Lessons · Cybersecurity · is the control worth it
Is the control worth it?
A control is worth buying when the yearly loss it removes is bigger than what it costs: value = annualised loss expectancy before, minus annualised loss expectancy after, minus the yearly cost of the control.
Hone is a place to practise a career, one idea a day. This is one of its lessons, written out in full and free to read without an account.
What it is for
The vendor says their product stops ransomware. The question that survives the meeting is what it costs, what the yearly loss is now, and what the yearly loss would be after. Three numbers and one subtraction turns a sales pitch into a decision.
How to think about it
Work out the annualised loss expectancy as it stands. Then the annualised loss expectancy with the control in place, which usually means a smaller rate rather than a smaller loss. Subtract both the remaining loss and the cost. A negative answer is an answer: it says do not buy it.
Worked example
value = ALE before - ALE after - annual costThe one line.
value = 40,000 - 9,000 - 12,000 = 19,000 per yearWorth it, by 19,000 dollars a year.
A control rarely takes the loss to zero, so the middle term is rarely 0Be honest about what is left over.
A negative value means the control costs more than it savesWhich is a good reason to spend the money on a different control.
Your turn
An ALE of 30,000 dollars falls to 5,000 dollars with a control costing 9,000 dollars a year. Write the line that gives its value.
value = 30000 - 5000 -
Solve one, graded on the server
The trap
Counting the purchase price and forgetting the running cost. Licences, the person who watches it and the training are all part of the yearly number.