Annual cybersecurity cost as a percentage of IT cost, excluding depreciation/amortization
This measure calculates the percentage of IT cost, excluding depreciation/amortization today for annual cybersecurity cost. Cybersecurity cost (for IT and OT - where applicable) includes all system, resource and overhead costs to develop and manage IT resilience, risk and compliance. This includes application, cloud and data security, identity access management, infrastructure protection, integrated risk management, network security equipment, other information security software, security services, consumer security software. Total IT Cost or Budget (excluding depreciation/amortization; i.e., based on cash flow) includes operating and capital expenses for performing the entire IT function. Operating expenses are independent of including or excluding depreciation/amortization. Capital expenses should include costs for all capitalized IT assets acquired during the reporting period. The IT function concerns the development, delivery, support, and management of IT business/strategy, IT customer relationships, IT resilience/risk/security, IT information, and IT services/solutions. This Cost Effectiveness measure is intended to help companies understand this cost expenditure related to the process group "Manage IT resilience and risk".
Benchmark Data
25th | Median | 75th |
---|---|---|
- | - | - |

Compute this Measure
Units for this measure are percent.
Annual cybersecurity cost as a percentage of IT cost, excluding depreciation/amortization, today
Key Terms
Cybersecurity is the ability to protect or defend the use of cyberspace from cyber-attacks. It is the state of being protected against the criminal or unauthorized use of electronic data, or the measures taken to achieve this, including defending computers, servers, mobile devices, electronic systems, networks, and data from malicious attacks.