Your Cybersecurity Budget is a Horse’s Behind
Download resourcesAbout this session
Ira Winkler, Field CISO at CYE and former Chief Security Architect at Walmart, opens with the (largely true) story that railroad cars, and even the space shuttle booster, were sized around a horse-drawn cart's wheelbase, as an analogy for how cybersecurity budgets are set: each year's number is just last year's number plus or minus a bit, not a figure derived from what protecting the organization actually requires. He argues security teams should value what they protect, not the IT hardware they run on, the way operations, safety science and accounting already quantify their own risk in dollars, and that most companies are underinsured and cannot say what a prevented incident was worth. He lays out a risk formula (value times threat times vulnerability over countermeasure), the four standard risk responses (avoid, mitigate, accept, transfer), and the Gordon-Loeb rule of thumb that roughly a third of potential loss is a sane countermeasure spend. He closes with a method for prioritizing countermeasures by return on investment using attack-path choke points, and a CISO's actual walk-in-and-negotiate example: state the exposure created by any budget cut and make the executive sign off on it.
Explore the historical influence of horse-drawn carts on railcar dimensions and how it relates to rigid cybersecurity budgeting. Join this session to learn how to apply machine learning and other mathematical concepts to justify budget allocation, optimize risk, and design effective cybersecurity programs for limited resources.
Key takeaways
- Stop basing next year's cybersecurity budget on last year's plus a percentage; build it from the value of what you are protecting and the loss you are willing to accept.
- Value the organization's transactions and data, not the IT hardware; a security budget framed as '% of IT spend' has no relationship to actual exposure.
- Track the value of incidents you prevented, including statistically avoided increases, so you can present a return-on-investment case, not just a cost line.
- Use a risk formula (threat times vulnerability over countermeasure) and choose your acceptable loss deliberately, rather than defaulting to maximum spend or the point where countermeasure cost equals potential loss.
- When management cuts your requested budget, quantify and present the resulting increase in expected loss so the decision-maker owns the trade-off explicitly.
Speakers

Ira Winkler, CISSP is the Field CISO for CYE Security, former Chief Security Architect at Walmart, and author of You Can Stop Stupid, Security Awareness for Dummies, and Advanced Persistent Security. He is considered one of the world’s most… Read moreRead less
Ira Winkler, CISSP is the Field CISO for CYE Security, former Chief Security Architect at Walmart, and author of You Can Stop Stupid, Security Awareness for Dummies, and Advanced Persistent Security. He is considered one of the world’s most influential security professionals, and has been named a “Modern Day James Bond” by the media. He did this by performing espionage simulations, where he physically and technically “broke into” some of the largest companies in the World and investigating crimes against them, and telling them how to cost effectively protect their information and computer infrastructure. He continues to perform these espionage simulations, as well as assisting organizations in developing cost effective security programs. Ira also won the Hall of Fame award from the Information Systems Security Association, as well as several other prestigious industry awards. CSO Magazine named Ira a CSO Compass Award winner as The Awareness Crusader. He was named 2021 Top Cybersecurity Leader by Security Magazine, and most recently 2022 Cybersecurity Champion of the Year by the Cybersecurity Association of Maryland.
