Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Marginal Return
Cyber Security

Marginal Return

← Back to Glossary
By NHI Mgmt Group Updated September 20, 2026 Domain: Cyber Security

Marginal return is the additional benefit gained from one more unit of input at the current operating point. It matters more than average return in optimization because it determines where extra budget, effort, or capacity creates the most value. Equal marginal returns usually mark the best allocation across subsystems.

What marginal return means in security investment decisions

Marginal return is the practical way to ask whether one more dollar, hour, control, or engineering sprint produces more security value than the next best alternative. In cybersecurity, that question matters because budgets are finite and the highest-value work is often the work that removes the largest remaining exposure, not the work that looks best on average.

This is why marginal return is useful for prioritisation across controls, programs, and remediation backlogs. A strong current control can still have low marginal value for the next increment, while a weaker area may deliver a disproportionate gain from one focused improvement. In that sense, marginal return is less about abstract efficiency and more about identifying the next best place to spend scarce security capacity.

How marginal return differs from average return

Average return tells you what has been achieved across all prior input. Marginal return tells you what the next input is likely to achieve right now. Those are not the same decision, and confusing them often leads teams to keep funding mature areas simply because they have historically performed well.

The distinction is especially important in security architecture, where diminishing returns are common. Once a control is broadly effective, further investment may yield only small gains unless the environment changes. By contrast, an area with concentrated weakness, such as exposed secrets, weak revocation, or poor visibility, can offer much higher marginal benefit because the first meaningful fix removes a large amount of residual risk. NHIMG research on NHI risk highlights that 97% of NHIs carry excessive privileges and only 5.7% of organisations have full visibility into their service accounts, which is exactly the kind of condition where the next unit of effort can matter far more than the average.

Where marginal return shows up in security operations

Marginal return is most visible when teams are choosing between multiple valid security investments. For example, one more hardening task on an already mature platform may produce little change, while one more effort spent on vaulting, rotating, or revoking credentials may remove a broad class of exposure. In practice, the highest marginal return often comes from controls that collapse a large number of downstream failure modes at once.

It also helps explain why some security work is high leverage and some is not. Improving detection on an asset class that is already well instrumented may add limited value, whereas closing a blind spot can sharply improve both response speed and assurance. For identity and secret-heavy environments, that often means prioritising the places where access persists too long, visibility is weak, or revocation is incomplete, because those gaps create outsized exposure relative to the effort required to fix them.

Why marginal return matters for prioritisation and governance

Good governance depends on spending where the security outcome changes most, not where the organisation is merely most comfortable investing. Marginal return gives decision-makers a defensible way to compare remediations, especially when multiple teams all believe their work is urgent. It keeps the focus on actual risk reduction per additional unit of effort.

It also supports more honest trade-offs between resilience, control coverage, and operating cost. When a control reaches a point of diminishing returns, continuing to fund it may be rational only if the remaining exposure is still material. When that is not true, the better choice is to shift effort to the subsystem where the next increment will materially change the security posture, such as identity governance, secrets hygiene, or remediation speed. For a broader control lens, the NIST Cybersecurity Framework 2.0 remains useful for structuring those prioritisation choices, while the NIST Cybersecurity Framework 2.0 and NIST SP 800-53 Rev 5 Security and Privacy Controls help map return-to-control decisions to governance and protection outcomes. When the focus is on non-human identity exposure, the OWASP Non-Human Identity Top 10 is a useful companion because it highlights the exact control gaps, such as overprivilege and secret sprawl, where marginal improvements often produce the largest security gain.

Risk and Threat Considerations

Marginal return becomes risky when organisations mistake a plateau for completion. Once the easiest improvements are done, the remaining exposure is often concentrated in harder-to-see areas, so underfunding the next increment can leave high-impact gaps open for much longer than expected. That is particularly true where compromised secrets or overprivileged access can be reused at scale.

Failure mechanism: Teams stop investing once average performance looks acceptable, even though the next improvement would remove a disproportionate share of residual exposure. Attackers then benefit from the left-behind gaps, especially in areas with broad privilege, weak rotation, or poor visibility.

Impact: The result is inefficient spending and avoidable compromise paths, because the organisation keeps funding low-yield work while the highest-value exposure remains open.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM — Risk Management StrategyMarginal return guides which security investment reduces risk most per additional unit of effort.
PR.AC — Access ControlControl value changes sharply when additional access reduction removes disproportionate exposure.
Recommendation — Prioritise controls that deliver the largest risk reduction for the next unit of spend or effort. Target access reductions where one more restriction materially lowers residual exposure.
CIS Controls v8CIS 5 — Account ManagementMarginal return often peaks when account and access changes remove broad privilege or dormant access.
CIS 6 — Access Control ManagementThe term maps to choosing the next access-control action with the highest security payoff.
Recommendation — Focus account management effort on the changes that eliminate the most unused or excessive access. Apply access-control changes where the next step most reduces attack surface and misuse potential.
OWASP Non-Human Identity Top 10NHI-02 — Secret Management and RotationMarginal return is high where one more rotation or vaulting action removes concentrated secret exposure.
NHI-03 — Privilege and Permissions ManagementExcessive privilege creates strong marginal gains when reduced because each change removes broad abuse paths.
Recommendation — Prioritise secret rotation and vaulting where each fix removes the most high-risk exposure. Reduce privilege where the next entitlement change closes the widest abuse path.

Practitioner Guidance

Governance implication: Treat marginal return as a prioritisation test, not a retrospective performance metric. The practical question is whether the next unit of effort materially changes exposure, resilience, or control coverage more than the next best alternative.

Practitioner takeaway: If the next improvement does not change the risk picture in a meaningful way, move the budget and attention to the subsystem where it will.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org