Return on Security Investment
Return on Security Investment (ROSI) is a way to estimate the value an organization gets from its security spending relative to the risk that spending reduces. It adapts the familiar return on investment idea to security by weighing the cost of security measures against the losses those measures are expected to help avoid. It is often used to help justify budgets and connect security decisions to business risk.
ROSI is a modified return on investment (ROI) calculation applied to security, in which the net benefit is typically expressed as the value of expected losses avoided, such as the annual cost of security breaches prevented, measured against the cost of the security investment. It is used to assess the effectiveness of cybersecurity investments and to link risk, security, and insurance for managing cyber exposure. As an estimate, its reliability depends heavily on the quality of underlying loss and probability assumptions, which are often uncertain; practitioners should treat ROSI as a decision-support and budget-justification tool rather than a precise or guaranteed measure of realized returns.
Why it matters
Security spending has historically been difficult to justify to boards and finance leaders because its primary output is the absence of a bad outcome, losses that never occurred. Return on Security Investment (ROSI) matters because it attempts to translate that intangible benefit into the language executives already use for capital allocation, weighing the cost of a security measure against the value of the losses it is expected to help avoid. This gives security leaders a structured way to connect a proposed investment to business risk rather than presenting it as an open-ended technical cost.
ROSI also has value as a communication and prioritization framework. As Aon describes, a ROSI approach can help organizations link risk, security, and insurance together to manage overall cyber exposure and increase resilience, positioning security spending as one lever among several for treating risk rather than an isolated expense. For virtual and fractional CISOs, who are frequently engaged specifically to build governance and justify budgets, ROSI can be a useful lens for framing recommendations in terms an executive audience will accept.
That said, ROSI's usefulness is bounded by the quality of its inputs. Because the calculation depends on estimated loss values and estimated probabilities of events that may not occur, it is a decision-support estimate rather than a guaranteed measure of realized return. Treating a ROSI figure as a precise financial promise, rather than as a reasoned argument built on stated assumptions, is a common misuse that experienced practitioners are careful to avoid.
Who it's relevant to
Inside ROSI
Common questions
Answers to the questions practitioners most commonly ask about ROSI.