Top Cybersecurity Myths: The Cost of Investing in Security Is Too High
- Contributor
- Allison D. Ward
Oct 5, 2026
Not everything you may have heard about cybersecurity is true. Some of the most common security beliefs can actually increase your organization’s cyber risk. In our Top Cybersecurity Myth series, we break down these misconceptions and explain what organizations should know instead.
MYTH: The cost of investing in security is too high.
It’s a fact that the average organization’s information security function is not income-producing. And you may find yourself struggling to justify information security-related expenses—whether for a new tool to provide enhanced monitoring, the salary for a dedicated information security officer, or expenses for an IT/information security audit.
However, while security requires financial resources, it’s a myth to think that the cost of security is too high to justify. Let’s investigate why this myth is unfounded.
The risk of a breach is growing.
With the use of connected devices, which will continue to increase, and a rise in remote work, the risk of a breach is only growing. For most organizations, control failures, incidents, breaches, phishing attacks, and other cybersecurity issues are not a matter of “if” but “when.” And “saving” money by neglecting to invest in security now can cause significant financial loss in the future.
The average cost of a breach is high.
There is so much data within most organizations, and the cost of a breach can quickly reach a significant level. The IBM Cost of a Data Breach Report 2025 found that the average total cost of a data breach was $4.44 million per breach globally. The country with the highest average cost was the United States, at a whopping $10.22 million per breach, and the healthcare industry had the highest average cost at $7.42 million per breach.
For small organizations, the absolute numbers are much smaller, but the impact can be devastating. When considering how your organization could be affected, an important takeaway from this study is the average cost per lost record. In IBM’s 2025 report, the average cost per lost record of employee personally identifiable information (PII) was $168, and the average cost for lost customer PII was $160. While this may not seem like a lot, consider how many records your organization has, such as records for employees, donors, patients, members, clients, and other constituents. With a breach of 1,000 records, the cost could add up to $160,000 or more.
Ask yourself: How many records does our organization have? Would we be able to recover if a breach affected these records?
The cost of a breach can be reduced with controls.
Breach costs are not one-time costs. In fact, most organizations are affected multiple years after the initial breach. However, implementing mitigating safeguards can lower overall breach costs. And organizations that identify breaches more quickly experience significantly reduced costs. Therefore, resources you devote now to prevent, detect, and respond to incidents can minimize the short-term and long-term financial impact on your organization.
In addition, many cybersecurity controls can increase the efficiency and effectiveness of existing processes. For example, a centralized monitoring tool may allow your IT staff to more effectively monitor the patch and anti-malware management processes. So while there is an up-front cost to implement that tool, your staff will have added time savings that will allow them to devote their expertise to other critical functions, such as incident identification.
Ask yourself: Does the up-front cost of investing in the tools and resources to empower the cybersecurity of our organization outweigh the risk and cost of a breach?
You can’t put a price on your reputation.
The loss of reputation can be a significant cost for organizations. If you have a cyber issue that results in a breach of sensitive donor, client, patient, or employee information, your constituents may lose trust in your organization.
Your constituents may turn to organizations that they feel can better protect their information. Nonprofit donors may look for organizations that are better able to use their donated funds for the mission rather than losing it to hackers. The loss of future revenue streams can have a significant impact on an organization’s ability to continue.
Ask yourself: Does the cost of investing in security now outweigh the risk of my organization being unable to complete its mission due to loss of reputation related to a breach?
It cannot be denied that the cost of a breach is high. And unfortunately, many organizations that suffer breaches do not recover and instead close their operations. That’s why it’s important to view security controls as an investment. With this mindset, you’ll likely find that the potential impact of an incident significantly outweighs the up-front cost for preventive, detective, and response controls.
Data breach costs are largely deductible.
No data loss prevention policy is perfect, but a good one will almost always be worth the cost. And fortunately, most of these expenses are tax deductible.
Data loss prevention methods—such as using data theft detection software, regularly reviewing data for inaccuracies, auditing the data environment for risks, purchasing encryption technology, installing more robust hardware, and implementing better network security—are ordinary and necessary business expenses. This means they are deductible for both federal and state income tax purposes for businesses filing as C corporations, S corporations, or partnerships, and to self-employed persons reporting their business activity on Schedule C.
By the same token, virtually all measures taken to control a breach—including ransom payments—are ordinary and necessary expenses and should be fully deductible. Losses arising from theft are deductible under Internal Revenue Code (IRC) Section 165. (Note that any costs that are covered by insurance are not tax-deductible.)
Ransomware attacks are considered theft by extortion and are therefore deductible. The IRS makes this clear in Revenue Ruling 72-112, when they state that ransom payments qualify as a theft loss deduction as long as the extortion was illegal in the state where it occurred. Although the revenue ruling was in response to a ransom paid in a kidnapping, the ruling is often applied to ransoms paid to recover digital assets or data.
Low-Cost, High-Reward Investments in Cybersecurity
When organizations are facing financial challenges, making investments in cybersecurity often takes a back seat. However, there are low-cost steps you can take to address cybersecurity gaps while facing budget shortfalls.
- Become a cybersecurity champion. A culture of security starts at the top levels. Staff must see management taking responsibility for cybersecurity, and this can be established by having standing IT/information security department updates at board meetings.
- Establish a cybersecurity training program to ensure staff members understand the threats that are out there and what they can do to help keep your organization secure.
- Implement authentication requirements, requiring longer, more complex passwords for critical IT systems and multi-factor authentication for critical and high-risk systems.
- Develop an incident response plan that includes input from applicable departments. Conduct tabletop testing (a discussion-based exercise in responding to a hypothetical incident) where these individuals discuss various scenarios and how the plan would be enacted.
CRI can help you assess your existing controls and put in place a practical strategy to tighten them up. Contact our cybersecurity advisors today to learn more.
















































































































































































































































































































































































































































































































































































































































































































































