Build a ROSI case for a control: ALE before and after, total annual cost, net benefit, payback, discounted NPV and the break-even mitigation rate.
The break-even mitigation rate is the most useful output because it inverts the hardest assumption: instead of defending a claim that the control removes 65% of the loss, you only have to argue that it removes more than the break-even figure. Productivity cost is included because controls that slow people down have a real price, and NPV is shown separately since a control with a positive annual return can still fail to justify its up-front spend. Security spending competes with everything else for capital, and finance functions discount arguments that arrive without an ALE, a cost and a payback period. ALE is the product of two estimates, so treat ROSI as a way to rank competing controls rather than as a forecast return.
Security Investment ROI
ROSI = (ALE reduction − total annualised cost) ÷ total annualised cost, where ALE = SLE × ARO and the reduction is ALE × mitigation rate.
NPV and break-even
NPV = annual cash benefit × annuity factor − implementation cost, with annuity factor = (1 − (1 + r)^−n) ÷ r; break-even mitigation = total annual cost ÷ ALE before.
ROSI = (ALE reduction − total annualised cost) ÷ total annualised cost, where ALE = SLE × ARO and the reduction is ALE × mitigation rate. The break-even mitigation rate is the most useful output because it inverts the hardest assumption: instead of defending a claim that the control removes 65% of the loss, you only have to argue that it removes more than the break-even figure. Productivity cost is included because controls that slow people down have a real price, and NPV is shown separately since a control with a positive annual return can still fail to justify its up-front spend.
Security spending competes with everything else for capital, and finance functions discount arguments that arrive without an ALE, a cost and a payback period. ALE is the product of two estimates, so treat ROSI as a way to rank competing controls rather than as a forecast return.
This calculator takes 8 inputs: Single loss expectancy, Annual rate of occurrence before the control, Share of the loss the control removes, One-off implementation cost, Annual licence and operating cost, Annual productivity or friction cost, Years to amortise the implementation, Discount rate. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Use external frequency data as a starting anchor, express the answer as a range rather than a point, and be honest that a one-in-twenty-year event is a guess. Then use the break-even mitigation rate and a sensitivity run at half and double your ARO: if the decision holds across the range, the imprecision does not matter.
Because it is often the largest real cost and the one that gets omitted. A control that adds thirty seconds to a workflow performed a thousand times a day costs more in aggregate than its licence, and ignoring it is how controls get deployed and then quietly bypassed.