
- 01How much engineering time should be spent on security versus features? The right answer is organization-specific. The wrong answer is a fixed industry benchmark. The defensible methodology starts from incident economics.
- 02Methodology: estimate annual loss expectancy (ALE) from cyber incidents at current control state, estimate the marginal ALE reduction from each candidate engineering investment, justify investment up to the point where marginal cost equals marginal ALE reduction, iterate annually with actual incident data — not just modeled data.
- 03Where most teams underspend: detection content engineering, identity threat detection, supply-chain provenance work. Each is unglamorous and consistently has marginal ALE reduction far exceeding marginal cost — and none of it produces a feature ship date.
- 04Where most teams overspend: tool consolidation projects that produce no detection improvement, custom tooling that duplicates available commercial offerings, compliance work that exceeds the lowest-cost path to the requirement. Each has lower marginal return than the prevention engineering it crowds out.
How much engineering time should be spent on security versus features? The right answer is organization-specific. The wrong answer is a fixed industry benchmark. The defensible methodology starts from incident economics.
The methodology
- 01Estimate annual loss expectancy (ALE) from cyber incidents at current control state
- 02Estimate the marginal ALE reduction from each candidate engineering investment
- 03Engineering investment is justified up to the point where marginal cost equals marginal ALE reduction
- 04Iterate annually with actual incident data, not just modeled data
Where most teams underspend
Detection content engineering, identity threat detection, supply-chain provenance work. Each is unglamorous and consistently has marginal ALE reduction far exceeding marginal cost. They are also the work that does not produce a feature ship date.
Where most teams overspend
Tool consolidation projects that produce no detection improvement. Custom tooling that duplicates available commercial offerings. Compliance work that exceeds the lowest-cost path to the regulatory requirement. Each of these has lower marginal return than the prevention engineering it crowds out.

