Two security plans can carry the same total and buy wildly different amounts of safety. What separates them is order: which family gets funded first, and whether anyone priced the reduction each line removes rather than only the invoice it arrives with. Put that second column in and the list rearranges itself. Access control, non-human identity and a working inventory sit at the top, cost less together than the guardrail licence, and return roughly ten times as much per dollar spent.
Every control family has a cost driver and a thing that makes it expensive, and in almost every case the thing that makes it expensive is buying it late. These three carry the highest yield in the model and the lowest invoices on the list.
Priced per system: authentication, authorisation, rate limits and query attribution on every model and every data path behind it. It carries the largest modelled reduction on the list and returns $2.56 per dollar at $64,000 a year in the worked example. What inflates it is retrofit onto systems already serving, and every endpoint that was stood up without one.
Charged per credential per year: an owner, a scope, an expiry, a rotation schedule and a revocation path for every agent, service account, connector and API key. Fewer than half of organisations run this at all. At $48,000 for $1.84 per dollar it is second on the ranking, and long-lived shared keys with no owner are what make it cost more.
A one-off discovery exercise and then a light standing process, almost entirely internal effort. At $26,000 it is the cheapest family on the list and the only one that tells the other five how many systems they have to cover, which is why it gets funded first. Leave it until after procurement and discovery becomes forensics on the expense ledger.
Against each line, write what expected loss it removes and divide by what it costs. Without that figure every item looks equally necessary and the biggest quote wins the argument.
Authentication, rate limiting, credential scoping and permission-aware retrieval often sit with identity or platform teams. If they are not funded by the line whose number they move, transfer the work or transfer the money.
Take the hours between compromise and containment from your own history, then model what logging, a named runbook and standing revocation authority would remove. The difference has a published hourly price.
It stays on the list and it buys real reduction on a real failure mode. At $0.21 per dollar it is the wrong first purchase for a budget that has not yet bounded who can reach the model.
Inventory, then access control on models and data. The inventory is the cheapest line in the model at $26,000 and it is the only one that tells the other five how many systems they have to cover. Access control carries the largest modelled reduction and returns $2.56 per dollar.
Break the input you trust least and check whether the conclusion survives. Halve the reduction on access control, from 26 per cent to 13, and it still returns $1.28 per dollar, six times the guardrail line at $0.21. Reversing the order needs a tenfold error on the one control 92 per cent of AI-breach victims did not have.
Rarely. In the worked example the whole programme of $350,000 returns $1.22 per dollar, and dropping the single largest line lifts the remaining $230,000 to $1.75. The problem is almost never the size of the budget. It is the order in which it is spent.
Yes, and not first. On one incident, going from 216 hours to 40 removes $193,600 of running cost and $184,400 of scope, which is $378,000 of value. Annualised at the example probability that is $56,700 against $57,000 of cost, a yield of $0.99. Worth buying, after the four lines above it.
AI and automation in defence save an average of $1.93M per breach, the largest single reduction in the 2026 study. Half of breached organisations point it at threat hunting and only 18 per cent at vulnerability management. That capability is already bought. It is aimed at the half of the problem that produces weekly reporting.
This one prices the spend side of security: what each control family costs to run and how much reduction a dollar of it buys. The Economics of AI Governance prices the standing cost of holding evidence, per system and per year, and compares generating it in the pipeline against assembling it by hand.
CISOs and CFOs arguing the same line from opposite sides. It assumes you accept that AI incidents cost real money and now need a defensible order of purchase, a yield figure per family, and one number that turns a response ask into arithmetic.
Drop your details and we'll send The Economics of AI Security straight to your inbox - no spam, unsubscribe anytime.
Come with your credential inventory and the timeline of your last incident. We run the ranking against your own exposure and reductions, and you leave with an order to fund in rather than a product list. SECTION 7 - FAQ - 5 to 8 questions
Review your control spend