
Blog Post
Building a Security Budget Case With Return on Security Investment
August 12, 2026
Security budget requests fail on arithmetic rather than on argument. A finance function asked to approve spending wants the same information it requires from every other proposal, being what it costs, what it returns and over what period. Most security cases supply the first, describe the second qualitatively, and omit the third.
Return on security investment closes that by expressing the benefit as reduced modeled loss rather than as reduced likelihood of an unspecified bad outcome. The calculation is straightforward, and the honest version includes what it cannot capture. What follows covers the arithmetic, the inputs that make it defensible, and where the method genuinely falls short.
Why Qualitative Cases Stall
A proposal describing a control as reducing risk from high to medium asks the approver to accept a translation nobody can check. Finance compares proposals against each other, and a severity category cannot be compared with anything.
Three Objections Recur
The first is comparability, since a request framed in severity terms cannot be weighed against a revenue project framed in currency. The second is counterfactual, because a case resting on prevented incidents describes events that will never be observed either way. The third is timing, as security proposals frequently omit the period over which benefit accrues while every capital process requires one. Existing data-driven budgeting approaches address the first objection and the other two need the same treatment.
The Calculation Itself
Return on security investment divides net benefit by cost and expresses the result as a percentage over a stated period. Benefit is the reduction in modeled annual loss the control produces, multiplied across the projection period, plus any operational savings the change also delivers. Cost includes one-time implementation and recurring maintenance across the same period.

A Worked Example Is More Persuasive Than a Large One
Consider a secure development tooling improvement costing forty-five thousand dollars to implement with six thousand dollars of annual maintenance, reaching sixty-three thousand across three years. Modeled exposure falls from just over one point eight million dollars to slightly below it, producing seventy-eight thousand dollars of avoided loss across the period, and the change also removes twelve thousand dollars of defect rework. The three-year return lands around forty-three percent.
Nothing about those figures is spectacular, which is the point. A case claiming a several hundred percent return invites scrutiny of the model rather than approval of the spend, while a modest figure with visible inputs reads as a calculation somebody performed rather than a number somebody wanted.
Separate the Cost Categories
One-time and recurring costs behave differently across a projection period and finance will separate them regardless, so presenting them separately avoids a revision cycle. Licensing, implementation labor and training sit in the first. Maintenance, support and the ongoing staff time the control consumes sit in the second. Omitting the second is the most common reason a security case survives approval and fails at renewal.
Getting the Benefit Figure Right
The cost side is an accounting exercise and the benefit side is where the work sits. Benefit is the difference between modeled exposure with the control at its current level and modeled exposure with it at the proposed level, which requires both numbers to come from the same model.
.png)
Model the Change, Not the Control
A control rarely moves from absent to complete, so the useful comparison is between current maturity and proposed maturity rather than between nothing and everything. Simulating that specific change produces a defensible delta, and it also reveals the cases where a large investment moves exposure very little because the control was already adequate. Discovering that before the request is preferable to discovering it during review, and control-change simulation exists for that comparison.
Use Both Average and Tail Figures
Expected annual loss suits the return calculation because it is an annualized figure that multiplies cleanly across a period. A return-period figure belongs in the narrative rather than the arithmetic, since a control reducing the one-in-one-hundred-year loss by several million dollars is making a resilience argument rather than an efficiency one. Presenting both prevents a modest return from concealing a substantial reduction in catastrophic exposure.
Where the Method Falls Short
Return on security investment is a useful frame and not a universal one. Three categories resist it and pretending otherwise weakens the cases where it works.
- Variance Reduction: Controls narrowing the range of outcomes without moving the average produce a poor return figure and real value.
- Regulatory Requirement: A mandatory control has no optional alternative, so return is the wrong question to ask about it.
- Enabling Investment: Asset inventory and logging deliver most of their value by making other controls possible.
Presenting these categories separately, with a different justification for each, is more credible than forcing every request through one calculation. A budget submission containing three return-based cases and two requirement-based ones reads as considered, while five return figures of suspiciously similar magnitude reads as a template.
Avoided Fines Need Care
Counting a potential penalty as avoided loss is legitimate where the exposure is modeled and unhelpful where the figure is a statutory maximum. Maximum penalties describe a ceiling rather than an expectation, and finance functions recognize the difference. Modeled regulatory exposure derived from materiality thresholds carries more weight than a headline number from a regulation.
Presenting It So the Case Survives
The submission itself does work the number cannot, and three practices raise the acceptance rate.
Show the ranked alternatives rather than a single request, because presenting three options with their respective returns lets the approver choose rather than only approve or decline. Rank by the loss each removes rather than by severity, since risk-focused prioritization produces an order that survives challenge. State the methodology and the trial count so the model can be interrogated rather than trusted, which is what quantified board reporting establishes before a budget conversation begins.
Commit to Measuring the Outcome
Offering to report exposure again after implementation converts a forecast into a testable claim, which is unusual enough in security proposals to be noticed. Programs tracking the same metric each period can show whether the predicted reduction materialized, and monitoring progress over time turns the following year's request into a continuation rather than a fresh argument.
What Changes in the Second Year
A first quantified submission establishes the method and a second establishes credibility, provided the earlier claims are revisited. Reporting that a predicted reduction arrived, or explaining why it did not, is what separates a program using quantification from one that used it once for a budget cycle.
Model changes deserve explicit treatment here. Exposure that fell because methodology was updated is not exposure that fell because the control worked, and conflating them the first time makes every subsequent figure suspect. Noting the model version alongside each measurement handles it, and maximizing program return over several cycles depends on the figures remaining comparable.
Arithmetic Beats Advocacy
A security budget case competes against proposals expressed in currency, and translation is the whole task. Cost separated into one-time and recurring, benefit derived from a modeled change rather than an asserted one, a stated period, and honest treatment of the requests that do not fit the frame produce a submission a finance function can evaluate on its own terms. Kovrr's cyber risk quantification produces the before and after figures those calculations depend on, from the same model each period.
To see what a specific control improvement removes from modeled exposure before you request the budget for it, book a demo with our cyber risk experts.
Return on Security Investment FAQs
Speak to an ExpertWhat is return on security investment?
Return on security investment divides net benefit by cost and expresses the result as a percentage across a stated period, using the same structure finance applies to other proposals. Benefit is the reduction in modeled annual loss the control produces, multiplied across the projection period, plus any operational savings the change delivers. Cost covers one-time implementation and recurring maintenance across the same period. The calculation only works where both exposure figures come from the same model, since comparing a modeled figure against an estimated one produces a number nobody can defend.
How do you calculate the benefit side of a security investment?
Take the difference between modeled exposure with the control at its current maturity and modeled exposure with it at the proposed maturity, rather than comparing against the control being absent entirely. Simulating that specific change produces a defensible delta and often reveals cases where substantial spending moves exposure very little because the control was already adequate. Expected annual loss belongs in the arithmetic because it annualizes cleanly, while a return-period figure belongs in the narrative since reducing catastrophic exposure is a resilience argument rather than an efficiency one.
Why do qualitative security budget requests fail?
Three objections recur. Comparability, since a request framed as moving risk from high to medium cannot be weighed against a revenue project framed in currency. Counterfactual, because a case resting on prevented incidents describes events that will never be observed whether the spending happens or not. Timing, as security proposals frequently omit the period over which benefit accrues while every capital process requires one. Expressing benefit as reduced modeled loss over a stated period addresses all three, and financially driven quantification exists largely for this reason.
When should you not use return on security investment?
Three categories resist the frame. Controls that narrow the range of outcomes without moving the average produce a poor return figure while delivering real value, so variance reduction needs a different argument. Mandatory controls have no optional alternative, which makes return the wrong question. Enabling investments such as asset inventory and logging deliver most of their value by making other controls possible, so their benefit appears elsewhere. Presenting these separately with a different justification for each is more credible than forcing every request through one calculation.
Can avoided regulatory fines count as benefit?
Only where the exposure is modeled rather than taken from a statutory maximum. Maximum penalties describe a ceiling rather than an expectation, and a finance function will identify the difference immediately. Modeled regulatory exposure, derived from the likelihood and scale of an event crossing a disclosure or notification threshold, carries considerably more weight. The same applies to reputational cost, which belongs in the narrative unless the model produces a figure for it.
How do you make the second year's budget case easier?
Commit to measuring the outcome when you make the first request, then report whether the predicted reduction arrived. Offering that converts a forecast into a testable claim, which is unusual enough in security proposals to build credibility on its own. Model changes need explicit handling, since exposure that fell because methodology was updated is not exposure that fell because a control worked, and conflating the two makes every later figure suspect. Recording model version beside each measurement keeps successive years comparable, which is what performance measurement requires to function.




