Security Investment ROI Calculator
Build a ROSI case for a control: ALE before and after, total annual cost, net benefit, payback, discounted NPV and the break-even mitigation rate.
Inputs
Return on Security Investment
56.0%
ALE Before the Control
$720,000
ALE After the Control
$252,000
Annual Loss Avoided
$468,000
Total Annualised Cost
$300,000
Annual Net Benefit
$168,000
Payback Period
17.0months
Net Present Value
$369,517
Break-Even Mitigation Rate
41.7%
Investment Verdict
Positive but sensitive — the case rests on the mitigation estimate, so state that assumption explicitly when you present it
Step by step
Values used
Single loss expectancy = 1,800,000 $; Annual rate of occurrence before the control = 0.4000 per year; Share of the loss the control removes = 65 %; One-off implementation cost = 450,000 $; Annual licence and operating cost = 120,000 $; Annual productivity or friction cost = 30,000 $; Years to amortise the implementation = 3 years; Discount rate = 8 %
Security Investment ROI
ROSI = (ALE reduction − total annualised cost) ÷ total annualised cost, where ALE = SLE × ARO and the reduction is ALE × mitigation rate.
NPV and break-even
NPV = annual cash benefit × annuity factor − implementation cost, with annuity factor = (1 − (1 + r)^−n) ÷ r; break-even mitigation = total annual cost ÷ ALE before.
Return on Security Investment
= 56.0
ALE Before the Control
= 720,000
ALE After the Control
= 252,000
Annual Loss Avoided
= 468,000
Total Annualised Cost
= 300,000
Annual Net Benefit
= 168,000
How it works
The break-even mitigation rate is the most useful output because it inverts the hardest assumption: instead of defending a claim that the control removes 65% of the loss, you only have to argue that it removes more than the break-even figure. Productivity cost is included because controls that slow people down have a real price, and NPV is shown separately since a control with a positive annual return can still fail to justify its up-front spend. Security spending competes with everything else for capital, and finance functions discount arguments that arrive without an ALE, a cost and a payback period. ALE is the product of two estimates, so treat ROSI as a way to rank competing controls rather than as a forecast return.
Formulas
Security Investment ROI
ROSI = (ALE reduction − total annualised cost) ÷ total annualised cost, where ALE = SLE × ARO and the reduction is ALE × mitigation rate.
- ALE
- Annualised loss expectancy = single loss expectancy × annual rate of occurrence
- mitigation rate
- Share of the annualised loss the control actually removes
- total annualised cost
- Amortised implementation + annual run cost + productivity cost
NPV and break-even
NPV = annual cash benefit × annuity factor − implementation cost, with annuity factor = (1 − (1 + r)^−n) ÷ r; break-even mitigation = total annual cost ÷ ALE before.
- r
- Discount rate
- n
- Amortisation years
- break-even mitigation
- The mitigation rate at which the control exactly pays for itself
Frequently Asked Questions
How is Security Investment ROI calculated?
ROSI = (ALE reduction − total annualised cost) ÷ total annualised cost, where ALE = SLE × ARO and the reduction is ALE × mitigation rate. The break-even mitigation rate is the most useful output because it inverts the hardest assumption: instead of defending a claim that the control removes 65% of the loss, you only have to argue that it removes more than the break-even figure. Productivity cost is included because controls that slow people down have a real price, and NPV is shown separately since a control with a positive annual return can still fail to justify its up-front spend.
Why does Security Investment ROI matter?
Security spending competes with everything else for capital, and finance functions discount arguments that arrive without an ALE, a cost and a payback period. ALE is the product of two estimates, so treat ROSI as a way to rank competing controls rather than as a forecast return.
What values do I need to enter?
This calculator takes 8 inputs: Single loss expectancy, Annual rate of occurrence before the control, Share of the loss the control removes, One-off implementation cost, Annual licence and operating cost, Annual productivity or friction cost, Years to amortise the implementation, Discount rate. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
How do I estimate the ARO for something that has never happened?
Use external frequency data as a starting anchor, express the answer as a range rather than a point, and be honest that a one-in-twenty-year event is a guess. Then use the break-even mitigation rate and a sensitivity run at half and double your ARO: if the decision holds across the range, the imprecision does not matter.
Why include productivity cost?
Because it is often the largest real cost and the one that gets omitted. A control that adds thirty seconds to a workflow performed a thousand times a day costs more in aggregate than its licence, and ignoring it is how controls get deployed and then quietly bypassed.