Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Activity Based Costing
Governance, Ownership & Risk

Activity Based Costing

← Back to Glossary
By NHI Mgmt Group Updated September 25, 2026 Domain: Governance, Ownership & Risk

A method for calculating breach cost by assigning expenses to the work performed during and after an incident. It separates detection and escalation, notification, post-breach response, and lost business so organizations can see where money is actually spent and which parts of the response drive the largest financial impact.

How Activity Based Costing Works in a Breach Context

Activity based costing turns incident spend into a sequence of accountable work items, rather than a single blended loss figure. That makes it easier to see how much budget is consumed by investigation, containment, notification, recovery, and business disruption, which is exactly why it is useful in post-incident financial analysis.

What Activity Based Costing Reveals About Incident Economics

The method is most valuable when the same incident category produces very different cost profiles depending on how long detection takes, how many teams are involved, and how much manual effort is needed to escalate and restore operations. It highlights hidden cost concentration, especially where labor and delay costs outweigh obvious technical remediation expenses.

For cyber incidents, that often means the largest cost driver is not the initial control failure but the response workload that follows. Activity based costing can show whether losses are concentrated in forensics, legal and notification work, customer support, downtime, or lost sales, giving leaders a more precise view of where the incident actually damaged the business.

Why Activity Based Costing Is Different from Simple Breach Estimates

Many breach cost estimates rely on averages, benchmarks, or high-level categories that blur together very different response patterns. Activity based costing is more granular because it traces expense to the actual tasks performed, which makes it better suited to comparing incidents, justifying investments, and challenging assumptions about where breach cost comes from.

That granularity also makes the model more useful for decision-making after the fact. If detection and escalation consume a disproportionate share of spend, the organization can see that the economics of the breach were driven by operational delay, not only by the compromise itself.

Where Activity Based Costing Fits in Security Governance

Activity based costing belongs in the broader discipline of security performance measurement and incident review. It helps organizations connect operational response to financial impact, so post-incident analysis can inform budget allocation, control prioritization, and recovery planning with more precision than a single headline loss number.

It is especially helpful when different teams own different parts of the response, because it exposes how costs move across functions instead of staying hidden in one department. Used well, it becomes a governance tool for understanding which stages of breach handling are expensive, slow, or consistently under-resourced.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyActivity based costing informs how incident costs shape cyber risk priorities.
GV.OV-01 — Oversight of Cybersecurity RiskIt supports oversight by showing where incident spending is concentrated.
RC.RP-01 — Recovery Plan ExecutionCosting incident activities exposes expensive recovery steps and bottlenecks.
Recommendation — Use incident cost breakdowns to guide risk prioritization and investment decisions. Track breach cost by activity to support board-level oversight of response economics. Measure recovery work by activity to improve execution and resource planning.
ISO/IEC 27001:2022A.5.24 — Information security incident management planning and preparationBreach cost analysis supports preparation and review of incident handling.
Recommendation — Use post-incident cost analysis to improve incident management planning.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org