You get a single team handling cybersecurity, IT, AI consulting, and data integration services like EDI, filling the gaps in your team.
“Corsica is a one-stop shop for us. If I have a problem, I can go to my vCIO or a number of people, and you take care of it. That’s an investment in mutual success.”
– Greg Sopcak | Southern Michigan Bank & Trust
From 24/7 SOC services to MDR/SIEM, penetration testing and training, we’ve got you covered.
Get the expert support you need for your network, on-premises devices, VoiP, M365, Google Workplace, and everything in between.
Full support of compliance frameworks, including CJIS, HIPAA, CMMC, NIST, SOC 2, and more
Cut through the hype with smart strategies and right-fit AI solutions for your organization.
Take strategic steps with confidence as you collaborate with our expert business and vCIO consultants.
Get cloud security, integration, server virtualization, and optimization strategies to reduce your cloud costs.
Connect any data source to any other with robust solutions and managed services.
Stay ahead of the curve, eliminate waste, and grow revenue with next-generation technologies.
Expert consulting, implementation, integration, managed services, and cybersecurity for Microsoft products.
One program. One partner. Complete AI transformation.
It takes dedicated experience to use technology strategically in your industry. That’s why we specialize in certain verticals while offering comprehensive technology services.
From webinars and video tutorials to guides and blogs, we’ve got resources to help you and your team address any technology challenge.
Originally published November 7, 2023. Completely refreshed July 13, 2026.
How do you calculate the ROI of a cybersecurity investment?
It’s a crucial question, particularly if you’re defending a proposed cybersecurity budget to your CFO or board of directors.
Unlike revenue investments, cybersecurity requires a unique calculation called ROSI (return on security investment). This calculation measures loss avoided rather than financial gain.
Here’s everything you need to know to understand the terms, calculate ROSI, and communicate with leadership about cybersecurity investments.
Key takeaways:
Need to quantify your investment?
In cybersecurity, “ROI” is usually expressed as ROSI (return on security investment). This is because security spending protects revenue rather than generating it. Instead of measuring profit gained, ROSI measures loss avoided, such as the breach costs, downtime, and regulatory fines that are prevented by strong cybersecurity controls.
The standard formula is ROSI = (monetary loss avoided − cost of the solution) ÷ cost of the solution, where loss avoided is your annualized loss expectancy multiplied by how effectively the control mitigates that risk. The result reframes an “unprofitable” expense as a quantifiable, defensible return, making it easier for CFOs and board members to understand the financial value of the investment.
The difference between ROI and ROSI comes down to what you’re measuring. Traditional ROI quantifies the profit generated by an investment. You spend money to make more money, and the return is the gain. Cybersecurity investments aren’t intended to produce revenue, so a traditional ROI calculation is the wrong tool to measure the value of the investment.
ROSI (return on security investment) is a better choice. This calculation measures loss avoided instead of income earned. ROSI is conceptually similar to ROI, but ROSI substitutes quantified risk reduction for revenue. This is why security professionals use it to justify spending that protects the business rather than growing revenue.
Here’s how ROI and ROSI compare in detail.
ROI | ROSI | |
Full name | Return on investment | Return on security investment |
What it measures | Profit or revenue gained | Financial loss avoided |
Purpose of the spend | Generate income | Protect revenue, systems, and data |
Core formula | (Net income − cost) ÷ cost | (Loss avoided − cost) ÷ cost |
Key inputs | Revenue, net income | ALE (annualized loss expectancy), mitigation ratio, security investment cost |
The return | New money coming in | Disasters that didn’t happen |
Best suited for | Revenue-generating investments | Security controls and risk reduction |
Audience framing | Growth and profitability | Risk, resilience, and cost avoidance |
The practical takeaway:
Loss avoidance in cybersecurity is the amount of financial loss that an organization avoids by implementing the proper cybersecurity controls.
For an analogy, consider the concept of avoiding shrinkage in retail. Physical security measures, like magnetic tags and detectors at exits, are essential to preventing shoplifting. It’s not enough to say, “We have a small store, and shoplifting probably won’t happen.” In fact, it will happen, and any good retail budget will quantify (and plan for) an acceptable percentage of shrinkage.
Once that expected shrinkage has been quantified in terms of dollars, you know how much loss you’re preventing if you invest in physical security measures. (Of course, no physical security measures are perfect, but these are rough calculations.)
Once you have the quantified loss that you’re preventing, you can express it as a percentage of the cost of the security measures. This is the concept behind ROSI.
As defined by the ENISA (European Network and Information Security Agency), the basic formula for cybersecurity ROSI is:
ROSI = ([ALE x mitigation ratio] – cost of solution) / cost of solution
To use this formula, you’ll need three datapoints:
Here’s what each of these terms means.
This is the total, annualized monetary loss that you can expect from the type of security incident(s) mitigated by the cybersecurity solution. It’s calculated as follows.
ALE = ARO x SLE
This is an estimate of how many times a certain type of cybersecurity incident will occur in one year. If the incident in question typically occurs once per year, ARO = 1. If it typically occurs 5 times per year, ARO = 5.
This is the monetary value of the loss from one occurrence. (See below for average losses incurred by single occurrences of various types of cybersecurity incidents.)
This is the ratio at which the solution in question mitigates the security risks that it addresses. For example, if an email security solution catches 96% of phishing emails, its mitigation ratio is 0.96.
Now let’s put all these together in the formula for cybersecurity ROSI.
Cybersecurity ROI is measured as ROSI (return on security investment), which quantifies loss avoided rather than revenue gained. You work through it in four steps:
The result expresses your security investment as a percentage return, giving you a defensible number to bring to leadership.
Here’s what the process looks like in detail.
Step 1 — Identify your assets and threats. List the incident types that your security investment is meant to prevent, since each carries a different loss profile. In this example, we’ll use a basic managed cybersecurity agreement for a mid-market organization. The solution addresses three primary threats: Ransomware, phishing/business email compromise (BEC), and DDoS.
Step 2 — Estimate probable losses (calculate ALE). For each threat, find its single loss expectancy (SLE, the cost of one occurrence) and its annualized rate of occurrence (ARO, how many times per year it happens), then multiply them: ALE = ARO × SLE. Using conservative illustrative figures for a mid-market organization: ransomware = 0.20 × $2,000,000 = $400,000; phishing/BEC = 0.50 × $500,000 = $250,000; DDoS = 0.50 × $300,000 = $150,000. Add them for a total annualized loss expectancy of $800,000.
Step 3 — Map your controls to risk reduction (apply the mitigation ratio). Determine how effectively the solution stops the attacks it targets, expressed as a mitigation ratio between 0 and 1. This example uses a conservative 75% (0.75) for the solution as a whole, meaning it’s expected to prevent 75% of the total ALE.
Step 4 — Calculate your payback (ROSI). Apply the formula ROSI = ([ALE × mitigation ratio] − cost of solution) ÷ cost of solution. With a total ALE of $800,000, a 0.75 mitigation ratio, and an annual solution cost of $120,000: ROSI = ([$800,000 × 0.75] − $120,000) ÷ $120,000 = ($600,000 − $120,000) ÷ $120,000 = 400%. That percentage is your return, i.e. the loss avoided relative to what you spent. Note that this $120,000 solution still costs less than the fully loaded salary of a single in-house cybersecurity hire, while covering multiple threat types.
Scenario: A mid-market organization is evaluating a managed cybersecurity solution that costs $120,000/year and addresses three threats: ransomware, phishing/business email compromise (BEC), and DDoS. (Note: This is the same scenario we covered above in “How to measure cybersecurity ROI.”)
Threat | SLE (cost per incident) | ARO (occurrences/year) | ALE (SLE × ARO) |
Ransomware | $2,000,000 | 0.20 | $400,000 |
Phishing / BEC | $500,000 | 0.50 | $250,000 |
DDoS | $300,000 | 0.50 | $150,000 |
Total ALE | $800,000 |
The solution is expected to prevent 75% of that loss:
$800,000 × 0.75 = $600,000 in loss avoided.
ROSI = ((ALE × mitigation ratio) − cost of solution) ÷ cost of solution
ROSI = ($600,000 − $120,000) ÷ $120,000
ROSI = $480,000 ÷ $120,000 = 4.0, or 400%
For every $1 spent on the solution, the organization avoids about $5 in expected loss ($600,000 avoided against $120,000 spent). This provides a net benefit valued at $480,000 per year. At 400%, this ROSI calculation sits in the “strong but defensible” band, and the $120,000 cost is still less than the fully-loaded salary of a single in-house security hire while covering three threat types.
One caveat: every figure here is illustrative. As ENISA notes, the ALE inputs are estimates, and your own historical incident data will always produce a more defensible SLE and ARO than industry averages. While this sample calculation can illustrate the concepts, the real value is running this calculation with your own numbers.
A break-even ROSI is the starting point for what’s considered “good.” An ROSI of 100% (a ratio of 1) means the investment exactly pays for itself in avoided loss, and anything above that returns more than it costs.
Beyond that threshold, there’s no widely acknowledge standard for “good/great/excellent.” Higher is better, but only up to the point at which the numbers are still believable. In practice, a strong, defensible ROSI for a mid-market security investment lands somewhere in the low hundreds of percent. Results in the thousands usually signal inflated loss estimates or an overly optimistic mitigation ratio rather than a genuinely spectacular investment. Returns that appear inflated tend to lose a finance audience rather than win it.
What counts as “good” also depends on the cost of the solution. A low-cost control like MFA or email filtering can legitimately post a very high ROSI because its denominator is small, while a broad managed-security platform will show a lower but still healthy return across many threats.
Here are some common ranges for ROSI and how to interpret them.
ROSI range | Interpretation | What it usually means |
Below 0% | Negative return | The solution costs more than the loss it’s expected to avoid; hard to justify on ROSI alone (may still be required for compliance) |
0–100% | Positive but thin | Returns something, but payback is weak; scrutinize whether the cybersecurity solution is the right fit for the scenario |
~100% | Breakeven | The authoritative threshold; the investment pays for itself |
100–300% | Solid, defensible | A reasonable, credible target for a justified security investment; easy to defend to finance |
300–800% | Strong | Common for managed or consolidated services covering multiple threat types |
800–1,500% | Exceptional; verify inputs | Realistic for low-cost, high-impact controls (MFA, email security), but confirm the ALE and mitigation ratio hold up |
Above ~2,000% | Red flag | Almost always indicates inflated ALE or an unrealistic mitigation ratio; may undermine credibility with CFO and/or board |
The fundamental problem is that cybersecurity succeeds by making things not happen. It’s nearly impossible to prove the financial impact of a disaster you prevented. When a breach doesn’t occur, there’s no invoice or downtime disrupting operations.
That’s the conceptual trap at the heart of cybersecurity ROI: you’re trying to measure the cost of events that will never appear on any ledger if the investment is successful. ENISA frames this bluntly, describing the task as estimating money saved from losses that may never happen—an exercise that requires more than plugging numbers into a formula.
The estimation problem compounds because the two variables that matter most are the hardest to pin down:
Both are educated guesses about hypotheticals, and small changes in either one can swing the result significantly.
There’s also a psychological dimension that makes it hard to quantify the value of the disaster-that-didn’t-happen. Success in cybersecurity is invisible, while failure is spectacular. A year with no breaches looks identical to a year when you were simply lucky, so the teams and tools doing their jobs well generate no visible evidence of their worth. This is the paradox every CISO lives with, and it’s the real reason that ROSI matters despite its imperfections: not because the number is precise, but because the exercise forces a structured, defensible conversation about risk in a domain where the most successful outcome is, by definition, that nothing happened at all.
IANS Research reports that across industries, companies spend an average of 10.9% of IT budget on cybersecurity. In the real world, that average represents a wide range. We find that most companies spend roughly 8-18% of their IT budget on cybersecurity. The exact number will depend on many factors, such as your industry, your regulatory requirements (if any), and your revenue size. Economies of scale tend to drive down the overall percentage for larger companies.
Here are typical spending ranges as a percentage of IT budget in various industries.
Industry | Cybersecurity as % of IT budget | Primary driver |
Financial services | ~12–18% | High regulation (GLBA, PCI-DSS), high-value target; banks commonly spend 10–12%, regulated firms push to the 15–18% ceiling |
Healthcare | ~12–15% | HIPAA compliance and the highest breach cost of any sector (~$7.42M avg in 2025) |
Government / SLED | ~12–16% | Compliance mandates (CMMC, CJIS, StateRAMP); note public-sector total IT spend is often only 3–7% of budget, so the security slice is squeezed |
Professional services | ~8–12% | Protection of confidential client data (legal, accounting, consulting); reputational stakes but lighter formal regulation |
Manufacturing | ~6–10% | Historically lower, now rising fast as OT/ICS risk climbs; still typically below the regulated sectors |
Education | ~5–8% | Chronically under-funded relative to threat level; large attack surface, thin budgets |
Nonprofit | ~5–8% | Budget-constrained; often below the baseline despite holding donor and PII data |
Calculating ROI from a cybersecurity training program uses the same ROSI logic covered elsewhere in this article. You want to measure loss avoided—specifically the reduction in human-driven incidents that the training covers.
Since phishing is the leading initial attack vector, and human error underpins most successful phishing attacks, the annualized loss expectancy (ALE) you’re working from is the expected annual cost of employee-triggered incidents like phishing, business email compromise, and credential theft.
The mitigation ratio becomes the measured improvement in employee behavior, typically the drop in phishing simulation click-through rates after training.
Therefore, the formula is ROSI = ((ALE × mitigation ratio) − cost of the program) ÷ cost of the program, where ALE is your human-error incident exposure, the mitigation ratio is the percentage reduction in successful phishing (say, a click rate falling from 30% to 5%, an ~83% reduction), and the cost is the fully-loaded price of the training platform plus employee time spent completing it.
Framed this way, cybersecurity awareness training tends to post a strong ROSI because its cost is low relative to the breach exposure it addresses. This is exactly the kind of conservative, defensible case that holds up in front of a CFO or board of directors.
Calculating ROI from MDR and early-detection technologies uses the same ROSI framework covered above (loss avoided over cost) but with an important conceptual twist. MDR doesn’t primarily stop attacks from happening; rather, it shrinks the cost of each attack by catching it early.
True prevention tools, like cybersecurity training, lower the frequency of incidents (the ARO). Detection-and-response services like MDR, XDR, and 24/7 SOC monitoring lower the severity of incidents (the SLE) by compressing the breach lifecycle, i.e. the dwell time between compromise and containment.
Therefore, in the ROSI formula, ROSI = ((ALE × mitigation ratio) − cost of the solution) ÷ cost of the solution, your “loss avoided” is the gap between what a breach costs when it remains undetected for months versus what it costs when caught in days. The mitigation ratio reflects that reduction in loss magnitude rather than a drop in attack count.
IBM’s most recent Cost of a Data Breach Report makes this quantifiable. The report found that breaches contained in under 200 days cost about $1.14 million less than those that lingered undetected. Meanwhile, organizations using AI-driven security tools saved roughly $1.9 million per breach while detecting incidents about 80 days faster.
Framed this way, the ROSI of a solution like MDR rests on mean-time-to-detect and mean-time-to-respond as the value levers. When you frame things this way, you get a defensible argument that a lower cost per incident, multiplied across your annual risk exposure, comfortably exceeds the annual cost of the service.
The most common framework for quantifying cyber risk is the FAIR (Factor Analysis of Information Risk) standard. However, there are other frameworks that may be appropriate in different industries or regulatory environments.
Framework | What it does | Type |
FAIR | Quantifies cyber risk in dollar terms as a probable loss range | Quantitative risk analysis |
Gordon-Loeb “37% rule” | Caps rational security spend at ~37% of a breach’s expected loss | Economic / budget model |
NIST CSF | Organizes a security program across six functions — Govern, Identify, Protect, Detect, Respond, Recover (v2.0, 2024) | Qualitative program framework |
ISO/IEC 27005 | Provides a structured process for identifying, analyzing, and treating infosec risk within an ISO 27001 ISMS | Risk-management process standard |
MITRE ATT&CK & TARA | Maps real adversary tactics/techniques (ATT&CK) and prioritizes countermeasures against them (TARA) | Threat modeling / qualitative |
Here’s a quick way to think about the split:
Note: Only FAIR and Gordon-Loeb feed a ROSI calculation directly. The other three shape the program that ROSI then measures.
Justifying a cybersecurity budget is fundamentally a translation problem. You’re converting technical risk into the financial language of CFOs and board members. The most effective internal strategy combines a solid ROSI calculation with communication tailored to each stakeholder’s priorities, benchmarking so your budget request looks well-reasoned, and grounding every number in a credible, cited source.
The goal isn’t to win a single budget cycle. It’s to reposition security as a recurring risk-management investment that the business expects to fund, using conservative, defensible figures.
It’s challenging to make the case for an investment that protects revenue rather than increasing it. Without that simple, traditional ROI calculation, the C-suite may hesitate to pull the trigger on cybersecurity investments.
The key here is to reframe the discussion. Use the loss prevention analogy from retail (discussed above), coupled with a quantified cybersecurity ROSI (return on security investment) calculation. With this analogy and these numbers in hand, you’ll want to craft individual messages that appeal to the concerns of each member of the leadership team.
Here’s what this might look like.
Ultimately, the CEO (or VP of sales) is responsible for revenue.
If you can express your cybersecurity investment in terms of revenue protected, you’ll make a great case.
You can do this by supplementing the basic ROSI calculation with a view of potential revenue loss from various outages. Consider these downtime stats and multiply them by your organization’s average revenue per minute, hour, or day.
The finance leader cares deeply about the final analysis on the profit and loss sheet. Lost revenue is a component of that, but it isn’t enough to give the CFO the full picture.
Instead, provide the detailed financial analysis that went into your cybersecurity ROSI calculation. The outcome of that calculation is the perfect number to convince your CFO, but they’ll want to see everything that went into your calculation. (Hint: You may want to provide far more granularity and precision than we did in our example calculation.)
The operations leader cares deeply about productivity. They want to control cost while producing as much output as possible. They should be quite familiar with both your organization’s cost of operations per day, and the value of your production output every day.
Given that, the best case you can make involves the average outage times that you shared with the CEO or sales leader. Here, however, you’ll want to generate two stats: 1) average outage lengths multiplied by the daily cost of operations, and 2) average outage lengths multiplied by the daily value of production.
These numbers will bring home the value of cybersecurity ROSI for your operations leader.
For the marketing leader, you’ll want to frame cybersecurity investments in terms of protecting brand equity and reputation. Consider these high-profile breaches that have hit well-known companies in the last few years.
If these stories feel too disconnected from your company, try googling cyberattacks in your industry. If there are recognizable brands in that list, especially competitors, this can really bring home the risk for your marketing leader.
Chances are, the IT leader is already in your corner. (Or maybe you are the IT leader!) But if you need to do some convincing, or you want data to make a stronger case, consider how a cybersecurity investment takes out the guesswork in IT operations (and budget) related to a potential security incident. You get a single IT budget line item, the retainer for your MSSP (managed security services provider). Your MSSP will step in to mitigate any threats that occur under the terms of the agreement, relieving the burden on your internal IT team.
Contact us today to get the outside perspective you need for the next step on your journey.
Need to quantify your investment?
We’ll respond within 1 business day, or you can grab time on our calendar.