by Scott Berinato

Calculating Return on Security Investment

Feb 15, 2002
IT Strategy

T is the cost of the intrusion detection tool.

To determine our return on security investment (ROSI) we simply subtract what we expect to lose in a year (ALE) from the annual cost of intrusion.

Doing this equation yields the Annual Loss Expectancy.

E is the dollar savings gained by stopping any number of intrusions through the introduction of an intrusion detection tool.

R is the cost per year to recover from any number of intrusions.

(R-E) + T = ALE

R – (ALE) = ROSI

The Earlier You Invest in Security, the Greater the Return

Researchers found that you get a 21% return on your security investment at the software design phase, a 15% return at the implementation stage and a 12% return at the testing stage.

RETURN on security investment


source: MIT/Stanford/@stake

