I am afraid your question is too broad. The factors would depend on each independent case, and the answer can only be given after having performed an information security risk assessment. A popular way of approaching this is by using ISO/IEC 27005.
Multi-Criteria Decision-Making (MCDM, also known as Multi-Criteria Decision Analysis, MCDA) involves making decisions based on considering multiple criteria (or objectives).
Trade-offs between the criteria are assessed in order to rank, prioritize or choose from among competing alternatives – depending on the application, often subject to a budget, or other resource, constraint.
The information presented here is practical and user-oriented:
Multi-criteria decisions
Points systems , Applications
Groups and websites
The process of Multi-Criteria Decision-Making (MCDM)
1000minds is based on MCDM (also known as Multi-Criteria Decision Analysis, MCDA) which involves these four key components:
Alternatives (or individuals) to be prioritized or ranked
Criteria by which the alternatives are evaluated and compared
Weights representing the relative importance of the criteria
Decision-makers and other stakeholders, whose preferences are to be represented
Multi-criteria decision making (MCDM) for cybersecurity involves using methods like Analytic Hierarchy Process (AHP) or Analytic Network Process (ANP) to prioritize security measures, assess risks, allocate resources, and make informed decisions considering multiple criteria such as threat severity, cost-effectiveness, and organizational priorities.