Cost-benefit analysisis the most effective and practical approach for evaluating the value of cybersecurity investments. It allows comparison of expected benefits (risk reduction, incident cost avoidance, compliance) against the costs (investment, operations).
While NPV and IRR are solid financial tools, they are better suited to revenue-generating projects. Cybersecurity's value is often intangible or indirect, making a straightforwardcost-benefit frameworkmore suitable.
[Reference:, CGEIT Review Manual: Domain 4 – Risk Optimization and Business Case Justification, COBIT 2019: EDM02 (Ensure Benefits Delivery)., , , , ]
Submit