Why Boards Should Measure Cyber Spend Per Employee
Boards routinely ask:
- What’s our cybersecurity budget?
- Are we spending enough?
- How do we compare to peers?
Most companies respond the same way:
“We spend X% of our IT budget on cybersecurity.”
That’s the problem.
Cybersecurity spend as a percentage of IT budget tells the board nothing about:
- whether spend matches business risk,
- whether investment follows the workforce footprint,
- or whether cyber dollars are producing outcomes.
Boards don’t need more budget detail.
They need a better way to measure value.
There is a simpler, more insightful metric:
Cyber spend per employee per month- try it at 👋 Stasiak.com

Cyber is a workforce-driven cost — not a technology-driven cost
Look at how cybersecurity is priced in the real world:
- Identity access and MFA are priced per user
- Email security is priced per mailbox
- Training platforms are priced per employee
- SOC/MSSP monitoring is based on number of endpoints
- SaaS security tools are subscription-based, tied to headcount growth
Regardless of how the budget is labeled internally, cybersecurity spending is really:
A cost to protect each human with access to systems and data.
Yet almost no companies measure it that way.
A better metric for board oversight:
Cyber Cost Per Employee Per Month (CPEM)
The calculation is straightforward:
CPEM = Annual Cybersecurity Spend ÷ Employee Count ÷ 12
Example:
- Annual cyber spend: $4,000,000
- Employees: 3,000
Effective cost:
$4,000,000 ÷ 3,000 ÷ 12 = $111 / employee / month
This gives everyone — board, CFO, CEO, CISO — a common unit of measurement.
Boards understand:
- cost per employee,
- cost per headcount,
- unit economics.
They may not understand:
- firewall replacement cycles,
- EDR deployment schedules,
- SOC shift models.
CPEM connects cybersecurity to the language of the business.
Industry benchmarks
Based on aggregated data from Deloitte, IANS Research, UnderDefense, and others:
| Industry | Cyber Spend Per Employee / Year | Monthly Equivalent |
| Healthcare | $2,500–$3,500 | $208–$292 |
| Financial Services | $3,000–$5,000 | $250–$417 |
| SaaS / Technology | $2,000–$3,000 | $167–$250 |
| Manufacturing | $1,200–$1,800 | $100–$150 |
| Retail / Hospitality | $900–$1,600 | $75–$133 |

These ranges give the board an investment expectation relative to workforce size and business model.
Instead of arguing whether a cybersecurity budget is “high or low,”
CPEM reveals whether spend is aligned with industry reality.
Why boards should adopt CPEM
Cyber spend as a percentage of IT budget hides the truth.
Two companies can both spend 12% of IT budget on cyber, yet:
| Company | Workforce Model | Outcome |
| Company A | 4,000 office-based employees | Higher risk footprint |
| Company B | 300 engineers, low user count | Lower risk footprint |
Same percent.
Completely different exposure.
CPEM reveals that difference immediately.
Boards can finally ask:
- Are we protecting access, not just infrastructure?
- Is cybersecurity budget scaling with workforce growth?
- Are we underinvesting in identity, the largest attack surface?
The moment that changes the conversation
Once the number appears, one of two reactions happens:
1: CPEM is low
“It costs less to protect an employee for a month than it does to provide coffee.”
2: CPEM is high
“Are we getting measurable reduction in risk for this investment?”
Either outcome drives better oversight.
CPEM turns cybersecurity oversight into capital allocation, not checklist review.
Introducing RevRisk CPEM
RevRisk now includes Cyber Cost Per Employee Per Month as a built-in metric.
RevRisk allows boards to input:
- Employee count
- Annual IT budget
- Cyber budget (or % allocated to cyber)
- Industry
RevRisk then calculates:
- Cyber spend per employee per month (CPEM)
- Comparison to industry benchmarks
- A simple red / yellow / green indicator
Green = aligned with peers
Yellow = borderline
Red = underinvested or overinvested relative to risk
And for impact during board meetings:
If your CPEM is lower than $25, RevRisk will tell you:
“You spend more on coffee per employee than cybersecurity.”
Direct. Memorable. Actionable.
The shift boards need to make
Cybersecurity shouldn’t be judged by:
- percent of IT budget,
- number of tools owned,
- or how many pages are in the risk register.
Cybersecurity should be judged by:
- how efficiently the company protects the identities and access that create risk.
When the metric aligns with unit economics,
oversight becomes strategic instead of reactive.
Boards shouldn’t ask:
Are we spending enough?
Boards should ask:
Are we spending enough for the workforce we are protecting?
That answer starts with CPEM.
Final takeaway
Every breach starts with a person —
an account, an identity, a credential.
If people create the access,
then cyber investment should be measured per person.
Cyber spend per employee per month moves cybersecurity into a business language the board already understands — investment efficiency.
And 👋 RevRisk now puts that number in front of them.

