Security spending is usually argued qualitatively. This threat feels serious, that control feels prudent, and the budget goes to whoever makes the case most forcefully. The quantitative alternative is unglamorous and much harder to argue with: estimate the annualised loss for each threat, estimate what a control reduces it to, subtract the cost of the control, and read the answer.
Run against six threat and control pairs for a regional retailer with a $30,000 budget, that method produced a result nobody asks for: one of the six controls was worth less than it cost, and the recommendation was to leave the risk unmitigated.
The setting was a supplied teaching case, a fictional retailer in regional Victoria holding $8 million of stock and running an online sales channel alongside its shopfront, carrying six distinct exposures from bushfire through ransomware to physical break-ins and device loss. The task was to decide which controls a risk-neutral firm should buy.
“Risk-neutral” is the load-bearing word. It means the firm values a certain loss of $1,000 exactly as it values a 10% chance of losing $10,000, so every decision reduces to expected value. That assumption is what makes the analysis tractable, and being explicit about it is what makes the analysis honest, because a real business is rarely risk-neutral about the tail. It is one thing to accept an expected loss of $800 a year on stolen laptops. It is another to be indifferent between certainty and a small chance of catastrophic stock loss.
The second constraint was the budget. Six controls, five of them worth having, and not enough money for all five. The recurring cost of every positive control comes to $32,200 against $30,000 available, so something has to be cut, and the two obvious ways to rank the candidates, efficiency per dollar and absolute impact, do not have to agree with each other.
They did agree here, which is itself the result worth reporting. Ranked by ROI and ranked by net benefit, the same four controls come out on top, so the prioritisation was not a judgement call and did not need to be dressed up as one. What the annualised figures conceal is a cash problem: the recommended set costs $29,700 a year on paper but $68,500 in the first year, because most of it is one-off capital being depreciated over five years. That gap is the part of the analysis a board would actually have needed.
In brief
- Six threat and control pairs modelled through ALE before and after, with annual savings, net benefit and ROI for each
- Five controls returned positive net benefit totalling $265,145 a year; one returned -$1,400 and was recommended against
- Highest efficiency: software updates at 15,614% ROI, $700 annual cost against $110,000 of avoided ransomware loss at 24 incidents a year
- Highest absolute impact: bushfire insurance at $120,000 net benefit, protecting $8 million of stock against a potential $4.8 million single-event loss
- ROI ranking and net-benefit ranking selected an identical top four, removing the need for a prioritisation judgement
- Budget constraint binds at $30,000 against $32,200 for all positive controls; recommended set costs $29,700
- Year-one cash requirement of $68,500 against $30,000 available identified as a phasing problem the annualised figures conceal
- Analysis stated as risk-neutral throughout, with the tail-risk caveat recorded rather than assumed away
The report as submitted
Executive summary
The retailer faces six identified security threats with combined expected annual losses of $434,700. This report analyses each threat using quantitative cost-benefit methodology and recommends control implementation prioritised within a $30,000 budget.
Five of six proposed controls return positive net benefit. Software and operating system updates are the most urgent, addressing a ransomware exposure running at 24 attacks a year at an ROI of 15,614%. Combined with bushfire insurance (600% ROI, highest absolute benefit), the server room upgrade (483% ROI) and firewall installation (191.67% ROI), these four controls cost $29,700 a year and generate $263,045 in net annual benefit, an 81% reduction in expected losses.
Immediate implementation of software updates ($3,500 one-off) and bushfire insurance ($20,000 annual) is recommended, followed by physical and network security upgrades within three months. The deferred antivirus control and the rejected CCTV installation can be reconsidered in future budget cycles.
1. Introduction
The client is a retail company operating in regional Victoria with both physical and online sales channels. It faces multiple security threats that could affect business operations and financial performance. This report analyses six identified threats using quantitative risk assessment methods and provides evidence-based recommendations for prioritising security investment.
The cybersecurity picture in Australia is difficult. Recent data indicates that 59% of Australian organisations detect business-interrupting security breaches at least monthly (Loiterton 2018), while the average cost of a successful cyberattack reaches USD 200,000 (Dobran 2019). For small and medium enterprises, effective risk management is critical to business continuity.
This analysis evaluates six threat and control pairs against an available budget of $30,000. Using established risk assessment frameworks (National Institute of Standards and Technology 2011), the report calculates expected losses, control costs and return on investment for each scenario. Key metrics are Single Loss Expectancy (SLE), Annual Loss Expectancy (ALE) and net benefit. All recommendations assume risk-neutral decision-making, where a control is implemented if it generates positive net benefit (Shortridge 2016).
2. Methodology
The analysis employs quantitative risk assessment based on expected value calculations. The method follows NIST SP 800-39 guidelines (National Institute of Standards and Technology 2011) and aligns with the Business Queensland (2016) risk assessment framework, which establishes that risk equals likelihood multiplied by impact. Combining a federal information security standard with an Australian government risk management practice gives the analysis two independent methodological anchors rather than one.
Formulas used:
- Single Loss Expectancy, the expected loss from one incident:
SLE = Asset Value (AV) × Exposure Factor (EF) - Annual Loss Expectancy, the expected annual loss from a threat:
ALE = SLE × Annual Rate of Occurrence (ARO) - Annual Control Cost: the annual price if the control recurs, otherwise the one-off price divided by five years
- Net benefit, the true value after control costs:
Net Benefit = (ALE_before - ALE_after) - ACC - Return on investment:
ROI = (Net Benefit ÷ ACC) × 100%
Decision criterion. For a risk-neutral organisation, implement controls where net benefit is greater than zero. This avoids the emotional bias of loss aversion, which causes organisations to overspend on vivid risks and underspend on dull ones (Heshmat 2018; Shortridge 2016). One-off costs are depreciated linearly over five years so that they can be compared fairly against recurring annual costs.
3. Threat and control analysis
3.1 A worked example: server room break-ins and a security upgrade
The server room case is the one that exercises the whole method, because the control changes both how often the incident happens and how much it costs when it does. The asset is $1,000,000 of goodwill and data. Standard door security allows a break-in every four years, damaging 18% of that value. A $30,000 upgrade reduces the frequency to once every fifteen years and the damage to 15%.
Step 1 SLE before = AV × EF_before = $1,000,000 × 0.18 = $180,000 per incident
Step 2 ALE before = SLE × ARO = $180,000 × 0.25 = $45,000 per year
Step 3 ACC = $30,000 ÷ 5 yr = $6,000 per year
Step 4 SLE after = AV × EF_after = $1,000,000 × 0.15 = $150,000 per incident
Step 5 ALE after = SLE × ARO = $150,000 × 0.0667 = $10,005 per year
Step 6 Savings = $45,000 - $10,005 = $34,995 per year
Step 7 Net benefit = $34,995 - $6,000 = $28,995 per year
Step 8 ROI = ($28,995 ÷ $6,000) × 100 = 483%
Two things in that sequence are worth pausing on. The exposure factor moves only three percentage points, from 18% to 15%, and contributes almost nothing to the result. Nearly all of the $34,995 saving comes from the annual rate of occurrence falling from 0.25 to 0.0667. When a control both reduces frequency and reduces severity, the frequency term is usually the one doing the work, and it is also the one estimated least confidently. Second, the $30,000 price tag becomes $6,000 in the comparison table only because it is depreciated over five years. That is the correct way to compare it against an insurance premium, and it is also the step where a genuine cash constraint disappears from view.
3.2 The remaining five pairs
Bushfire and an insurance policy. $8,000,000 of stock, severe bushfire once every 20 years (ARO 0.05), 60% of stock lost without cover and 25% with it. ALE before $240,000, ALE after $100,000, control cost $20,000 a year. Net benefit $120,000, ROI 600%. Implement. Note that insurance does not change the frequency at all, only the exposure factor, which is the opposite of the server room case.
Denial of service and a firewall. $3,500 damage per attack, three attacks a year falling to one every two years. ALE before $10,500, ALE after $1,750, control cost $15,000 one-off, so $3,000 a year. Net benefit $5,750, ROI 191.67%. Implement.
Viruses and antivirus software. $600 a month of losses falling to $300 a month. ALE before $7,200, ALE after $3,600, control cost $2,500 a year. Net benefit $1,100, ROI 44%. Implement, but this is the marginal case and the first to be cut.
Ransomware and software updates. Two attacks a month, 24 a year, at $5,500 each, falling to one every three months. ALE before $132,000, ALE after $22,000, control cost $3,500 one-off, so $700 a year. Net benefit $109,300, ROI 15,614%. Implement immediately. Ransomware frequently results in complete operational shutdown (Microsoft n.d.), and 90% of security breaches stem from human error rather than technical sophistication (Loiterton 2018), which is a plausible explanation for why patches go unapplied and the attack rate is this high.
Device loss and CCTV. One $400 device lost or stolen every six months, falling to one every two years. ALE before $800, ALE after $200, control cost $10,000 one-off, so $2,000 a year. Net benefit -$1,400, ROI -70%. Do not implement.
4. Comparative analysis
4.1 Summary of results
| Threat and control | Annual cost | ALE before | ALE after | Net benefit | ROI |
|---|---|---|---|---|---|
| Ransomware, software updates | $700 | $132,000 | $22,000 | $109,300 | 15,614% |
| Bushfire, insurance | $20,000 | $240,000 | $100,000 | $120,000 | 600% |
| Break-ins, server room upgrade | $6,000 | $45,000 | $10,005 | $28,995 | 483% |
| DoS, firewall | $3,000 | $10,500 | $1,750 | $5,750 | 191.67% |
| Virus, antivirus | $2,500 | $7,200 | $3,600 | $1,100 | 44% |
| Device loss, CCTV | $2,000 | $800 | $200 | -$1,400 | -70% |
Five of six controls return positive net benefit. Implementing all five would generate $265,145 of annual net benefit, cutting total expected losses from $434,700 to $137,355, an 83% reduction.
4.2 Two rankings, and why both were produced
ROI and net benefit answer different questions. ROI measures efficiency per dollar committed, which matters when capital is constrained. Net benefit measures absolute impact, which matters when the exposure is large enough to threaten the business. Ranked by ROI the order is software updates, insurance, server room, firewall, antivirus. Ranked by net benefit it is insurance, software updates, server room, firewall, antivirus. Only the top two swap places, and both rankings select the same top four.
That convergence is worth stating plainly rather than glossing over. When efficiency and impact agree, the prioritisation is not a judgement call, and the analyst should say so instead of manufacturing a tiebreak.
4.3 Budget allocation
The total recurring cost of all positive controls, $32,200, exceeds the available budget of $30,000 by $2,200. Implementing the top four costs $29,700 a year, stays within budget, and captures $263,045 of the $265,145 available, which is 99.2% of the total value. Antivirus is deferred, at a cost of $1,100 of forgone net benefit.
The awkward part sits underneath the annualised figures. The $29,700 is a depreciated number. The actual year-one cash requirement is $48,500 of one-off capital (software updates $3,500, server room $30,000, firewall $15,000) plus the $20,000 insurance premium, which is $68,500 against $30,000 available. Depreciated annual cost and cash out the door are different numbers, and a recommendation quoting only the first is not implementable. Phasing resolves it: year one takes software updates and insurance at $23,500, year two takes the server room and firewall at $45,000.
5. Recommendations
Critical priority: software and operating system updates. This control requires immediate implementation. The business is currently absorbing 24 ransomware attacks a year and $132,000 of annual loss, which is an active crisis rather than a latent risk. The control costs $700 a year against $109,300 of net benefit. Every dollar spent returns roughly $156 of risk reduction. Nothing else in the analysis is close.
High priority: bushfire insurance. The highest absolute net benefit at $120,000 a year and 600% ROI. Regional Victoria’s bushfire exposure creates the potential for a $4.8 million single-event loss that could close the business. The $20,000 premium should be bound before the summer season rather than at the next budget review.
High priority: server room upgrade and firewall. Both have strong financial cases at 483% and 191.67%. The server room protects $1 million of goodwill and data that cannot be replaced; the firewall protects the online sales channel. Combined annual cost of $9,000.
Implementation sequence. Phase 1, immediately: software updates and bushfire insurance. Phase 2, months one to three: server room upgrade and firewall. Phase 3, next budget cycle: antivirus. Not recommended: CCTV.
Do not buy the CCTV. The device-loss exposure is $800 a year. The control costs $2,000 a year and reduces the exposure to $200. There is no configuration of these numbers in which the purchase makes the firm better off. The correct action is to absorb the $800 loss. The value of running the analysis is having the evidence to decline a control that sounds obviously sensible.
This level of spending is consistent with peer behaviour: 69% of firms are expanding cybersecurity budgets, with 85% planning increases of up to 50% (Dobran 2019).
6. Conclusion
Combined expected annual losses without controls exceed $434,000. Implementing the four recommended controls within the $30,000 budget generates $263,045 of annual net benefit and reduces expected losses by 81%.
Software updates are the most urgent priority by a wide margin. Combined with insurance, the server room upgrade and the firewall, the recommended set covers physical, digital and operational exposure. The one-off capital component should be phased across two years, because the annualised figures understate the first-year cash requirement by $38,500.
Two caveats belong on the record. The analysis is risk-neutral throughout, which is a modelling convenience rather than a description of how this business would actually feel about losing $4.8 million of stock in one afternoon. And every ALE here rests on an estimated rate of occurrence; the sensitivity of the server room result to that single parameter is a fair illustration of how much weight those estimates carry.
References
Business Queensland 2016, ‘Identifying business risk’, Queensland Government, 26 June, viewed 10 November 2025, https://www.business.qld.gov.au/running-business/protecting-business/risk-management/identifying-risk
Dobran, B 2019, ‘17 Types of Cyber Attacks to Secure Your Company From in 2019’, Phoenix NAP Global IT Services, blog post, 21 February, viewed 10 November 2025, https://phoenixnap.com/blog/cyber-security-attack-types
Heshmat, S 2018, ‘What is Loss Aversion?’, Psychology Today, blog post, 8 March, viewed 10 November 2025, https://www.psychologytoday.com/au/blog/science-choice/201803/what-is-loss-aversion
Loiterton, G 2018, ‘Understanding your Cybersecurity Loss Aversion’, LinkedIn, 5 August, viewed 10 November 2025, https://www.linkedin.com/pulse/understanding-your-cybersecurity-loss-aversion-george-loiterton/
Microsoft n.d., What is a Cyberattack?, Microsoft, viewed 10 November 2025, https://www.microsoft.com/en-us/security/business/security-101/what-is-a-cyberattack
National Institute of Standards and Technology 2011, Information Security, NIST Special Publication 800-39, US Department of Commerce, March, pp. 9-22, viewed 10 November 2025, https://csrc.nist.gov/publications/detail/sp/800-39/final
Shortridge, K 2016, ‘Behavioral Models of InfoSec: Prospect Theory’, Medium, 1 August, viewed 10 November 2025, https://medium.com/threat-intel/prospect-theory-c6bb49902768
Companion report: the same method against a real breach
The third assessment in the same course applied the method at enterprise scale to a real organisation with a public incident record: Medibank Private, Australia’s largest private health insurer, breached in October 2022 with 9.7 million customer records taken and direct costs above $125 million.
Critical issue
The finding was that the breach was a governance failure rather than a technical one. The attack path is documented: a contractor’s admin credentials were saved in a personal browser, synced to a personal device, harvested by malware, and used to log into the VPN, which did not require multi-factor authentication, giving admin-level access to most systems. Endpoint alerts fired on 24 and 25 August 2022 and were not properly triaged; roughly 520 GB left the network over the following weeks; the security operations centre finally investigated a critical alert on 11 October, seven to eight weeks after the first warning.
Four separate control layers had to fail for that to happen: no policy prohibiting credential storage in personal applications, no MFA on VPN, contractor privileges beyond legitimate need, and monitoring that produced alerts nobody acted on. The single critical issue underneath all four is that third-party privileged access was treated as an extension of internal access rather than as an elevated risk category, which is precisely what both APRA CPS 234 and ISO 27001 require organisations not to do.
Quantitative analysis
Loss expectancy was modelled across five scenarios using the FAIR-ROSI approach (He, Xin & Luo 2025), which pairs the FAIR framework with return-on-security-investment metrics so that technical risk assessment produces a number a CFO can act on.
| Risk scenario | Asset value | EF | SLE | ARO | ALE before | ALE after | Reduction |
|---|---|---|---|---|---|---|---|
| Credential-based breach | $1.94B | 6.5% | $126M | 0.8 | $100.8M | $20.2M | 80% |
| Ransomware and extortion | $500M | 25% | $125M | 0.3 | $37.5M | $11.3M | 70% |
| Insider data theft | $970M | 5% | $48.5M | 0.4 | $19.4M | $5.8M | 70% |
| Third-party compromise | $200M | 30% | $60M | 0.5 | $30M | $7.5M | 75% |
| DLP failure and exfiltration | $1.94B | 2% | $38.8M | 0.6 | $23.3M | $4.7M | 80% |
| Total | $211M | $49.5M | 76.5% |
Values are estimated from the incident record, healthcare sector benchmarks and FAIR distributions validated by Wang, Neil and Fenton (2020). The residual $49.5 million sits just inside the organisation’s stated tolerance of $50 million in annual cyber losses, which is a narrow enough margin to be worth flagging rather than celebrating. Zero-day vulnerabilities, state-sponsored actors and residual human error are the components that cannot be driven out (Prümmer, van Steen & van den Berg 2025).
Recommendations and cost
| Initiative | Cost | ALE reduction | ROI |
|---|---|---|---|
| Third-party risk controls | $2-3M | $82M | 2,733% |
| Security culture programme | $1-1.5M | $13.6M | 907% |
| Training enhancement | $0.5-1M | $8M | 800% |
| Adaptive frameworks, year 1 | $3-5M | $25M | 500% |
| Incident learning programme | $0.5M | $15M | 3,000% |
| Total year 1 | $7-11M | $143.6M | 1,305% |
The short-term set (0 to 6 months) is mandatory MFA for all third-party access, security assessments of every vendor with system access, a prohibition on credential storage on personal devices, and user activity monitoring for privileged third-party accounts (Inayat et al. 2024). Alongside that, security culture work with executive sponsorship, clear responsibilities and blame-free reporting (Colabianchi et al. 2025), and training redesigned as quarterly micro-learning with phishing simulations rather than an annual module, which is the format the evidence supports (Prümmer, van Steen & van den Berg 2025).
The long-term set (6 to 24 months) is continuous rather than annual risk assessment with threat intelligence integrated, on the grounds that adaptive strategies outperform fixed ones (Al-Dosari & Fetais 2023) and that standard frameworks need tailoring to organisational context rather than adoption wholesale (Barraza de la Paz et al. 2023), with NIST SP 800-30 (National Institute of Standards and Technology 2012) as the reference method for the assessments themselves. Alongside that: formal post-incident review with a knowledge repository and tracked remedial actions, healthcare-specific data loss prevention rules and standards for internet-connected medical devices (Ksibi, Jaidi & Bouhoula 2023; Aldosari 2025), and baseline measurement of security culture using a validated instrument so that improvement can be evidenced.
Two pieces of context justify weighting the recommendations towards people rather than tools. Tolah, Furnell and Papadaki (2021) found 44% of breaches involve insiders; Colabianchi et al. (2025) report 72% involve human elements. And the February 2024 Change Healthcare attack, which affected more than 100 million people and cost upwards of $872 million, ran on the same pattern of credential-based access into a claims processor, which suggests the problem is structural to the sector rather than particular to one insurer. Patterson, Nurse and Franqueira (2023) caution that most organisations fail to learn from incidents because investigations stay superficial and remedial actions are never evaluated, which is the failure mode this set of recommendations is built to avoid.
References for the companion report
Aldosari, B. 2025, ‘Cybersecurity in healthcare: new threat to patient safety’, Cureus, vol. 17, no. 5, article e83614.
Al-Dosari, K. & Fetais, N. 2023, ‘Risk-management framework and information-security systems for small and medium enterprises (SMEs): a meta-analysis approach’, Electronics, vol. 12, no. 17, article 3629.
Barraza de la Paz, J.V., Rodríguez-Picón, L.A., Morales-Rocha, V. & Torres-Argüelles, S.V. 2023, ‘A systematic review of risk management methodologies for complex organizations in Industry 4.0 and 5.0’, Systems, vol. 11, no. 5, article 218.
Colabianchi, S., Costantino, F., Nonino, F. & Palombi, G. 2025, ‘Transforming threats into opportunities: the role of human factors in enhancing cybersecurity’, Journal of Innovation & Knowledge, vol. 10, no. 4, article 100695.
He, Y., Xin, T. & Luo, C. 2025, ‘Enhancing cybersecurity investment with FAIR-ROSI: a responsible cybersecurity approach to digital society’, Information Systems Frontiers, vol. 27, no. 4, pp. 1123-1145.
Inayat, U., Farzan, M., Mahmood, S., Zia, M.F., Hussain, S. & Pallonetto, F. 2024, ‘Insider threat mitigation: systematic literature review’, Ain Shams Engineering Journal, vol. 15, no. 12, article 103068.
Ksibi, S., Jaidi, F. & Bouhoula, A. 2023, ‘A comprehensive study of security and cyber-security risk management within e-health systems: synthesis, analysis and a novel quantified approach’, Mobile Networks and Applications, vol. 28, no. 1, pp. 107-127.
National Institute of Standards and Technology 2012, Guide for Conducting Risk Assessments, NIST Special Publication 800-30 Revision 1, US Department of Commerce, Gaithersburg, MD.
Patterson, C.M., Nurse, J.R.C. & Franqueira, V.N.L. 2023, ‘Learning from cyber security incidents: a systematic review and future research agenda’, Computers & Security, vol. 132, article 103309.
Prümmer, J., van Steen, T. & van den Berg, B. 2025, ‘Assessing the effect of cybersecurity training on end-users: a meta-analysis’, Computers & Security, vol. 150, article 104206.
Tolah, A., Furnell, S.M. & Papadaki, M. 2021, ‘An empirical analysis of the information security culture key factors framework’, Computers & Security, vol. 108, article 102354.
Wang, J., Neil, M. & Fenton, N. 2020, ‘A Bayesian network approach for cybersecurity risk assessment implementing and extending the FAIR model’, Computers & Security, vol. 89, article 101659.