Skip to main content
Category: Security Economics & Investment

Return on Security Investment

Also known as: ROSI, RoSI, Return on Security Investments
Simply put

Return on Security Investment (ROSI) is a way to estimate the value an organization gets from its security spending relative to the risk that spending reduces. It adapts the familiar return on investment idea to security by weighing the cost of security measures against the losses those measures are expected to help avoid. It is often used to help justify budgets and connect security decisions to business risk.

Formal definition

ROSI is a modified return on investment (ROI) calculation applied to security, in which the net benefit is typically expressed as the value of expected losses avoided, such as the annual cost of security breaches prevented, measured against the cost of the security investment. It is used to assess the effectiveness of cybersecurity investments and to link risk, security, and insurance for managing cyber exposure. As an estimate, its reliability depends heavily on the quality of underlying loss and probability assumptions, which are often uncertain; practitioners should treat ROSI as a decision-support and budget-justification tool rather than a precise or guaranteed measure of realized returns.

Why it matters

Security spending has historically been difficult to justify to boards and finance leaders because its primary output is the absence of a bad outcome, losses that never occurred. Return on Security Investment (ROSI) matters because it attempts to translate that intangible benefit into the language executives already use for capital allocation, weighing the cost of a security measure against the value of the losses it is expected to help avoid. This gives security leaders a structured way to connect a proposed investment to business risk rather than presenting it as an open-ended technical cost.

ROSI also has value as a communication and prioritization framework. As Aon describes, a ROSI approach can help organizations link risk, security, and insurance together to manage overall cyber exposure and increase resilience, positioning security spending as one lever among several for treating risk rather than an isolated expense. For virtual and fractional CISOs, who are frequently engaged specifically to build governance and justify budgets, ROSI can be a useful lens for framing recommendations in terms an executive audience will accept.

That said, ROSI's usefulness is bounded by the quality of its inputs. Because the calculation depends on estimated loss values and estimated probabilities of events that may not occur, it is a decision-support estimate rather than a guaranteed measure of realized return. Treating a ROSI figure as a precise financial promise, rather than as a reasoned argument built on stated assumptions, is a common misuse that experienced practitioners are careful to avoid.

Who it's relevant to

Virtual and Fractional CISOs
vCISOs and fractional CISOs are frequently engaged to build security governance and justify budgets to non-technical leadership. ROSI gives them a structured way to frame proposed investments in business risk terms. Because these engagements advise and direct rather than assume organizational accountability, the CISO's role is typically to build the ROSI case and its assumptions transparently, while final spending and risk-acceptance decisions remain with the client's officers.
Boards and Executive Leadership
Boards and executives responsible for capital allocation use ROSI-style reasoning to weigh security spending against expected losses avoided. It helps them compare security proposals to other business investments, though they should understand that ROSI is an estimate whose credibility depends on the assumptions behind it, not a guaranteed financial return.
Finance and FP&A Teams
Finance and financial planning teams contribute to and scrutinize the loss and probability assumptions that drive ROSI calculations. Their involvement helps ground security estimates in the organization's broader financial modeling and ensures inputs are documented and defensible rather than arbitrary.
Risk and Insurance Managers
A ROSI framework can help organizations link risk, security, and insurance to manage overall cyber exposure. Risk and insurance managers can use it to evaluate whether a given exposure is better addressed through controls, through transfer via insurance, or through a combination, supporting a more holistic view of cyber resilience.

Inside ROSI

Cost of the Security Investment
The total expenditure associated with a security control, program, or engagement, which may include licensing, staffing, tooling, and the cost of advisory services such as a virtual CISO. In many analyses this is expressed over a defined time period to allow comparison against expected loss reduction.
Expected or Avoided Loss
An estimate of the financial impact a security investment is expected to reduce, often derived from concepts such as annualized loss expectancy or the modeled reduction in likelihood or severity of an incident. These figures are typically estimates and can vary significantly by organization, threat environment, and assumptions used.
Risk Reduction Factor
The proportion by which a control or program is expected to lower the frequency or impact of a loss event. This is a modeled input rather than a guaranteed outcome, and its accuracy depends heavily on the quality of underlying data and assumptions.
ROSI Calculation Output
The resulting ratio or percentage that expresses the value generated relative to the cost of a security investment. It is a decision-support metric used to compare options and communicate value to executives, not a precise prediction of actual returns.
Governance and Business Context
The organizational risk appetite, regulatory obligations, and strategic priorities that frame how ROSI is interpreted. A virtual CISO often helps translate technical control decisions into this business risk context so that ROSI supports governance-level conversations rather than purely technical ones.

Common questions

Answers to the questions practitioners most commonly ask about ROSI.

Does a positive ROSI calculation prove that a security investment prevented a breach?
No, and treating it that way is a common mistake. ROSI is a decision-support estimate built on modeled loss expectancy and assumed risk reduction, not a measurement of breaches that were actually stopped. Because avoided incidents are counterfactual, you generally cannot observe them directly. A positive ROSI suggests an investment is expected to reduce anticipated loss relative to its cost given your assumptions; it does not confirm that any specific attack was averted. A virtual CISO can help frame ROSI as one input to risk-based prioritization rather than as proof of outcome.
Is ROSI a precise financial metric like ROI that produces a reliable, objective number?
Not in the way traditional ROI is often assumed to be. ROSI typically relies on estimated inputs such as expected loss, probability of an incident, and the percentage of risk mitigated, all of which carry significant uncertainty. The output should be understood as a directional estimate that varies with the assumptions used, and results can differ substantially depending on the data and methodology applied. It is most useful for comparing options and communicating tradeoffs to executives, not for asserting an exact, guaranteed financial return.
What inputs do I typically need to calculate ROSI for a proposed control?
In many engagements, ROSI calculations draw on an estimate of expected loss from a given risk (often expressed as annualized loss expectancy), an estimate of how much that loss would be reduced by the control, and the total cost of implementing and maintaining the control. Because these figures are frequently estimates rather than measured values, it helps to document the sources and assumptions behind each one and to note their uncertainty. A virtual CISO can advise on structuring these inputs but the underlying loss and probability data usually depend on client-provided context.
How can I use ROSI to prioritize among competing security investments?
ROSI is often applied comparatively rather than as a standalone verdict. By modeling estimated risk reduction against cost for several candidate investments, you can rank options and surface where limited budget may yield the greatest expected risk reduction. It is generally advisable to pair ROSI comparisons with qualitative factors such as regulatory obligations, organizational maturity, and risk appetite, since a purely numeric ranking can understate governance and business-risk considerations that a security leadership function is meant to weigh.
How should I present ROSI figures to executives and the board without overstating them?
It is often effective to present ROSI as a range or scenario-based estimate rather than a single figure, and to state the key assumptions explicitly so decision-makers understand the sensitivity of the result. Framing the output with qualified language, and clarifying that it supports prioritization rather than guaranteeing outcomes such as breach prevention, helps set accurate expectations. Because accountability for the resulting decisions typically remains with client officers, presenting ROSI transparently supports informed choices rather than implying the metric itself carries the decision.
What are the main limitations to keep in mind when relying on ROSI?
ROSI's usefulness depends heavily on the quality of its inputs, and small changes in estimated probability or loss can materially shift the result. It does not capture every relevant factor, such as compliance requirements, reputational considerations, or interdependencies between controls, and it cannot confirm that modeled risk reductions will occur in practice. Its value also tends to depend on organizational maturity and access to reliable data. For these reasons ROSI is best treated as one qualified input within a broader risk management and governance process rather than a definitive answer.

Common misconceptions

ROSI produces a precise, guaranteed financial return that proves an investment will prevent breaches.
ROSI is a modeling and decision-support tool built on estimates and assumptions. It can inform prioritization and communicate expected value, but it does not guarantee outcomes such as breach prevention, and its inputs may vary considerably by organization.
Calculating ROSI is a hands-on operational task that a virtual CISO executes as part of running security tools.
A virtual CISO typically supports ROSI as a strategy, governance, and risk management activity, advising on assumptions and helping frame investment decisions. This is an executive-level advisory function and is distinct from operational tasks such as SOC monitoring or tool administration, which are generally out of scope unless explicitly contracted.
A favorable ROSI figure means the organization has transferred accountability for the security decision to the vCISO or provider.
A virtual CISO advises on and directs the analysis, but legal and organizational accountability for security investment decisions usually remains with the client organization and its officers unless a contract specifies otherwise.

Best practices

Document the assumptions behind loss estimates and risk reduction factors explicitly, and treat ROSI outputs as estimates that may vary rather than fixed predictions.
Use ROSI as one input among several for prioritizing security investments, alongside regulatory obligations, risk appetite, and organizational maturity.
Frame ROSI results in business risk and governance terms so executives can evaluate them, rather than presenting the calculation as a purely technical output.
Clarify in the engagement scope who is responsible for gathering data and building the ROSI model, recognizing that a virtual CISO typically advises rather than performs operational data collection unless contracted to do so.
Revisit ROSI assumptions periodically as the threat environment, control effectiveness, and organizational context change, since inputs can become outdated.
Ensure accountability for the resulting investment decisions remains clearly assigned to the client organization and its officers unless a contract states otherwise.