Blog Post

Building a Security Budget Case With Return on Security Investment

August 12, 2026

Table of Contents

Security budget requests fail on arithmetic rather than on argument. A finance function asked to approve spending wants the same information it requires from every other proposal, being what it costs, what it returns and over what period. Most security cases supply the first, describe the second qualitatively, and omit the third.

Return on security investment closes that by expressing the benefit as reduced modeled loss rather than as reduced likelihood of an unspecified bad outcome. The calculation is straightforward, and the honest version includes what it cannot capture. What follows covers the arithmetic, the inputs that make it defensible, and where the method genuinely falls short.

Why Qualitative Cases Stall

A proposal describing a control as reducing risk from high to medium asks the approver to accept a translation nobody can check. Finance compares proposals against each other, and a severity category cannot be compared with anything.

Three Objections Recur

The first is comparability, since a request framed in severity terms cannot be weighed against a revenue project framed in currency. The second is counterfactual, because a case resting on prevented incidents describes events that will never be observed either way. The third is timing, as security proposals frequently omit the period over which benefit accrues while every capital process requires one. Existing data-driven budgeting approaches address the first objection and the other two need the same treatment.

The Calculation Itself

Return on security investment divides net benefit by cost and expresses the result as a percentage over a stated period. Benefit is the reduction in modeled annual loss the control produces, multiplied across the projection period, plus any operational savings the change also delivers. Cost includes one-time implementation and recurring maintenance across the same period.

Return on security investment calculation showing implementation and recurring costs, modeled exposure before and after, additional savings, and a three-year return percentage
Stating exposure before and after alongside one-time and recurring costs produces a return figure a finance function can check line by line.

A Worked Example Is More Persuasive Than a Large One

Consider a secure development tooling improvement costing forty-five thousand dollars to implement with six thousand dollars of annual maintenance, reaching sixty-three thousand across three years. Modeled exposure falls from just over one point eight million dollars to slightly below it, producing seventy-eight thousand dollars of avoided loss across the period, and the change also removes twelve thousand dollars of defect rework. The three-year return lands around forty-three percent.

Nothing about those figures is spectacular, which is the point. A case claiming a several hundred percent return invites scrutiny of the model rather than approval of the spend, while a modest figure with visible inputs reads as a calculation somebody performed rather than a number somebody wanted.

Separate the Cost Categories

One-time and recurring costs behave differently across a projection period and finance will separate them regardless, so presenting them separately avoids a revision cycle. Licensing, implementation labor and training sit in the first. Maintenance, support and the ongoing staff time the control consumes sit in the second. Omitting the second is the most common reason a security case survives approval and fails at renewal.

Getting the Benefit Figure Right

The cost side is an accounting exercise and the benefit side is where the work sits. Benefit is the difference between modeled exposure with the control at its current level and modeled exposure with it at the proposed level, which requires both numbers to come from the same model.

Decision simulation setup offering gap analysis, cybersecurity initiative justification and compliance framework adoption as decision types
Framing the request as a simulated decision rather than a proposal produces the before and after figures the calculation needs.

Model the Change, Not the Control

A control rarely moves from absent to complete, so the useful comparison is between current maturity and proposed maturity rather than between nothing and everything. Simulating that specific change produces a defensible delta, and it also reveals the cases where a large investment moves exposure very little because the control was already adequate. Discovering that before the request is preferable to discovering it during review, and control-change simulation exists for that comparison.

Use Both Average and Tail Figures

Expected annual loss suits the return calculation because it is an annualized figure that multiplies cleanly across a period. A return-period figure belongs in the narrative rather than the arithmetic, since a control reducing the one-in-one-hundred-year loss by several million dollars is making a resilience argument rather than an efficiency one. Presenting both prevents a modest return from concealing a substantial reduction in catastrophic exposure.

Where the Method Falls Short

Return on security investment is a useful frame and not a universal one. Three categories resist it and pretending otherwise weakens the cases where it works.

  • Variance Reduction: Controls narrowing the range of outcomes without moving the average produce a poor return figure and real value.
  • Regulatory Requirement: A mandatory control has no optional alternative, so return is the wrong question to ask about it.
  • Enabling Investment: Asset inventory and logging deliver most of their value by making other controls possible.

Presenting these categories separately, with a different justification for each, is more credible than forcing every request through one calculation. A budget submission containing three return-based cases and two requirement-based ones reads as considered, while five return figures of suspiciously similar magnitude reads as a template.

Avoided Fines Need Care

Counting a potential penalty as avoided loss is legitimate where the exposure is modeled and unhelpful where the figure is a statutory maximum. Maximum penalties describe a ceiling rather than an expectation, and finance functions recognize the difference. Modeled regulatory exposure derived from materiality thresholds carries more weight than a headline number from a regulation.

Presenting It So the Case Survives

The submission itself does work the number cannot, and three practices raise the acceptance rate.

Show the ranked alternatives rather than a single request, because presenting three options with their respective returns lets the approver choose rather than only approve or decline. Rank by the loss each removes rather than by severity, since risk-focused prioritization produces an order that survives challenge. State the methodology and the trial count so the model can be interrogated rather than trusted, which is what quantified board reporting establishes before a budget conversation begins.

Commit to Measuring the Outcome

Offering to report exposure again after implementation converts a forecast into a testable claim, which is unusual enough in security proposals to be noticed. Programs tracking the same metric each period can show whether the predicted reduction materialized, and monitoring progress over time turns the following year's request into a continuation rather than a fresh argument.

What Changes in the Second Year

A first quantified submission establishes the method and a second establishes credibility, provided the earlier claims are revisited. Reporting that a predicted reduction arrived, or explaining why it did not, is what separates a program using quantification from one that used it once for a budget cycle.

Model changes deserve explicit treatment here. Exposure that fell because methodology was updated is not exposure that fell because the control worked, and conflating them the first time makes every subsequent figure suspect. Noting the model version alongside each measurement handles it, and maximizing program return over several cycles depends on the figures remaining comparable.

Arithmetic Beats Advocacy

A security budget case competes against proposals expressed in currency, and translation is the whole task. Cost separated into one-time and recurring, benefit derived from a modeled change rather than an asserted one, a stated period, and honest treatment of the requests that do not fit the frame produce a submission a finance function can evaluate on its own terms. Kovrr's cyber risk quantification produces the before and after figures those calculations depend on, from the same model each period.

To see what a specific control improvement removes from modeled exposure before you request the budget for it, book a demo with our cyber risk experts.

Tomer Shoolman

Product Manager

Return on Security Investment FAQs

Speak to an Expert
No items found.