With the growing importance of cybersecurity, organizations are compelled to balance effective security controls using limited resources. Despite the existence of numerous economic models to support cybersecurity decisions, many stakeholders are unaware of their availability or lack criteria for the selection of models suited to their specific contexts. The present study addresses this gap by conducting a systematic literature review to establish a comprehensive taxonomy of cybersecurity economic models. From a corpus of 60 reviewed articles, 75 distinct cybersecurity economic model instances were extracted and analyzed using the established taxonomy development methodology, resulting in seven dimensions and 29 characteristics. This taxonomy provides a structured framework for classifying and comparing models, facilitating researchers and practitioners in identifying and applying the most appropriate approaches. In addition, the mapped collection provides a consolidated overview of existing models, highlighting their distinct characteristics and revealing underexplored areas. The present study serves as a foundational reference for future research on model development and supports informed decision-making in cybersecurity investment strategies.
CC BY 4.0
Corresponding author: ali.padyab@his.se, University of Skövde, Sweden
This research was supported by the Swedish Civil Defence and Resilience Agency, MCF, agreement no 2023–12625.