Skip to content
Calcrivo

Security Investment ROI Calculator

Build a ROSI case for a control: ALE before and after, total annual cost, net benefit, payback, discounted NPV and the break-even mitigation rate.

Inputs

$
per year
%
$
$
$
years
%

Return on Security Investment

56.0%

ALE Before the Control

$720,000

ALE After the Control

$252,000

Annual Loss Avoided

$468,000

Total Annualised Cost

$300,000

Annual Net Benefit

$168,000

Payback Period

17.0months

Net Present Value

$369,517

Break-Even Mitigation Rate

41.7%

Investment Verdict

Positive but sensitive — the case rests on the mitigation estimate, so state that assumption explicitly when you present it

Step by step

  1. Values used

    Single loss expectancy = 1,800,000 $; Annual rate of occurrence before the control = 0.4000 per year; Share of the loss the control removes = 65 %; One-off implementation cost = 450,000 $; Annual licence and operating cost = 120,000 $; Annual productivity or friction cost = 30,000 $; Years to amortise the implementation = 3 years; Discount rate = 8 %

  2. Security Investment ROI

    ROSI = (ALE reduction − total annualised cost) ÷ total annualised cost, where ALE = SLE × ARO and the reduction is ALE × mitigation rate.

  3. NPV and break-even

    NPV = annual cash benefit × annuity factor − implementation cost, with annuity factor = (1 − (1 + r)^−n) ÷ r; break-even mitigation = total annual cost ÷ ALE before.

  4. Return on Security Investment

    = 56.0

  5. ALE Before the Control

    = 720,000

  6. ALE After the Control

    = 252,000

  7. Annual Loss Avoided

    = 468,000

  8. Total Annualised Cost

    = 300,000

  9. Annual Net Benefit

    = 168,000

How it works

The break-even mitigation rate is the most useful output because it inverts the hardest assumption: instead of defending a claim that the control removes 65% of the loss, you only have to argue that it removes more than the break-even figure. Productivity cost is included because controls that slow people down have a real price, and NPV is shown separately since a control with a positive annual return can still fail to justify its up-front spend. Security spending competes with everything else for capital, and finance functions discount arguments that arrive without an ALE, a cost and a payback period. ALE is the product of two estimates, so treat ROSI as a way to rank competing controls rather than as a forecast return.

Formulas

Security Investment ROI

ROSI = (ALE reduction − total annualised cost) ÷ total annualised cost, where ALE = SLE × ARO and the reduction is ALE × mitigation rate.

ALE
Annualised loss expectancy = single loss expectancy × annual rate of occurrence
mitigation rate
Share of the annualised loss the control actually removes
total annualised cost
Amortised implementation + annual run cost + productivity cost

NPV and break-even

NPV = annual cash benefit × annuity factor − implementation cost, with annuity factor = (1 − (1 + r)^−n) ÷ r; break-even mitigation = total annual cost ÷ ALE before.

r
Discount rate
n
Amortisation years
break-even mitigation
The mitigation rate at which the control exactly pays for itself

Frequently Asked Questions

How is Security Investment ROI calculated?

ROSI = (ALE reduction − total annualised cost) ÷ total annualised cost, where ALE = SLE × ARO and the reduction is ALE × mitigation rate. The break-even mitigation rate is the most useful output because it inverts the hardest assumption: instead of defending a claim that the control removes 65% of the loss, you only have to argue that it removes more than the break-even figure. Productivity cost is included because controls that slow people down have a real price, and NPV is shown separately since a control with a positive annual return can still fail to justify its up-front spend.

Why does Security Investment ROI matter?

Security spending competes with everything else for capital, and finance functions discount arguments that arrive without an ALE, a cost and a payback period. ALE is the product of two estimates, so treat ROSI as a way to rank competing controls rather than as a forecast return.

What values do I need to enter?

This calculator takes 8 inputs: Single loss expectancy, Annual rate of occurrence before the control, Share of the loss the control removes, One-off implementation cost, Annual licence and operating cost, Annual productivity or friction cost, Years to amortise the implementation, Discount rate. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

How do I estimate the ARO for something that has never happened?

Use external frequency data as a starting anchor, express the answer as a range rather than a point, and be honest that a one-in-twenty-year event is a guess. Then use the break-even mitigation rate and a sensitivity run at half and double your ARO: if the decision holds across the range, the imprecision does not matter.

Why include productivity cost?

Because it is often the largest real cost and the one that gets omitted. A control that adds thirty seconds to a workflow performed a thousand times a day costs more in aggregate than its licence, and ignoring it is how controls get deployed and then quietly bypassed.

You might also need