Cybersecurity · Cybersecurity · Medium · 25-35 min

How Much Should We Spend on Cybersecurity?

How Much Should We Spend on Cybersecurity? is a medium Cybersecurity cybersecurity case interview that runs 25-35 min. A retailer's board is split: the CISO wants to double the $25M security budget after a peer's breach made headlines; the CFO wants evidence, not fear. A strong answer works through 5 phases: Frame security spend as risk reduction; Map the current posture and the biggest gaps relative to the company's risk profile; Prioritize controls by risk-reduction per dollar rather than buying everything; Consider risk transfer (cyber insurance) and residual-risk acceptance, not just controls; Recommend a spend level and allocation justified by risk, with what 'enough' looks like.

Last updated 2026-09-05

The brief

A retailer's board is split: the CISO wants to double the $25M security budget after a peer's breach made headlines; the CFO wants evidence, not fear. You're asked to frame how much the company should actually invest, where, and how to justify it — without either under-protecting or gold-plating.

How to approach it

  1. Frame security spend as risk reduction — likelihood × impact across the main threat scenarios
  2. Map the current posture and the biggest gaps relative to the company's risk profile
  3. Prioritize controls by risk-reduction per dollar rather than buying everything
  4. Consider risk transfer (cyber insurance) and residual-risk acceptance, not just controls
  5. Recommend a spend level and allocation justified by risk, with what 'enough' looks like

What a strong answer does

  • Anchors the decision in quantified risk, not headlines or fear
  • Prioritizes the highest risk-reduction-per-dollar controls (MFA, patching, backups, segmentation)
  • Treats cyber insurance and residual-risk acceptance as part of the portfolio
  • Recognizes diminishing returns — more spend isn't linearly more safety
  • Ties the recommendation to the company's specific threat profile

Red flags interviewers score down

  • Sets the budget by benchmarking a single peer or reacting to a news story
  • Recommends buying every tool without prioritizing by risk
  • Ignores insurance and residual-risk acceptance entirely
  • Can't articulate what level of spend is 'enough' or where returns diminish

Cases are written in each firm's style, written and reviewed by working consultants; they are not the firms' own published cases.

More Cybersecurity cases