· Kai Roer

Can cybersecurity be an efficiency tool instead of a sunk cost?

Can cybersecurity be a capital investment instead of an operational expense? Increase profit margins, raise efficiency AND improve security.

Can cybersecurity be an efficiency tool instead of a sunk cost?

Throughout a career in IT and information security, cybersecurity investments have traditionally been viewed as sunk costs — necessary burdens that reduce profitability. But what if this perspective could shift?

Rethinking Security Investment

Instead of treating cybersecurity as an operational expense (OpEx) that drains resources, consider it a capital investment (CapEx) — a hidden treasure rather than a sunken ship. This reframing could dramatically change organizational perspectives on security spending.

The People, Process, Technology Triangle

Security operates across three dimensions: People, Process (policy), and Technology. However, the industry has historically overlooked the People perspective, focusing instead on technology and compliance-driven policies. This imbalance creates inefficiencies and inflated costs.

Real-World Example: VPN Implementation Costs

Consider an organization requiring VPN usage for remote workers. When the technology is poorly designed and policies lack employee buy-in, significant hidden costs emerge:

  • IT and security teams spend 5 hours weekly managing alerts
  • Employees spend another 5 hours weekly addressing security messages
  • Total annual cost: approximately 480 hours — equivalent to 2.5 full-time employees

This single implementation wastes resources across the organization.

Finding Efficiency Gains

By examining security programs through a people-centered lens, organizations can identify friction points and inefficiencies. Even modest improvements — such as saving 5 minutes daily per employee — accumulate to 20 hours saved annually per person.

The Business Case

Imagine demonstrating a 1-5% return on investment from cybersecurity improvements, reflected in overall organizational performance. This transforms security from a cost center into a value driver.

Praxis Security Labs developed its methodology to simultaneously improve security while enhancing business efficiency.

Ready to measure your security culture?

Connect your Microsoft 365 and see months of employee security behavior data in 15 minutes. Free 30-day trial.

Start Free Trial