Cybersecurity Budgeting: A Cyber Risk Perspective. Lawrence A. Gordon, Martin P. Loeb, and Lei Zhou published this work in Transactions on Engineering and Computing Sciences in 2026. They examine how organizations should decide what to budget for cybersecurity. Their economic framework concentrates on investments intended to prevent breaches. By the end, you will understand how the framework connects spending with reduced cyber risk, why it produces an investment ceiling, and why its conclusions require cautious interpretation. Cybersecurity budgeting is advance planning for a budgeting cycle. In its broadest form, it can fund prevention and detection. It can also cover incident response and risk transfer through cyber insurance. This analysis narrows its attention mainly to breach prevention. That creates an awkward economic problem: effective controls prevent losses that otherwise might have happened, so their savings cannot be directly observed. Decision-makers must estimate unstable breach probabilities and the magnitude of potential losses. They must also judge how productive further spending will be while recognizing that each additional investment may reduce less risk than the previous one. The authors organize the budgeting problem around several challenges. One group concerns invisible benefits and uncertainty about incident probability, loss size and control effectiveness. Another covers changing attacks and costs passed to customers or supply-chain partners. A third concerns misaligned spending authority and security responsibility as well as compliance demands. The unanswered research question is whether these challenges really dominate inside organizations or whether other difficulties matter more. The list is therefore a proposed structure for analysis, not an empirically settled ranking of budgeting problems. The Gordon–Loeb Model defines cyber risk as expected loss: the probability of a successful attack multiplied by its potential cost. Security spending is assumed to reduce that probability, and the resulting drop in expected loss represents the investment’s benefit. The economic target is the point where the cost of spending a little more equals the benefit from the additional risk reduction. The model assumes diminishing returns, meaning each extra unit of spending reduces less risk than the previous one. Although the approach is static, its probability, loss, and control-effectiveness estimates can be updated when new information arrives. Within the model, optimal preventive investment has an upper bound based on expected loss. This is not a universal spending target. The analysis also starts from the premise that 100% cybersecurity is infeasible and that overspending can waste scarce resources. Rather than judging security through unobservable savings or budget variance alone, the authors favor risk-based measures such as prevented intrusions, response times and incident severity. They also propose continually revising the model’s estimates as conditions change. Applying the framework begins with estimates of the maximum loss from a successful attack, the current probability of that event, and how additional spending would change that probability. Expected loss before investment is compared with expected loss afterward; the difference is the modeled benefit. Another formulation selects the budget that minimizes the combined cost of remaining expected loss and security spending. These calculations do not eliminate uncertainty. Future incident probabilities are difficult to estimate, historical cyber-loss data are limited, and unusually severe losses may occur more often than a normal bell-shaped distribution would suggest. The authors identify several caveats. The analysis focuses on spending intended to prevent incidents. A fuller budget would also cover response and insurance or other risk transfer. It could also account for possible competitive benefits from security investment. Whether the budgeting challenges identified here are the ones organizations struggle with most remains untested. The static Gordon–Loeb Model also relies on simplifying assumptions and needs empirical data to test future hypotheses. Attacker–defender strategic interactions remain a subject for later research. One step is estimating the maximum potential loss. The expected effect of each proposed investment can also be estimated, and the model’s estimates can be revisited as new information arrives. Performance reviews can emphasize detected or prevented intrusions. Response time and incident severity can also be more informative than budget variance alone. Governance matters because the chief information security officer may carry responsibility for security performance while the chief financial officer controls the budget. The authors propose stronger shared accountability. This could include linking security performance with senior-executive compensation. Gordon, Loeb, and Zhou contribute a risk-based structure for connecting preventive security spending with expected-loss reduction. Security and finance leaders can use it to expose assumptions and discuss diminishing returns. It also offers an alternative to simply adjusting last year’s budget or satisfying compliance checklists. They should not treat the model’s upper bound as universal. Nor should they assume the identified challenges are exhaustive or that the model has been validated across organizations. Treat it as a disciplined starting point. Update its inputs and test its assumptions against operational evidence before turning its outputs into policy.