In an academic paper to be presented next month at the University of Cambridge in England, a research team will make a compelling and somewhat surprising mathematical case for how enterprises should spend their IT security budgets. The three researchers, from the Florida Atlantic University in Boca Raton, looked at how companies can evaluate their vulnerabilities, analyze the risk and calculate the potential for damage. Rather than spending evenly to guard against all attacks, it’s not necessarily the right approach if one kind of breach could cause many times more damage than another kind.