Back to Field Notes
API & Application Security/Field Note

How Much Engineering Time Should Be Spent on Security?

Set the security engineering budget proportional to the cost of incidents the engineering can prevent. The math is concrete.

Author

Ravi Shankaran

Lead GRC Engineer

Published

April 17, 2026

Read

8 min

Share
AI-generated illustration of a banking data center
AI-generated illustration of a banking data center
Key Takeaways
  • 01How much engineering time should be spent on security versus features? The right answer is organization-specific. The wrong answer is a fixed industry benchmark. The defensible methodology starts from incident economics.
  • 02Methodology: estimate annual loss expectancy (ALE) from cyber incidents at current control state, estimate the marginal ALE reduction from each candidate engineering investment, justify investment up to the point where marginal cost equals marginal ALE reduction, iterate annually with actual incident data — not just modeled data.
  • 03Where most teams underspend: detection content engineering, identity threat detection, supply-chain provenance work. Each is unglamorous and consistently has marginal ALE reduction far exceeding marginal cost — and none of it produces a feature ship date.
  • 04Where most teams overspend: tool consolidation projects that produce no detection improvement, custom tooling that duplicates available commercial offerings, compliance work that exceeds the lowest-cost path to the requirement. Each has lower marginal return than the prevention engineering it crowds out.

How much engineering time should be spent on security versus features? The right answer is organization-specific. The wrong answer is a fixed industry benchmark. The defensible methodology starts from incident economics.

The methodology

  • 01Estimate annual loss expectancy (ALE) from cyber incidents at current control state
  • 02Estimate the marginal ALE reduction from each candidate engineering investment
  • 03Engineering investment is justified up to the point where marginal cost equals marginal ALE reduction
  • 04Iterate annually with actual incident data, not just modeled data

Where most teams underspend

Detection content engineering, identity threat detection, supply-chain provenance work. Each is unglamorous and consistently has marginal ALE reduction far exceeding marginal cost. They are also the work that does not produce a feature ship date.

Where most teams overspend

Tool consolidation projects that produce no detection improvement. Custom tooling that duplicates available commercial offerings. Compliance work that exceeds the lowest-cost path to the regulatory requirement. Each of these has lower marginal return than the prevention engineering it crowds out.

#Engineering#DevSecOps#Investment

/WRITTEN_BY

Ravi Shankaran

Lead GRC Engineer · Alexa Cybersecurity