ROI in cybersecurity
Return on Investment (ROI) is a big deal in business. Any business venture needs to demonstrate a positive ROI, and a good one at that, in order to be viable.
The problem is that security is not an investment that provides a return, such as a new factory or a financial instrument. It’s an expense that, hopefully, pays for itself in cost savings. Security is about loss prevention, not about earnings. So, while security can’t produce ROI, loss prevention most certainly affects a company’s bottom line.
Most importantly, while ROI may not be a perfect fit, it’s a concept that business folks are very familiar with. Since security teams do not exist for their own benefit, and have very real costs of their own, communicating risk in security-specific terms makes it very difficult for business leaders to understand how to value their efforts.
You’ll need to know how to talk about ROI if you want to convince your business partners...