iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To get identity-security funding, price a specific business scenario—not “identity risk” as a single, universal number. Trace a compromised account to the services and assets it can reach, estimate the resulting financial impact with your organization’s own inputs, and show how a proposed control changes the exposure and what risk remains.
Why identity risk needs a business-impact model
An identity compromise matters financially when it disrupts a service, exposes sensitive information, changes trusted data, or gives an attacker access to money or critical systems. The useful question is therefore not “What does identity risk cost?” but “What could this account enable an attacker to do, and what would that mean for the business?”
NIST’s 2025 guidance on using business impact analysis to inform risk prioritization and response recommends connecting critical assets and services to mission objectives, assessing their criticality and sensitivity, and considering the impact of losing confidentiality, integrity, availability, or trusted access. That analysis can help connect cybersecurity risk management with enterprise risk management.
For example, a supplier account with access to invoice workflows presents a different business scenario from an employee account that can administer production systems. Both are identity risks; their reachable assets, consequences, and plausible safeguards differ.
#1 Best Overall
What the breach data can—and cannot—tell you
Population-level breach statistics can establish that a scenario is worth considering. They cannot supply your organization’s probability of loss or a defensible price for your own exposure.
- Credential abuse: Verizon’s 2025 Data Breach Investigations Report release says credential abuse was an initial attack vector in 22% of 12,195 confirmed breaches. The report covers incidents from November 1, 2023, through October 31, 2024. That is a share of the report’s breach dataset, not a forecast that your organization has a 22% chance of a credential-abuse breach. See the 2025 DBIR release and the 2025 DBIR report page.
- Third parties: Verizon’s 2025 release says third-party involvement doubled to 30% of breaches. Treat this as a reason to include supplier and partner identities in your exposure map, not as your own likelihood estimate. The same release provides the statistic.
- Business email compromise: Verizon’s 2026 Breach Impact Study describes attackers using a stolen email chain to impersonate a vendor or partner and redirect invoice payments. BEC represented 12% of the DBIR data for the study’s 2019–2025 window. These figures describe the study’s data, not an individual company’s risk. See the 2026 Breach Impact Study.
- Claim costs: In its analysis of BEC insurance claims, the same 2026 study reports a median economic loss around the mid-$50,000 range and says response and recovery accounted for 64% of total claim dollars. It also describes occasional incidents around $10 million. These are claim-dataset results—not a typical guaranteed outcome, a forecast for your organization, or a suitable default input for your model.
The practical takeaway is to use external figures as context for choosing scenarios. Price your own scenario from internal evidence and explicit assumptions.
Rank #2
Build a scenario from identity to business service
Start with an account and a plausible compromise or misuse path, then follow its access to the business activities that depend on it. Avoid stopping at a list of users, applications, or security controls.
- Choose a scenario. Examples include a compromised employee account used to access sensitive records, misuse of a privileged account to alter production systems, or a supplier account used to redirect an invoice payment. Keep the scenario specific enough to evaluate.
- Map the access path. Identify the account, authentication and authorization path, applications, data, administrators, and third parties it can reach. Note where access is broad, shared, or difficult to revoke.
- Connect access to a service. Name the business service or workflow that depends on those systems—such as processing invoices, delivering a customer service, or operating production. Record the service’s criticality and the effects of losing confidentiality, integrity, availability, or trusted access.
- Estimate consequences with local inputs. Use documented costs and operational facts: investigation and recovery hours, service interruption, delayed transactions, fraud or extortion loss, and legal or notification duties where applicable. Include other financial effects only when you can explain their basis.
- Separate the event from the annual view. A single-event scenario estimates what an incident could cost under stated conditions. An annualized estimate also needs a credible estimate of event frequency or likelihood. Do not turn a scenario impact into an annual expected loss by multiplying it by an unsupported probability.
- Make the assumptions visible. State the time period, scope, likely dependencies, and what is included or excluded. Use low, central, and high cases when inputs are uncertain; if there is not enough evidence to estimate probability, show the scenario range without presenting it as an annual forecast.
Count the costs beyond the payment or outage
A transfer to an attacker or a period of downtime may be the most visible consequence, but neither necessarily captures the full business impact. Build the estimate from cost categories relevant to the scenario and avoid counting the same effect twice.
- Fraud or extortion: Funds transferred, attempted payments stopped, or other documented direct losses. Distinguish amounts actually lost from amounts merely at risk.
- Response and recovery: Internal and external investigation, containment, account restoration, system recovery, and staff time. The Verizon BEC claims analysis is a reminder that these costs can make up a substantial share of claim dollars; its 64% result applies to that claims dataset, not automatically to your incident scenario.
- Interrupted operations: Affected services, duration, transaction volume, delayed work, and the organization’s own method for estimating the financial effect. Explain the calculation rather than presenting an unsupported lump sum.
- Legal and notification work: Include duties and costs only where they apply to the data, jurisdiction, and facts of the scenario.
- Recovery and residual loss: If insurance or recovery is relevant, distinguish gross potential loss from what may be recoverable. Do not treat coverage as certain without checking its scope, conditions, and limits.
Compare safeguards on the same decision axes
Do not claim that a control “pays for itself” unless your organization has defensible evidence for the change in risk and cost. Instead, compare proposed options against the same scenario and make the trade-offs explicit.
| Decision axis | Question for the proposal |
|---|---|
| Coverage | Which employee, supplier, service, or privileged identities and which systems does it cover? Which part of the scenario remains outside scope? |
| Likelihood and blast radius | How could it make compromise or misuse less likely, or limit what a compromised identity can reach? |
| Detection and recovery | Could it improve detection, containment, account revocation, or recovery time? What evidence supports that expectation? |
| Cost and operating burden | What are the implementation and ongoing costs, deployment dependencies, and support requirements? |
| User and business friction | What changes for employees, suppliers, or business processes, and how will that burden be managed? |
| Evidence and residual risk | How strong is the organization-specific evidence, and what exposure remains after the change? |
Verizon’s 2025 DBIR page lists multifactor authentication, software updates, employee training, encryption, testing, and incident-response planning among measures that can help prevent breaches. The cited material does not assign a universal dollar return to any one measure. Select safeguards based on the scenario’s access paths, expected risk reduction, cost, operating fit, and evidence—not a generic ROI claim.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Turn the estimate into a funding decision
A CFO-ready request should make the decision visible without disguising uncertainty. Present the scenario, the business service at stake, the estimated impact range, the assumptions behind it, and the proposed change. Then state what risk remains and what management is being asked to accept.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Exposure: Identify the account or identity group, access path, and business service.
- Impact: Show scenario-specific consequences and the inputs used to estimate them.
- Proposal: Specify the control or process changes, the identities and systems covered, and their implementation and operating costs.
- Expected change: Explain which likelihood, blast-radius, detection, or recovery factors should improve and what evidence supports that expectation.
- Residual exposure: Name the scenario elements the proposal does not address and the risk the business would retain.
- Measurement and review: Define what will be measured and when the business will revisit assumptions, costs, and remaining risk.
This frames funding as a choice about a business exposure and its treatment—not as a request to buy security because a breach statistic sounds alarming.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

