Logiciel Solutions Contact Us
Success Stories Tech News Investors Contact Us
whitepaper

The Economics of AI Security.

Two security plans can carry the same total and buy wildly different amounts of safety. What separates them is order: which family gets funded first, and whether anyone priced the reduction each line removes rather than only the invoice it arrives with. Put that second column in and the list rearranges itself. Access control, non-human identity and a working inventory sit at the top, cost less together than the guardrail licence, and return roughly ten times as much per dollar spent.

In depth

Where The Money Goes Decides More Than How Much Of It There Is.

01

Budgets are sized against the model and breached through the credential.

Ask where AI security money sits and the answer is usually a guardrail product, a red-teaming engagement and an evaluation harness, all of which describe properties of a model. The 2026 study of 602 breached organisations points somewhere else entirely. Access control appears in 92% of AI-related breaches by its absence, six organisations in ten cannot say who may reach a model or the data behind it, and the service accounts, connectors and keys that agents run on go unmanaged at more than half. Each of the three is a purchase, and none of them is a model.

In shortnone of them is a model
02

A shopping list without a second column funds itself in the wrong order.

Every control plan arrives with a price against each line and almost none of them carries the reduction that line removes, so the largest invoice wins by looking the most serious. Divide modelled value by cost and the ranking inverts: access control on models and data returns $2.56 per dollar, non-human identity lifecycle $1.84 and inventory $1.70, while model-layer guardrails return $0.21. The three cheapest families cost $138,000 together, less than the guardrail line on its own, and buy $296,100 of modelled reduction.

In short100 of modelled reduction
03

The controls that pay sit on somebody else's roadmap.

Access control on models and data, non-human identity lifecycle and permission-aware retrieval usually belong to identity engineering, to platform or to the data team, not to whoever holds the AI security budget. So that budget buys what it can authorise on its own, which is tooling beside the model, and the high-yield lines wait for a different sponsor. Two organisations then report identical spend and identical maturity while one has authenticated, attributed and rate-limited calls into every model and the other has a licence.

In shortTwo organisations then report identical spend and id…
04

Containment is the only family whose value you can count in hours.

Five of the six argue from a modelled reduction, which makes them arguable; the sixth is arithmetic at roughly $1,100 an hour. Take one incident from 216 hours to contain down to 40, with logging, a runbook that names the AI systems and one person holding authority to revoke a credential, and 176 hours disappear at a running cost of $193,600. Add the scope that never gets reached and the incident is $378,000 cheaper, yet at $0.99 per dollar containment still ranks fifth of six.

In short99 per dollar containment still ranks fifth of six
The detail

The Three Lines That Move The Number, And What Inflates Them.

Every control family has a cost driver and a thing that makes it expensive, and in almost every case the thing that makes it expensive is buying it late. These three carry the highest yield in the model and the lowest invoices on the list.

Zone · 01

Access control

Priced per system: authentication, authorisation, rate limits and query attribution on every model and every data path behind it. It carries the largest modelled reduction on the list and returns $2.56 per dollar at $64,000 a year in the worked example. What inflates it is retrofit onto systems already serving, and every endpoint that was stood up without one.

Zone · 02

Non-human identity lifecycle

Charged per credential per year: an owner, a scope, an expiry, a rotation schedule and a revocation path for every agent, service account, connector and API key. Fewer than half of organisations run this at all. At $48,000 for $1.84 per dollar it is second on the ranking, and long-lived shared keys with no owner are what make it cost more.

Zone · 03

Inventory and registration

A one-off discovery exercise and then a light standing process, almost entirely internal effort. At $26,000 it is the cheapest family on the list and the only one that tells the other five how many systems they have to cover, which is why it gets funded first. Leave it until after procurement and discovery becomes forensics on the expense ledger.

By the numbers

The figures that make it a board-level conversation.

$2.15
returned per dollar by access control, non-human identity and inventory in the worked example
$1,100
added for every hour an incident runs before it is contained, the one measured unit price
92%
of AI-related breaches happened at organisations with no AI access controls in place
Inside the report

What you'll take away.

01

Step 1 - Add a reduction column to the security plan

Against each line, write what expected loss it removes and divide by what it costs. Without that figure every item looks equally necessary and the biggest quote wins the argument.

02

Step 2 - Move the high-yield work onto the budget it belongs to

Authentication, rate limiting, credential scoping and permission-aware retrieval often sit with identity or platform teams. If they are not funded by the line whose number they move, transfer the work or transfer the money.

03

Step 3 - Price your containment hours before you argue for response

Take the hours between compromise and containment from your own history, then model what logging, a named runbook and standing revocation authority would remove. The difference has a published hourly price.

04

Step 4 - Size the guardrail line last, against what is left

It stays on the list and it buys real reduction on a real failure mode. At $0.21 per dollar it is the wrong first purchase for a budget that has not yet bounded who can reach the model.

Questions

Frequently asked.

Which control family should we fund first?

Inventory, then access control on models and data. The inventory is the cheapest line in the model at $26,000 and it is the only one that tells the other five how many systems they have to cover. Access control carries the largest modelled reduction and returns $2.56 per dollar.

The reductions in your model are estimates. Why should we trust the ranking?

Break the input you trust least and check whether the conclusion survives. Halve the reduction on access control, from 26 per cent to 13, and it still returns $1.28 per dollar, six times the guardrail line at $0.21. Reversing the order needs a tenfold error on the one control 92 per cent of AI-breach victims did not have.

Does a bigger AI security budget fix this?

Rarely. In the worked example the whole programme of $350,000 returns $1.22 per dollar, and dropping the single largest line lifts the remaining $230,000 to $1.75. The problem is almost never the size of the budget. It is the order in which it is spent.

Is containment worth funding if it ranks fifth of six?

Yes, and not first. On one incident, going from 216 hours to 40 removes $193,600 of running cost and $184,400 of scope, which is $378,000 of value. Annualised at the example probability that is $56,700 against $57,000 of cost, a yield of $0.99. Worth buying, after the four lines above it.

What is the largest reduction already measured, and are we using it?

AI and automation in defence save an average of $1.93M per breach, the largest single reduction in the 2026 study. Half of breached organisations point it at threat hunting and only 18 per cent at vulnerability management. That capability is already bought. It is aimed at the half of the problem that produces weekly reporting.

How does this differ from your paper on governance economics?

This one prices the spend side of security: what each control family costs to run and how much reduction a dollar of it buys. The Economics of AI Governance prices the standing cost of holding evidence, per system and per year, and compares generating it in the pipeline against assembling it by hand.

Who should be in the room for this?

CISOs and CFOs arguing the same line from opposite sides. It assumes you accept that AI incidents cost real money and now need a defensible order of purchase, a yield figure per family, and one number that turns a response ask into arithmetic.

Get the whitepaper

Have it emailed to you.

Drop your details and we'll send The Economics of AI Security straight to your inbox - no spam, unsubscribe anytime.

Download whitepaper
Next step

Rank the families by what each buys, then fund downwards.

Come with your credential inventory and the timeline of your last incident. We run the ranking against your own exposure and reductions, and you leave with an order to fund in rather than a product list. SECTION 7 - FAQ - 5 to 8 questions

Review your control spend