Current approaches in the area of proposed measures in the cyber risk management process usually do not take into account the costs of security measures. The goal is to systematically and comprehensively evaluate the proposed SW tools as an investment in security measures from the point of view of respecting the basic economic condition: "It is appropriate to invest only enough financial resources in security measures so that the costs are proportional to the potential amount of imminent damage."