Knowing when, where, and how much to invest in cyber defense is a challenge. This tool was created by Juniper Networks and interprets some of the principles of a framework, developed by The RAND Corporation, which aims to provide a new way to think about the various levers organizations should consider across the major areas that they can control in order to reduce the potential costs associated with cybersecurity. The RAND model analyzes a vast array of variables that impact the return on managing risk to investment, in a way that suggests how an organization might balance the four major spend areas: tools, workforce training, BYOD and IoT policy, and network isolation techniques.
Let’s get started.
The percentages below represent possible investment levels for your organization in each of these four areas as a percentage of your overall revenue, by the year 2025. Because these are percentages of your annual revenue, the sum of them will not add up to 100%.
It is plausible that your results may produce some or all zeroes. If this is true for your results, it indicates that baseline efforts are sufficient for the dynamics of your organization.