Abstract
Risk management and optimised information security control selection in information technology, particularly information security, is crucial for identifying and mitigating organisational threats. Information security control selection and planning are challenging aspects due to limited resources such as funding, time and staffing. This study is an academic exposition in which a quantitative method of evaluating cyber security risk and utilising principles of quantitative risk management and Modern Portfolio Theory (MPT) to optimise the allocation of resources and funding to select information security controls to mitigate an organisation’s specific information security risk and in addition reduce and organisations attack surface and increase risk mitigation, as the identified Return on Investment (ROI) of investment. This study details and illustrates a novel model that uses quantitative risk evaluation methods such as Monte Carlo Simulations as opposed to the commonly used qualitative methods. The aim is to provide organisations with empirical data to make informed decisions, using Modern Portfolio Theory (MPT) when selecting and managing a portfolio of security controls such as Anti-DDOS solutions, Endpoint Detection and Response (EDR), and Cloud Access Security Broker (CASB) solutions.