Skip to content
Cyber loss exposureDecision comparison

Cybersecurity Investment Prioritization: A FAIR Worked Example

Compare cyber investments within a $100,000 budget. A reproducible FAIR-based example shows why average annual loss and P95 can favor different actions.

Cybersecurity investment prioritization starts with a decision: which action should one company fund, under a defined budget, for a stated loss objective? Ranking findings by severity alone cannot answer that question. You also need implementation costs, required work, assumptions about effectiveness, and evidence for the business loss scenario.

This guide works through the same fictional company and assumptions as Valty’s sample decision memo. You can inspect the inputs and replay the model. The company, costs, and control effects are invented for the demonstration. The results are modeled annual gross loss before insurance, not customer outcomes or savings observed after implementation.

The answer depends on the objective

Example Manufacturing Co. has a $100,000 first-year cyber budget. Its sponsor requires a $15,000 recovery tabletop. That tabletop consumes budget but receives no modeled loss-reduction credit. It is a fictional sponsor policy, not a claim that a regulator or insurer requires it.

Two optional investments are priced: access hardening at $55,000, and recovery capability at $75,000. The totals below include the tabletop. All dollar outputs are rounded from the 50,000-trial fixture.

Scroll sideways to compare all amounts.

OptionFirst-year spendModeled mean annual lossModeled P95 annual loss
Required tabletop only$15,000$791,066$3,512,449
Tabletop + access hardening$70,000$402,566$2,092,283
Tabletop + recovery capability (proposed for P95)$90,000$513,439$1,908,058
Tabletop + both optional actions (over budget)$145,000$257,921$1,285,222

If the objective is the lowest modeled P95 annual loss within budget, recovery is proposed. It leaves $10,000 unallocated. If the objective is the lowest modeled average annual loss within budget, access hardening is preferred and leaves $30,000. Funding both has the lowest values in this table but exceeds the cap by $45,000.

P95 is the annual loss threshold exceeded in about 5% of simulated years. It is not the mean, a maximum loss, or a 95% confidence interval around the estimate. Choosing a tail-loss objective can therefore select a different action than choosing the mean. Agree that objective before looking for a winner.

Download the comparison and assumptions (.csv), or inspect the full sample memo, including its unrounded figures and model provenance.

1. Define the business loss scenario

Describe the critical service, the event that could disrupt it, and the resulting types of loss. Keep the boundary narrow enough to gather evidence and compare actions. For a post-close manufacturer, the decision could concern recovery from a disruptive cyber event affecting a specific production service.

The Open FAIR body of knowledge provides a risk taxonomy and an analysis process for making economic comparisons. In practical terms, separate how frequently a loss event occurs from how much each event costs. A control finding, an attempted attack, and a business loss event are different objects.

For this demonstration, the baseline frequency assumption is 0.8 loss events per year. Mean severity is $1,000,000 per event. The engine draws an annual event count and per-event severities, then adds the losses for each simulated year. It does not treat one scanner finding as one annual loss event.

Record each input’s source, scope, date, and owner. A prior drawn from other companies can inform an assumption, but it should not be labeled observed evidence about this company. The CRQ data requirements checklist shows what to request and how to handle missing inputs.

2. State how each investment changes the assumptions

Access hardening is assumed to reduce frequency from 0.8 to 0.4 events per year while leaving severity unchanged. Recovery capability leaves frequency unchanged and reduces mean severity from $1,000,000 to $650,000. Its modeled severity distribution also becomes narrower: log-sigma changes from 1.2 to 0.6.

These are assumed effects, not measured treatment results. The distributions differ because the assumptions differ. Showing a lower modeled number does not prove the investment will cause that reduction in the company’s actual environment.

The required tabletop receives no modeled benefit. Network segmentation is held outside the priced comparison because its cost and effectiveness evidence are missing. It needs a scoped quote, a tested-coverage report, and an agreed link to this loss scenario. Missing cost must not become $0; missing effectiveness must not become proof of zero benefit.

3. Compare the same costs and financial objects

For every option, use one currency and a matching first-year cost horizon. Include implementation, recurring fees, internal effort, and dependencies where relevant. If an action requires another investment, include the prerequisite rather than comparing the cheaper standalone price.

The table reports annual gross loss and first-year spend in separate columns. The annual loss estimate is not an amount the company necessarily loses next year. It must not be subtracted from reported EBITDA or multiplied by an exit multiple to manufacture a valuation adjustment.

The modeled P95 change from baseline to recovery is about $1.60 million. That is a difference between two modeled quantiles, not expected savings or a return percentage. The modeled mean change is about $278,000, but it is still an estimate based on fictional effectiveness assumptions. A complete economic business case would also consider implementation timing, recurring costs, the evaluation horizon, and whether the effectiveness assumptions are credible.

4. Test whether uncertain evidence could reverse the recommendation

A useful sensitivity test challenges the assumption most likely to change the choice. Suppose recovery lowers mean event severity only to $800,000 rather than $650,000, while retaining the same modeled shape. Its P95 becomes $2,348,379. Access hardening then has a lower modeled P95 at $2,092,283.

That reversal matters more to the approver than another decimal place. The recovery recommendation depends on evidence supporting its assumed effect. Ask for the recovery scope, tested restoration evidence, operational dependencies, and a defensible estimate of the resulting interruption costs. If that evidence is insufficient, obtain it or make the approval conditional.

The sample also tests weaker access-hardening effectiveness. Moving frequency to 0.6 rather than 0.4 events per year increases access’s modeled P95 to $2,832,883; recovery remains preferred for the base P95 objective. The complete methodology distinguishes input uncertainty, modeled outcome variability, and simulation error. A wide loss distribution does not by itself prove that the input assumptions are well calibrated or poorly known.

5. Do not add independently modeled reductions

The combined-action option is a separate model run using both actions’ assumptions. It is not calculated by adding each action’s independent P95 reduction. Percentiles generally do not add that way. Portfolio aggregation also needs a stated treatment of dependence between companies; adding company P95 figures does not produce a portfolio P95.

The sample uses paired random streams to make scenario comparisons less noisy. This numerical technique helps compare the assumptions on consistent terms. It supplies no causal evidence that a control works and does not replace independent calibration against appropriate real-world data.

6. Turn the comparison into an owned decision

A useful funding record states the objective, selected option, cost horizon, required work, alternatives, evidence gaps, and conditions that could change the decision. It also names the company budget approver, execution owner, and next review date.

Use the cybersecurity board report template to present the choice. In a deal workflow, carry unresolved evidence into the investment committee memo and assign it in the 100-day cyber plan. The sponsor coordinates the decision; the company’s authorized approver controls its spend.

After implementation, distinguish three facts: the money actually spent, the control state actually verified, and the modeled financial exposure recomputed from updated assumptions. An approved action is not completed work. Completed configuration work is not necessarily an effective recovery test. A lower modeled loss estimate is not observed avoided loss.

Start with a decision you can inspect

The annual loss expectancy calculator is a useful first arithmetic check: frequency times mean loss per event. It does not simulate a distribution, estimate P95, or recommend an investment. The CRQ software evaluation page shows what to ask about evidence, scenario comparison, approvals, and follow-through.

For a private-equity use case, start with one company and one unresolved funding choice. Explore Valty for PE or request a platform demo. The free 30-minute demo uses illustrative data; company scope, supported workflows, evidence handling, access, and terms are agreed separately before evaluation.

Product context Real application capture · illustrative data
Cybersecurity Investment Prioritization: A FAIR Worked Example product viewOpen full-size product view ↗
Back to blogBrowse category

Put the comparison to work

Carry the evidence into your funding decision.

Use the same assumptions and alternatives in a board report, investment committee memo or first 100-day plan.