The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →There is no universal percentage of revenue or guaranteed return that every business should spend on cybersecurity. Leaders should base investment on the business functions that matter most, the risks that could disrupt them, the safeguards already in place, and the organization’s ability to respond and recover. CISA guidance points to practical priorities—including multifactor authentication, tested backups, logging, and continuity planning—but does not set a company-specific budget.
How much should a business spend on cybersecurity?
No figure in the available CISA guidance establishes a universal cybersecurity budget, and the sources do not provide a formula that predicts return on investment. A useful budget is therefore an outcome of risk decisions, not a percentage selected in isolation.
Start by identifying critical business functions and the systems, data, and people they depend on. Then compare the consequences of disruption with current safeguards and the cost and effort of addressing gaps. The right investment will vary with company size, sector, regulatory duties, existing controls, risk appetite, and available expertise.
CISA captures the trade-off plainly: “In nearly every organization, security improvements are weighed against cost and operational risks to the business.” The statement appears in CISA’s Shields Up: Guidance for Corporate Leaders and CEOs; it is attributed to CISA as the issuing organization, not to an individual speaker.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
How should leaders prioritize limited cybersecurity resources?
Prioritize by the potential effect on important business functions rather than by product category or vendor claims. For each proposed investment, consider:
- How much it reduces risk to a critical business function.
- Its implementation and ongoing operating costs.
- Whether it works with the organization’s current systems and how long deployment will take.
- Whether the outcome can be measured or tested.
- Whether it improves the ability to recover after an incident.
- Whether internal staff can operate it or outside expertise is needed.
CISA’s voluntary Cross-Sector Cybersecurity Performance Goals (CPGs) are designed to help small and midsize organizations focus limited resources on a manageable set of high-impact actions. The goals are organized around the six NIST Cybersecurity Framework functions: Govern, Identify, Protect, Detect, Respond, and Recover. CISA describes them as a prioritization aid when expertise, resources, or capabilities are limited—not as a prescribed budget or a complete compliance checklist. CISA says the CPGs are being updated to align with NIST CSF 2.0, so check the current CPG guidance before relying on a particular version or mapping.
Rank #2
What cybersecurity investments should a small business make first?
There is no single first purchase for every small business. A sensible starting point is to identify gaps in basic protections and recovery readiness, then address the gaps most likely to affect critical operations. CISA’s small and midsize business resources cover practical areas including phishing, passwords, MFA, software updates, logging, backups, and encryption.
Require multifactor authentication
Use multifactor authentication (MFA) wherever possible, with particular attention to administrator accounts, remote access, and workers handling sensitive information. CISA advises organizations to use the strongest option available and aim for phishing-resistant MFA. Physical security keys are one possible method, but compatibility depends on the identity provider, account type, and device environment. A key does not secure an account by itself; the organization still needs appropriate account configuration and operating practices. See CISA’s MFA guidance.
Rank #3
Back up critical data and prove it can be restored
Back up critical data and system configurations automatically and continuously where feasible, and keep a retrievable copy air-gapped from the organizational network. The existence of backup files is not proof of recovery readiness: ask for evidence that restores have been tested and that critical business functions can resume. CISA’s guidance does not establish a universal recovery time objective or recovery point objective; those targets should reflect business needs. See CISA’s ransomware guidance.
Set up logging and monitoring
Establish policies for what to log, how logs are monitored, who can access them, how they are stored securely, and how long they are retained under policy and compliance requirements. Logging can help an organization understand and investigate suspicious activity, but it needs assigned ownership and a response process. CISA lists Logging Made Easy as a no-cost resource. Paid monitoring services may be one way to implement monitoring, but CISA does not require them.
Use available no-cost resources carefully
CISA’s small-business resource hub includes guidance on common security topics and lists no-cost cyber hygiene services, including vulnerability and web application scanning, as well as a tool for assessing and hardening some SaaS configurations. Check the live pages for eligibility and current service scope before planning around a particular offering.
How can leaders justify cybersecurity spending to the board?
Frame proposals around business consequences, not fear-based statistics or a vendor’s threat claims. Explain which critical function a proposal protects, what risk or readiness gap it addresses, what it costs to implement and operate, and how the organization will verify that it works. Make clear what risk remains after the investment.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
CISA advises senior management to include CISOs in company-risk decisions and to signal that security investment is a priority. It also recommends that incident response plans include security and IT teams, senior business leadership, and board members, and that leaders participate in a tabletop exercise. This puts governance, response readiness, and business continuity into the same investment conversation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Which security controls offer the best return?
The sources do not establish a ranked list of controls by financial return, nor a guaranteed ROI for any product or safeguard. What is valuable depends on the business’s exposures and the systems supporting its critical functions. Evaluate alternatives against risk reduction, implementation and operating cost, compatibility, deployment time, testability, recovery benefit, and the expertise required to run them.
Do not treat buying a product as equivalent to reducing risk. Configuration, accountable ownership, staff training, and testing determine whether a safeguard works in practice. A security key, backup service, logging tool, or monitoring contract is only one part of an operating capability.
What does the $2.4 billion cybercrime figure mean?
CISA reported that total cybercrime costs to small businesses reached $2.4 billion in 2021. This is a historical aggregate, not a current annual spending figure, an estimate of any individual company’s expected losses, or a calculation of the return on a cybersecurity investment. It should not be divided into a per-company amount or used as a direct budget target. See CISA’s small-business cybersecurity article.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

