David Rice, SANS Instructor and Security Guru has a new book coming out this October called, Geekonomics: The Real Cost of Insecure Software. It's now available on Amazon.com.
I heard a brief introduction on this very topic in David Rice's Security 616: Defensible .NET class at SANS Network Security 2006 in Las Vegas and found it eye opening - I'll be pre-ordering this one.
If you'd like to get a taste of what the book will have to offer, David Rice will be giving a talk on this exact topic at SANS@Night at SANS Network Security 2007 in Las Vegas that I'm really looking forward to.

