Cybersecurity · Cybersecurity · Medium · 25-35 min
How Much Should We Spend on Cybersecurity?
How Much Should We Spend on Cybersecurity? is a medium Cybersecurity cybersecurity case interview that runs 25-35 min. A retailer's board is split: the CISO wants to double the $25M security budget after a peer's breach made headlines; the CFO wants evidence, not fear. A strong answer works through 5 phases: Frame security spend as risk reduction; Map the current posture and the biggest gaps relative to the company's risk profile; Prioritize controls by risk-reduction per dollar rather than buying everything; Consider risk transfer (cyber insurance) and residual-risk acceptance, not just controls; Recommend a spend level and allocation justified by risk, with what 'enough' looks like.
Last updated 2026-09-05
The brief
A retailer's board is split: the CISO wants to double the $25M security budget after a peer's breach made headlines; the CFO wants evidence, not fear. You're asked to frame how much the company should actually invest, where, and how to justify it — without either under-protecting or gold-plating.
How to approach it
- Frame security spend as risk reduction — likelihood × impact across the main threat scenarios
- Map the current posture and the biggest gaps relative to the company's risk profile
- Prioritize controls by risk-reduction per dollar rather than buying everything
- Consider risk transfer (cyber insurance) and residual-risk acceptance, not just controls
- Recommend a spend level and allocation justified by risk, with what 'enough' looks like
What a strong answer does
- Anchors the decision in quantified risk, not headlines or fear
- Prioritizes the highest risk-reduction-per-dollar controls (MFA, patching, backups, segmentation)
- Treats cyber insurance and residual-risk acceptance as part of the portfolio
- Recognizes diminishing returns — more spend isn't linearly more safety
- Ties the recommendation to the company's specific threat profile
Red flags interviewers score down
- Sets the budget by benchmarking a single peer or reacting to a news story
- Recommends buying every tool without prioritizing by risk
- Ignores insurance and residual-risk acceptance entirely
- Can't articulate what level of spend is 'enough' or where returns diminish
Cases are written in each firm's style, written and reviewed by working consultants; they are not the firms' own published cases.