MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-08 · via Help Net Security

Qualys executive outlines how CISOs can attach financial value to security choices

Image via Help Net Security
Image via Help Net Security

Ivan Milenkovic of Qualys argues that security leaders should build economic models that connect controls and fixes to potential business losses. He recommends starting with a small set of severe loss scenarios, then tracing them down to the assets and exposures that drive those costs. Such models can help boards and cyber insurers understand the value of avoided incidents, not just vulnerability counts.

Expanded Detail

Ivan Milenkovic, Qualys’s VP of Risk Technology for EMEA, argues that security spending should be tied to monetary outcomes rather than vulnerability totals. He compares mature security economics to credit scoring, where a score gains meaning because it estimates possible repayment loss.

He advises beginning with a few major loss scenarios—such as extended payment outages, regulatory data letters, or regional ransomware—then assigning loss ranges and tracing them to underlying assets. Early models will be imperfect, he says, but improve when fed system-derived outcomes; human-adjusted figures are less trustworthy.

Context

If security leaders adopt such economic models, boards, CFOs, cyber insurers, and customers could be affected. Budgets may shift toward exposures tied to revenue, outages, or regulatory loss, potentially reducing costly disruptions. Insurers might gain clearer signals for underwriting, while security teams could communicate avoided incidents more convincingly. However, forecast-based models may misprice risk or overlook low-revenue assets, so benefits would depend on data quality and governance. Society could see more resilient digital services, but only if these tools improve decisions rather than merely add paperwork.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Help Net Security →
Related stories
Using AI to catch data pipeline errors before they cause damage · Artificial intelligence
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Pricing your bad days and how to build an economic model for security decisions.” Browse more stories.