Maryland Smith Research / September 10, 2026

Smith Researchers Produce New Framework for Smarter Cybersecurity Budgeting

Glowing lightbulb labeled “RISK” over an open financial report, with a 2027 risk-mitigation timeline, progress bars and rising and falling arrows.
University of Maryland researchers apply the Gordon-Loeb Model to AI-driven cyberthreats, recommending risk-based cybersecurity budgets generally capped at 37% of expected losses. The framework lets executives update attack probabilities, potential losses and investment effectiveness as threats and conditions evolve rapidly.

The study applies the Gordon-Loeb Model to today’s AI‑driven threat landscape, giving executives a rigorous, risk‑based benchmark for setting cybersecurity budgets.

As cyberattacks grow in frequency, sophistication and financial impact—accelerated further by advances in artificial intelligence—organizations face a deceptively simple but increasingly urgent question: How much should we spend on cybersecurity?

New research from the University of Maryland Robert H. Smith School of Business provides an answer.

Published in Transactions on Engineering and Computing Sciences, “Cybersecurity Budgeting: A Cyber Risk Perspective is co‑authored by Lawrence A. Gordon, EY Alumni Professor of Managerial Accounting and Information Assurance; Martin P. Loeb, professor emeritus of accounting and information assurance; and Lei Zhou, research scholar and academic director of Smith’s MS in Accounting program.

The paper builds on the influential Gordon-Loeb Model, long considered a foundational framework for determining optimal cybersecurity investment.

“Given that AI has increased the number and magnitude of cyberattacks, cybersecurity has become even more important today than it was in the pre‑AI world,” says Gordon. “Organizations in both the private and public sectors are grappling with the challenge of determining how much they should budget for cybersecurity‑related activities.”

Risk‑Based Approach for Modern Cyber Threats
The authors argue that cybersecurity budgeting must shift from a compliance‑driven or cost‑avoidance mindset to a cyber‑risk perspective—a view directly aligned with the U.S. Securities and Exchange Commission’s 2023 rules on cybersecurity risk management and governance.

Their framework addresses eight persistent challenges organizations face when setting cybersecurity budgets, including:

  • Invisible cost savings from prevented attacks
  • Extreme uncertainty in estimating breach probability
  • Difficulty quantifying potential losses, especially catastrophic ones
  • Measuring the productivity of cybersecurity investments
  • Rapid growth in attack sophistication
  • Externalities that spill across supply chains and customers
  • Misalignment between budget authority (often CFOs) and cybersecurity responsibility (CISOs/CIOs)
  • Cybersecurity disclosure rules that create added compliance requirements for publicly traded companies

By expressing cyber risk in simple mathematical terms—expected loss equals the probability of a successful attack multiplied by the potential loss—the Gordon-Loeb Model helps organizations identify how much they should ideally invest in cybersecurity. The authors show that this optimal amount generally should not exceed 37% of the expected loss, giving executives a practical, economically grounded benchmark to guide their budgeting decisions.

Dynamic Framework for a Dynamic Threat Landscape
Although the model is static, the authors emphasize its adaptability. Key parameters—probability of attack, potential loss, and the effectiveness of security investments—can be continuously updated as new information emerges. This makes the framework well‑suited for today’s fast‑changing digital environment, where AI‑enabled threats evolve rapidly and cybersecurity budgets must remain flexible.

The paper also highlights how incorporating externalities—the spillover costs borne by customers, partners, and even national security—can help organizations invest at a more socially efficient level, addressing chronic underinvestment in cybersecurity.

Implications for Leaders
For executives, the research offers actionable insights:

  • Cybersecurity budgeting should be integrated into enterprise risk management, not treated as a technical silo.
  • Risk‑based metrics—not traditional accounting variances—are more appropriate for evaluating cybersecurity performance.
  • Linking cybersecurity outcomes to senior executive compensation, as some firms have begun to do, can help resolve incentive misalignment.
  • AI and data analytics can strengthen real‑time estimation of cyber risk and improve budget responsiveness.

A Smith Legacy in Cybersecurity Economics
As the Gordon-Loeb Model has shaped cybersecurity investment thinking for more than two decades, cited widely by academics, practitioners, and policymakers, this new paper, Gordon says, “extends that legacy, offering organizations a rigorous, economically grounded way to navigate one of the most complex budgeting challenges of the digital era.”

Read the research, “Cybersecurity Budgeting: A Cyber Risk Perspective.”

Media Contact

Greg Muraski
Media Relations Manager
301-405-5283  
301-892-0973 Mobile
gmuraski@umd.edu 

Get Smith Brain Trust Delivered To Your Inbox Every Week

Business moves fast in the 21st century. Stay one step ahead with bite-sized business insights from the Smith School's world-class faculty.

Subscribe Now

Read More Research

Back to Top