A Decision Model on Optimising Cybersecurity Controls Using Organisation Preferences

Optimizing cybersecurity involves understanding it as an organizational concern with varying stakeholder perspectives. Instead of viewing it as a standalone issue, decision-makers should align security measures with business goals. This paper proposes a model considering organizational priorities, translating them into a utility function for evaluating security controls, and finding an optimal balance between risk, cost, and benefit.

