Cybersecurity Investment vs Budget Constraints
CyberTRIZ analysis · Regulatory contradiction R053 · one of 8,235 worked contradictions published by CyberTRIZ.AI
Regulations
Business Context
Financial institutions must continuously invest in cybersecurity technologies, resilience programmes, threat detection, cloud security, identity management, and operational resilience to satisfy DORA requirements. At the same time, organizations operate under financial constraints and must allocate limited budgets across multiple business priorities.
Conflict
Increasing cybersecurity investment improves resilience but raises operational costs. Reducing expenditure improves short-term financial performance but may increase operational and regulatory risk.
Regulatory Obligations
Assess ICT risks regularly
Allocate resources according to risk
Protect critical ICT services
Review investment priorities
Monitor resilience performance
Report significant ICT risks to management
Business Risks
Underfunded cybersecurity
Increased cyber incidents
Operational disruption
Compliance Risks
Inadequate resilience capabilities
Regulatory findings
Supervisory intervention
Recommended Controls
Adopt a risk-based investment model that prioritizes spending according to business criticality, threat exposure, and regulatory obligations. Investment decisions should be supported by measurable risk reduction rather than technology acquisition alone.
Evidence Required
ICT Investment Strategy
ICT Risk Assessments
Budget Approval Records
Investment Review Reports
Executive Risk Reports
Audit Questions
Are ICT investments aligned with risk assessments?
Are critical services appropriately funded?
Are investment decisions documented?
Is investment effectiveness periodically reviewed?
Suggested Kpis
Percentage of ICT budget allocated to critical services
Number of high-risk issues awaiting funding
Percentage of planned resilience investments completed
Number of cybersecurity findings related to insufficient controls