urgent for leaders in both the public and private sectors.
“Given that AI has increased the number and magnitude of cyberattacks, cybersecurity has become even more important today than it was in the pre-AI world,” he said. “Organizations are grappling with the challenge of determining how much they should budget for cybersecurity-related activities.”
The researchers argue that organizations have long struggled with cybersecurity budgeting because they treat it as a compliance mandate or an isolated technical expense. Expressing risk mathematically—where expected loss equals the probability of an attack multiplied by the potential loss—gives executives an economically grounded ceiling. Because spending beyond the 37% threshold yields diminishing returns in risk reduction, the model can help companies avoid overinvesting in ineffective defenses.
At the same time, the authors found that traditional budgeting methods fail to capture the full scope of cyber risk. Calculating return on investment is notoriously difficult when success means an attack never occurred or when catastrophic losses are hard to quantify in advance. Compounding the issue, budget authority often sits with CFOs, while operational responsibility rests with CISOs or CIOs, creating competing internal incentives.
Furthermore, data breaches frequently spill over to affect customers, supply chain partners and national security. Companies that ignore these external impacts tend to chronically underinvest in baseline protection.
To address these friction points, the framework is designed to adapt dynamically. Parameters such as breach probability and potential loss can be continuously updated as new security data emerges. The researchers recommend integrating cybersecurity directly into enterprise risk management, aligning executive compensation with cyber-risk metrics and using real-time data analytics to keep budgets flexible.
—News brief adapted from an article by the Robert H. Smith School of Business