Closing the Validation Gap in Cybersecurity Investment: The CISO Investment Validation Loop (CIVL)—A Design Science Approach to Linking Financial Forecasts and Operational Metrics

Cybersecurity investments are critical for organizational resilience, yet their business value remains difficult to quantify, validate, and communicate to executive stakeholders. This study addresses this challenge by combining an expanded Systematic Literature Review (SLR) with a Design Science Research (DSR) approach. The SLR identifies and synthesizes 132 full-text studies and analyzes existing approaches across financial, technical, governance-related, risk-based, and temporal evaluation dimensions. The findings reveal a structural validation gap in cybersecurity investment evaluation: while many approaches support ex-ante prediction, investment justification, or risk-based decision-making, comparatively few provide mechanisms for ex-post validation of whether financial assumptions are realized through operational outcomes. This disconnect limits the ability of organizations to assess whether cybersecurity investments deliver the expected value over time. To address this gap, the paper proposes the CISO Investment Validation Loop (CIVL), a cyclical design artifact that links financial assumptions with operational proxy indicators across the cybersecurity investment lifecycle. CIVL is conceptually illustrated through a scenario involving the consolidation of legacy firewall infrastructure into a Secure Access Service Edge (SASE) architecture. The study contributes a lifecycle-oriented framework for connecting ex-ante cybersecurity investment assumptions with ex-post operational validation mechanisms and highlights the need for further empirical and practitioner-based evaluation of CIVL in real organizational settings.

Authors

Institutions

Publication Details

Journal
Journal of Cybersecurity and Privacy
Published
2026-10-04
DOI
https://doi.org/10.3390/jcp6050171
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Closing the Validation Gap in Cybersecurity Investment: The CISO Investment Validation Loop (CIVL)—A Design Science Approach to Linking Financial Forecasts and Operational Metrics

Bernhard Köelmel, Duronke Owoleso, Ariel Montes Cohen
Journal of Cybersecurity and Privacy
Information and Cyber Security
article

Closing the Validation Gap in Cybersecurity Investment: The CISO Investment Validation Loop (CIVL)—A Design Science Approach to Linking Financial Forecasts and Operational Metrics

Bernhard Köelmel, Duronke Owoleso, Ariel Montes Cohen
article en

Abstract

Cybersecurity investments are critical for organizational resilience, yet their business value remains difficult to quantify, validate, and communicate to executive stakeholders. This study addresses this challenge by combining an expanded Systematic Literature Review (SLR) with a Design Science Research (DSR) approach. The SLR identifies and synthesizes 132 full-text studies and analyzes existing approaches across financial, technical, governance-related, risk-based, and temporal evaluation dimensions. The findings reveal a structural validation gap in cybersecurity investment evaluation: while many approaches support ex-ante prediction, investment justification, or risk-based decision-making, comparatively few provide mechanisms for ex-post validation of whether financial assumptions are realized through operational outcomes. This disconnect limits the ability of organizations to assess whether cybersecurity investments deliver the expected value over time. To address this gap, the paper proposes the CISO Investment Validation Loop (CIVL), a cyclical design artifact that links financial assumptions with operational proxy indicators across the cybersecurity investment lifecycle. CIVL is conceptually illustrated through a scenario involving the consolidation of legacy firewall infrastructure into a Secure Access Service Edge (SASE) architecture. The study contributes a lifecycle-oriented framework for connecting ex-ante cybersecurity investment assumptions with ex-post operational validation mechanisms and highlights the need for further empirical and practitioner-based evaluation of CIVL in real organizational settings.

Journal of Cybersecurity and PrivacyVol. 6(5)
Texas State University (US), Pforzheim University of Applied Sciences (DE), Institut des Sciences Moléculaires (FR), International School of Management (FR)
Openalex Percentile: Top 5%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.