ROI: Expert Advice for Building the Case for Security Investment

Making a convincing case for security investment requires a combination of technical knowledge and business-oriented communication. Cybersecurity ROI is based on four main pillars: lower operating costs, regulatory compliance, reduced risk, and new business opportunities. Cost reduction and compliance can strengthen the justification for an initiative. However, the greatest value comes from connecting risk mitigation with the organization’s broader strategy. Security leaders need to collaborate with executives, develop practical impact estimates, and present security as a strategic business enabler rather than an expense.

The challenges of calculating ROI in IT security

Recent discussions have repeatedly focused on the need to justify security expenditure. IT budgets are generally not increasing. In addition, funds that had already been approved have often needed to be redirected toward changing business priorities. At the same time, executives and board members have become increasingly aware of modern cyber risks and the potential consequences of ignoring them. They expect IT teams and security leaders to provide reliable data that supports effective decisions about security investment.

This is where many organizations encounter an unexpected obstacle. For decades, IT and information security were viewed primarily as technical disciplines. As a result, highly skilled technical specialists were often promoted into IT leadership roles. These professionals can explain even the most complex technology-related issue. However, not all of them are equally comfortable communicating in business terms. This gap can prevent both sides from reaching productive decisions.

A lack of reliable factual data creates another challenge for IT leaders. Technology work is normally based on facts, accurate metrics, and defensible measurements. For instance, teams can report the number of security incidents recorded during a specific period. They can also measure how long it takes to patch a vulnerable server. Estimating the expected return on a security investment is much more difficult because the calculation often depends on assumptions and probabilities. This uncertainty takes many IT professionals outside their usual area of expertise.

Experts from Netwrix analysed existing approaches and practices in this area.

The four pillars of security ROI

When security investments in people, processes, or technology are being discussed, one central question needs to be answered: How can the investment generate measurable value? The responses can differ significantly, but they usually fall into one or more of four categories:

  • The investment will lower ongoing operational costs.
  • The investment will support compliance with contractual requirements, industry standards, or government regulations.
  • The investment will reduce business risk by lowering its probability, its potential impact, or both.
  • The investment will enable new business opportunities.

Each of these outcomes can provide a valid reason for approving an investment. However, their role in the overall business case and the way they should be combined require closer examination.

Operational cost savings

Lower operating expenses are among the clearest measures of ROI. This is particularly relevant when the CIO or head of IT is also responsible for information security. A project may reduce storage requirements, consolidate software licenses, or decrease the amount of time and manual effort required through automation. In such cases, the financial return can usually be calculated with a reasonable degree of confidence.

However, cost savings should never be the only justification for a security investment. The primary purpose of information security is to manage risk. Any project that does not begin with a risk-related objective creates a weak foundation for the investment decision. Nevertheless, operational savings can provide a strong supporting argument for an initiative that also addresses a risk the organization considers important.

Compliance

Organizations understand that compliance with applicable regulations is necessary to remain in business. Many information security teams use this requirement to position new security initiatives as essential for regulatory compliance. Professional communities and industry conferences frequently recommend using compliance obligations as a source of funding for security programs.

In general, regulations are designed to establish minimum requirements for protecting specific categories of data or certain business activities. However, no regulation can provide a universal security framework that fully addresses the unique characteristics of every organization, the threats it currently faces, and the conditions that exist at a specific point in time.

Compliance can be an effective starting point for an ROI discussion. It can also attract executive attention in organizations with a lower level of security maturity, where leadership may not yet fully understand the relevant business risks. At the same time, relying too heavily on compliance can be dangerous. Completing every item on a compliance checklist can create a false sense of security, even when significant threats remain unaddressed.

Another potential problem is the perception that the information security team is merely a necessary burden. Executives may tolerate and fund such a function because it is required, while still preferring to eliminate it if regulatory obligations allowed them to do so.

This does not mean that compliance should be excluded from budget discussions. Security leaders need to understand both existing and anticipated regulatory requirements within the organization’s industry and jurisdiction. However, as with operational cost reduction, compliance should not become the primary justification for a security investment.

Risk reduction

The main objective of every information security function is to manage and mitigate risk. However, determining which risks are relevant can be complicated. For example, does a newly discovered vulnerability create a meaningful threat to a specific organization? Should reports about state-sponsored advanced persistent threat groups such as Lazarus influence investment decisions?

The solution is to align information security risk management with the organization’s wider business risk management framework. Organizations in the defense and financial sectors often have mature and well-established risk management strategies. Some also have a dedicated Chief Risk Officer. Where such a position exists, that individual can provide valuable guidance on the organization’s established approach to evaluating risk. However, every organization continuously makes risk-related decisions, even when no formal risk management function exists. In many cases, responsibility for those decisions belongs to the CFO and CEO.

Their guidance should be used to create a coordinated and consistent risk management strategy across the organization. Without business involvement, the security team may duplicate existing work or overlook genuine threats because the relevant business context was not considered.

Estimating the financial impact of a risk and the extent to which it can be reduced will require expert judgment. However, expert judgment should not be confused with unsupported assumptions. A two-part approach can help produce more reliable estimates:

Use internal knowledge. Review the organization’s existing business risk management practices and apply the same methodology consistently. This requires cooperation with the C-suite and their input when estimating potential losses.

Use external knowledge. Relevant CISO communities, professional groups, and industry forums can provide valuable insight based on the experience of other organizations. Industry research is another useful source of information, including reports such as the Cost of a Data Breach Report produced by the Ponemon Institute and sponsored by IBM.

The process should not be made unnecessarily complex. The organization should agree on a practical methodology and apply it consistently. After several quarters, the collected data should make it possible to identify and demonstrate trends, as well as refine the approach when necessary.

Business opportunity

The concept of security as a business enabler has been discussed at industry events for several years. Although this idea is widely supported, relatively few organizations successfully turn it into practice.

As with the other components of ROI, communication plays a critical role. Security leaders need to establish strong working relationships with executives and business unit leaders. Regular communication allows security requirements to become part of discussions about new projects from the beginning. Security can then be incorporated into the implementation plan instead of being added after major decisions have already been made.

Security leadership does not own the broader business initiative and therefore cannot reliably calculate the total return generated by that opportunity. However, producing such an estimate is not necessary.

New initiatives can still be referenced during ROI discussions as examples of opportunities that depend on appropriate security controls. Specific financial figures do not need to be assigned to those opportunities when the security team does not have enough information to calculate them accurately.

Conclusion

A practical assessment of cybersecurity ROI begins with expert judgment. The level of risk reduction associated with each investment should be estimated using the information available. Absolute precision is not always possible, and some uncertainty must be accepted. Risk management expertise may already exist elsewhere in the organization, so established internal methodologies should be studied and reused whenever appropriate. Available tools, historical information, and industry data should also support the assessment.

Security leaders also need to communicate in business terms. Information security is not exclusively a technical concern. Collaboration with the CFO, CRO, and CEO can improve the security team’s understanding of business risk. At the same time, these discussions can help executive leaders develop a clearer understanding of cybersecurity. A comprehensive risk management program that addresses financial, reputational, operational, and security risks can strengthen the organization in multiple areas.

Open communication with leaders across the business is equally important. Security investment can and often should be included in new projects and emerging business opportunities. Early involvement makes it easier to position security as a strategic initiative rather than a cost center.

Finally, all four ROI arguments should be used in a balanced way. Risk reduction should remain the starting point. However, every investment should also be evaluated according to its ability to support compliance, lower operating expenses, and enable new business opportunities.

Subscribe to news