Cyber Risk Starts With People. Your Budget Should Too.

Boards routinely underfund cybersecurity because they never actually see it. Cyber spend gets buried inside the IT budget — competing with infrastructure projects and help desk cycles. In reality, cybersecurity is not a technology expense. It’s revenue protection and risk allocation. In this issue, we show why the board must separate cyber spend from the IT budget, how to tie it to revenue exposure, and the three questions directors should be asking during budget season.

Why Boards Should Measure Cyber Spend Per Employee

Boards routinely ask:

  • What’s our cybersecurity budget?
  • Are we spending enough?
  • How do we compare to peers?

Most companies respond the same way:

“We spend X% of our IT budget on cybersecurity.”

That’s the problem.

Cybersecurity spend as a percentage of IT budget tells the board nothing about:

  • whether spend matches business risk,
  • whether investment follows the workforce footprint,
  • or whether cyber dollars are producing outcomes.

Boards don’t need more budget detail.

They need a better way to measure value.

There is a simpler, more insightful metric:

Cyber spend per employee per month- try it at 👋 Stasiak.com 

Cyber is a workforce-driven cost — not a technology-driven cost

Look at how cybersecurity is priced in the real world:

  • Identity access and MFA are priced per user
  • Email security is priced per mailbox
  • Training platforms are priced per employee
  • SOC/MSSP monitoring is based on number of endpoints
  • SaaS security tools are subscription-based, tied to headcount growth

Regardless of how the budget is labeled internally, cybersecurity spending is really:

A cost to protect each human with access to systems and data.

Yet almost no companies measure it that way.

A better metric for board oversight:

Cyber Cost Per Employee Per Month (CPEM)

The calculation is straightforward:

CPEM = Annual Cybersecurity Spend ÷ Employee Count ÷ 12

Example:

  • Annual cyber spend: $4,000,000
  • Employees: 3,000

Effective cost:

$4,000,000 ÷ 3,000 ÷ 12 = $111 / employee / month

This gives everyone — board, CFO, CEO, CISO — a common unit of measurement.

Boards understand:

  • cost per employee,
  • cost per headcount,
  • unit economics.

They may not understand:

  • firewall replacement cycles,
  • EDR deployment schedules,
  • SOC shift models.

CPEM connects cybersecurity to the language of the business.

Industry benchmarks

Based on aggregated data from Deloitte, IANS Research, UnderDefense, and others:

IndustryCyber Spend Per Employee / YearMonthly Equivalent
Healthcare$2,500–$3,500$208–$292
Financial Services$3,000–$5,000$250–$417
SaaS / Technology$2,000–$3,000$167–$250
Manufacturing$1,200–$1,800$100–$150
Retail / Hospitality$900–$1,600$75–$133

These ranges give the board an investment expectation relative to workforce size and business model.

Instead of arguing whether a cybersecurity budget is “high or low,”
CPEM reveals whether spend is aligned with industry reality.

Why boards should adopt CPEM

Cyber spend as a percentage of IT budget hides the truth.

Two companies can both spend 12% of IT budget on cyber, yet:

CompanyWorkforce ModelOutcome
Company A4,000 office-based employeesHigher risk footprint
Company B300 engineers, low user countLower risk footprint

Same percent.
Completely different exposure.

CPEM reveals that difference immediately.

Boards can finally ask:

  • Are we protecting access, not just infrastructure?
  • Is cybersecurity budget scaling with workforce growth?
  • Are we underinvesting in identity, the largest attack surface?

The moment that changes the conversation

Once the number appears, one of two reactions happens:

1: CPEM is low
“It costs less to protect an employee for a month than it does to provide coffee.”

2: CPEM is high
“Are we getting measurable reduction in risk for this investment?”

Either outcome drives better oversight.

CPEM turns cybersecurity oversight into capital allocation, not checklist review.

Introducing RevRisk CPEM

RevRisk now includes Cyber Cost Per Employee Per Month as a built-in metric.

RevRisk allows boards to input:

  • Employee count
  • Annual IT budget
  • Cyber budget (or % allocated to cyber)
  • Industry

RevRisk then calculates:

  • Cyber spend per employee per month (CPEM)
  • Comparison to industry benchmarks
  • A simple red / yellow / green indicator

Green = aligned with peers
Yellow = borderline
Red = underinvested or overinvested relative to risk

And for impact during board meetings:

If your CPEM is lower than $25, RevRisk will tell you:
“You spend more on coffee per employee than cybersecurity.”

Direct. Memorable. Actionable.

The shift boards need to make

Cybersecurity shouldn’t be judged by:

  • percent of IT budget,
  • number of tools owned,
  • or how many pages are in the risk register.

Cybersecurity should be judged by:

  • how efficiently the company protects the identities and access that create risk.

When the metric aligns with unit economics,
oversight becomes strategic instead of reactive.

Boards shouldn’t ask:

Are we spending enough?

Boards should ask:

Are we spending enough for the workforce we are protecting?

That answer starts with CPEM.

Final takeaway

Every breach starts with a person —
an account, an identity, a credential.

If people create the access,
then cyber investment should be measured per person.

Cyber spend per employee per month moves cybersecurity into a business language the board already understands — investment efficiency.

And 👋 RevRisk now puts that number in front of them.

RELATED POSTS

Discover more from Stasiak

Subscribe now to keep reading and get access to the full archive.

Continue reading

[mailpoet_form id="5"]
[mailpoet_form id="1"]