When does it make sense to spend more on security than on the item being secured? I recently moved to the Netherlands to accept a position as the CISO for a non-profit international organization. It rains quite a bit more here than in New Jersey, where I used to live, and when the people speak Dutch, they do so with a guttural cacophony that sounds as if they’re winding up to expel a troublesome bit of phlegm. Those adjustments aside, information security here is pretty much the same. I mean, securing a Windows 2003 server on this side of the pond is no different than in the States.But there are some glaring cultural differences between Americans and the Dutch, and here is where it gets interesting. Dutch society is extremely ecology-minded, and practically every Dutch man and woman rides a bicycle. Naturally, my inclination when I arrived here was, When in Holland, do as the Hollanders do. But not so fast.The first advice I got was to not buy an expensive bike. Instead, I was told to buy a good Dutch grandma bike. You know, an upright one with pedal brakes and a bit of rust on the handlebars. No fancy gears, bike seats or racing wheelsthe closer one gets to the original caveman concept of the wheel, the better.Then came part two of the advice: Invest more money in your bicycle lock than in the bicycle. Otherwise, the bike will be stolen. (I guess all that cheese and chocolate makes for sticky fingers.) When I first heard this advice, I wondered if perhaps it wasn’t the Dutch equivalent of a snipe hunt. I could just see myself rolling out my rickety, old grandma bike and being caught up in a maelstrom of biking Dutchmen. Lance Armstrong look-alikes would whiz past whilst I navigated my wobbly (but highly protected) bike down the the bike lane. Small children would point and laugh, and bullies would heave rotting fruit in my direction. Surely I would be the laughingstock of this bicycle-fanatic nation.Such was not the case. The Dutch are a serious people, and they are at their most serious when it comes to bike riding. Buy a cheap bike and an expensive lock, everyone said. My security sense began to tingle. The Cardinal Rule of SecurityWe’ve all heard this basic tenet of security: Don’t spend more money protecting something than the something is actually worth. Would you, for example, pay $15,000 for guards to protect a diamond that was worth only $10,000? Couldn’t you just accept it if the damn thing got stolen and save yourself some money?Ah yes, but the economists in the audience also recognize that there is such a thing as opportunity costs.The bicycle (unlike the diamond) actually allows us to save money that we’d otherwise spend on things such as car insurance, taxes, parking and $6-per-gallon gasoline. What’s more, the bicycle provides intangible benefits, such as the feeling of oneness with the outdoors, a sense of well-being from improved cardiovascular health and the downright joie de vivre one derives from imbibing the sheer Dutchness of it all. Thus, in terms of both actual value and derived benefit, the bicycle is actually worth much more to the average Dutch biker than it costs.Second, given the bicycle’s intrinsic value to potential thieves, the theft of a poorly locked bicycle is a near certainty. If you don’t lock your bike, then you will have to purchase another one. The expected loss from not having a solid lock is not only the value of the present, sure-to-be-stolen bike but also the value of the next bike that you’ll have to purchaseand, if you continue to fail to lock your bike, the cost of all the future bikes that you will have to buy because you failed to protect the previous ones. Have I lost anyone here? Good.Secure in the knowledge of these economic principles, I happily ventured forth and purchased my scruffy little granny bike and a shiny new lock. In doing so, I learned a new lesson in security: You must take into account not only an object’s monetary value, but also its opportunity cost and expected value. Now, if I could just learn to feel a bit more secure in the Dutch bike lanes. Related content feature Top cybersecurity M&A deals for 2023 Fears of recession, rising interest rates, mass tech layoffs, and conservative spending trends are likely to make dealmakers cautious, but an ever-increasing need to defend against bigger and faster attacks will likely keep M&A activity steady in By CSO Staff Sep 22, 2023 24 mins Mergers and Acquisitions Mergers and Acquisitions Mergers and Acquisitions brandpost Unmasking ransomware threat clusters: Why it matters to defenders Similar patterns of behavior among ransomware treat groups can help security teams better understand and prepare for attacks By Joan Goodchild Sep 21, 2023 3 mins Cybercrime news analysis China’s offensive cyber operations support “soft power” agenda in Africa Researchers track Chinese cyber espionage intrusions targeting African industrial sectors. By Michael Hill Sep 21, 2023 5 mins Advanced Persistent Threats Cyberattacks Critical Infrastructure brandpost Proactive OT security requires visibility + prevention You cannot protect your operation by simply watching and waiting. It is essential to have a defense-in-depth approach. By Austen Byers Sep 21, 2023 4 mins Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe