The Costs of Security Controls: Balancing Effectiveness, Investment, and Perception
Introduction
In security operations, controls are the safeguards that protect people, assets, information, and reputation. However, controls are not free—each comes with an implementation cost (CAPEX) and ongoing maintenance burden (OPEX). The challenge for security leaders is not only to decide which controls to implement, but also to ensure that these controls are effective, sustainable, and justified.
Through large-scale assessments of more than 1,800 security controls across departments, a recurring theme emerges: the difference between perceived control effectiveness and actual control effectiveness. This discrepancy highlights the risk of investing in additional controls—sometimes at high cost—without measurable assurance of real improvement.
The Catalogue of Security Controls
A catalogue of controls provides a structured list of measures available to mitigate risks. Inspired by ISO 27002's control families but tailored to the ISO 18788 security environment, controls may include:
- Governance Controls - Policies, oversight structures, codes of ethics.
- Operational Controls - Deployment protocols, guard rostering, incident response.
- Human Resource Controls - Vetting, training, performance monitoring.
- Technology Controls - CCTV, access control, surveillance drones, body-worn cameras.
- Asset & Facility Controls - Physical barriers, lighting, alarm systems, patrol schedules.
- Compliance Controls - Legal licensing, contractual compliance checks, audits.
- Community & Stakeholder Controls - Engagement forums, grievance mechanisms, human rights safeguards.
A catalogue ensures that decision-making is systematic—controls are not added ad hoc, but selected from an evidence-based, comprehensive inventory.
Control Costs: CAPEX vs. OPEX
When evaluating controls, two dimensions of cost must be considered:
- Capital Expenditure (CAPEX): Initial investment in infrastructure, technology, or systems. Example: installing a biometric access control system.
- Operational Expenditure (OPEX): Ongoing costs for maintenance, licensing, upgrades, and manpower. Example: annual software licenses, technician call-outs, or additional security staff.
A control may appear appealing in theory, but its OPEX can erode long-term sustainability if not carefully assessed. For instance, body-worn cameras may reduce liability, but storing and managing petabytes of video evidence requires massive, recurring costs.
Measuring Control Effectiveness: The ICE Methodology
To ensure controls deliver real value, organizations must measure Internal Control Effectiveness (ICE). This methodology assesses whether a control actually mitigates risk exposure as intended:
- Excellent (90%+) - Control is fully effective and reliable.
- Good (70-80%) - Control works well, but with minor gaps.
- Weak (≤ 50%) - Control exists, but provides little assurance.
- No Control (0%) - No meaningful protection in place.
Example
- Control: CCTV cameras installed.
- Perceived Effectiveness: 85% (managers believe incidents are fully monitored).
- Actual Effectiveness (ICE): 50% (cameras poorly positioned, footage not monitored in real time, retention policies weak).
This gap shows why perceptions cannot replace evidence-based measurement.
The Perception Gap in Control Effectiveness
Findings across multiple organizations reveal a consistent pattern:
- Managers often overestimate effectiveness (based on visibility of the control).
- Frontline staff may underestimate controls if they lack training or awareness.
- Audits and ICE assessments reveal actual gaps, showing that controls thought to be strong are often partial or ineffective.
This perception gap creates risk: leaders may approve costly new controls instead of optimizing existing ones.
Linking Control Costs to Effectiveness
Every proposed control must pass through a cost-effectiveness lens:
- Is the control addressing a significant, prioritized risk?
- Does it provide measurable improvement in ICE scoring?
- What is the CAPEX vs. OPEX profile?
- Does it duplicate or complement existing controls?
- Is the perceived enhancement supported by actual effectiveness data?
Example Decision Scenario
- Proposal: Add an additional manned guard post (high OPEX).
- ICE Assessment: Current surveillance + patrols already provide 80% effectiveness.
- Outcome: Instead of duplicating manpower, optimize surveillance coverage to push effectiveness above 90%—a more cost-efficient choice.
Combined Assurance Mapping of Controls
Controls must also be viewed through a Combined Assurance lens:
- Management (1st Line): Implement and monitor controls daily.
- Risk & Compliance (2nd Line): Assess compliance and effectiveness.
- Internal Audit (3rd Line): Independent verification.
- External Assurance (4th Line): Certification, regulators, client oversight.
By mapping controls this way, organizations can prioritize assurance efforts where ICE scores are weakest, rather than applying costly blanket solutions.
Conclusion
Security controls are essential, but they are not free and not equal. Each control carries both visible costs (CAPEX, OPEX) and hidden risks (effectiveness vs. perception gaps). A structured catalogue of controls, combined with ICE measurement and Combined Assurance mapping, ensures that controls are not only implemented but are also effective, sustainable, and justifiable.
This evidence-based approach empowers leaders to optimize investments, close perception gaps, and deliver measurable assurance, ensuring that every Rand, Dollar, or Euro spent on security controls translates into real risk reduction and stakeholder confidence.