Qualys executive outlines how CISOs can attach financial value to security choices

Ivan Milenkovic of Qualys argues that security leaders should build economic models that connect controls and fixes to potential business losses. He recommends starting with a small set of severe loss scenarios, then tracing them down to the assets and exposures that drive those costs. Such models can help boards and cyber insurers understand the value of avoided incidents, not just vulnerability counts.
Ivan Milenkovic, Qualys’s VP of Risk Technology for EMEA, argues that security spending should be tied to monetary outcomes rather than vulnerability totals. He compares mature security economics to credit scoring, where a score gains meaning because it estimates possible repayment loss.
He advises beginning with a few major loss scenarios—such as extended payment outages, regulatory data letters, or regional ransomware—then assigning loss ranges and tracing them to underlying assets. Early models will be imperfect, he says, but improve when fed system-derived outcomes; human-adjusted figures are less trustworthy.
If security leaders adopt such economic models, boards, CFOs, cyber insurers, and customers could be affected. Budgets may shift toward exposures tied to revenue, outages, or regulatory loss, potentially reducing costly disruptions. Insurers might gain clearer signals for underwriting, while security teams could communicate avoided incidents more convincingly. However, forecast-based models may misprice risk or overlook low-revenue assets, so benefits would depend on data quality and governance. Society could see more resilient digital services, but only if these tools improve decisions rather than merely add paperwork.