It has occurred to me that you could develop an interesting incentive program for an information security team, assuming that y...
It has occurred to me that you could develop an interesting incentive program for an information security team, assuming that you believe a couple of data points (or can come up with your own) and your primary concern is a data breach. In my opinion, security people are all too often incented only to maintain security - not to optimize the investment in security. Interests need to be aligned.
First, assume that you believe, as discussed in Gordon & Loeb's book Managing Cybersecurity Resources: A Cost-Benefit Analysis and discussed here that an organization should spend no more than 37% of their expected loss on information security. Second, assume that you agree with the Ponemon Institute on the cost of business data breaches: $182 per record. Then, as I have pointed out, you have enough info to figure out what your info sec budget should be, or at least it's cap.
So, let's set up a very simplistic model:
Would it be easily game-able? It seems to me, only in the initial determination of the caps. You should also subtract a charge for the assets deployed. So you would have to figure out what assets are in fact security assets and not network assets. You could also put the network team in the mix and have a penalty for downtime too.
So there it is, just a simple, starting point proposal. Comments welcome!
.
