Spend on resilience, not on fear
I don't try to quantify risk for cybersecurity events. I buy enough insurance to cover a 90th-percentile event — maybe 99th if the company has unlimited liability caps in contract or a large number of mega-caps — and put the rest of my money and time into building resilience into the business.
The number of companies that have failed due to a cybersecurity event is greatly eclipsed by those that failed due to low feature-development velocity. Cybersecurity investments should be based on business priorities and known threats.
> invest the middle
> protect velocity ▋
> Getting to the right "yes"
When security concerns could slow product development, the goal is always to get to the right "yes." I treat each stage as a successively smaller hoop to jump through.
In initial product development, does the effort implicate major legal or regulatory hurdles that would require massive added program expense — e.g., FedRAMP compliance?
Do we need to build in a new language the team isn't familiar with, or on a cloud provider we don't have experience with? Building that expertise takes time and money.
Finally, the deep-dive architecture reviews: do the design patterns match what we know? If not, we bring in 3rd-party experts to help.