Download presentation
Presentation is loading. Please wait.
Published byHarjanti Tedja Modified over 5 years ago
1
Gordon-Loeb Model for Cybersecurity Investments*
Benefits and Costs of an Investment in Cyber/Information Security* Insights from the Gordon-Loeb Model Key components of optimal amount to invest: Potential losses from cybersecurity breach (cost savings or lost benefits) Vulnerabilities (including threats) or probability of breach Productivity of investments. Optimal level of cybersecurity investments does not always increase with level of vulnerability. Firms should generally invest β€ 37% of expected loss (i.e., invest, but invest wisely). BBB Recommends the Gordon-Loeb Model 2017 U.S. Better Business Bureau (BBB) report recommends the Gordon-Loeb Model as "...a useful guide for organizations trying to find the right level of cybersecurity investment." $ ππ³ Expected Benefits of Investment =(πβπΊ[π,π])π³ π Level of investment in information security ππ π π β Costs of Investment π β (π) < π π ππ³ π£β Vulnerability (Probability of security breach) πΏβ Potential Loss π£πΏβ Expected Loss π§β Level of Investment π§ β β Optimal Investment Level π[π§,π£]β Revised v after z (Revised probability of breach) Benefits are increasing at a decreasing rate. 100% security is not possible. How Can Organizations Use the Gordon-Loeb Model? Step 1. Estimate the potential loss (L) from a cybersecurity breach for each set of information (information segmentation is important). Step 2. Estimate the probability that an information set will be breached, by examining its vulnerability (π£) to attack. Step 3. Create a grid with all the possible combinations of the first two steps, from low value, low vulnerability, to high value, high vulnerability. Step 4. Focus spending where it should reap the largest net benefits based on productivity of investments. See YouTube Video explaining the Gordon-Loeb Model: *Gordon, L.A. and M.P. Loeb, βThe Economics of Information Security Investment,βΒ ACM Transactions on Information and System Security, November 2002. *Gordon, L.A., M.P. Loeb, and L. Zhou,Β βInvesting in Cybersecurity: Insights from the Gordon-Loeb Model,βΒ Journal of Information Security, March 2016.
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.