The Cost of a Security Incident vs. the Cost of Prevention: The Maths CISOs Use
Sep 08, 2026Every security budget conversation eventually comes down to the same question: is this spend worth it? Founders and finance leaders are right to ask it. The honest answer requires putting a number on both sides of the equation, not just the side that's easy to see.
The cost of an incident
The direct costs are the ones everyone thinks of first: detection, containment, forensic investigation, legal advice, regulatory notification, and remediation. IBM's 2025 Cost of a Data Breach Report puts the global average cost of a breach at $4.44 million. That figure moves depending on sector, size and geography, and any business quoting a number to a board or an insurer should check the latest edition of that report rather than relying on a figure that ages quickly.
The indirect costs are usually larger and far less visible in advance:
- Customer churn. Customers who learn their data was exposed don't always leave loudly. Many simply don't renew.
- Deal delays. An incident disclosed during due diligence, whether for a sale, a funding round, or a large contract, tends to stall the process while the other side reassesses risk.
- Insurance and financing costs. Premiums rise, and some insurers decline to renew cover at all following a claim.
- Leadership time. Weeks of senior attention diverted from growth into incident response and cleanup, at exactly the moment competitors keep moving.
The cost of prevention
Prevention doesn't need to mean matching a large enterprise security budget. A fractional security leader, sized correctly for an £2-20m revenue business, typically costs a small fraction of a single incident, spread across a year rather than absorbed in one shock. Prevention spend also compounds in the other direction: a control put in place this year keeps paying off every year after, rather than being a one-off cost.
The maths
The comparison CISOs actually use is closer to expected value than a simple side-by-side. It's roughly: probability of an incident in a given year, multiplied by the likely cost if one happens, compared against the annual cost of the controls that reduce that probability. Run over three to five years rather than a single budget cycle, the probability of at least one incident compounds, and the case for consistent prevention spend gets stronger every year it's deferred.
The businesses that get this maths right treat security as an ongoing cost of doing business at scale, not a one-off project to tick off. That reframing, from "can we afford this" to "what does the exposure actually cost us if we don't", is usually the point where a serious conversation about security leadership starts.