In Depth

Calculated Risk: Return on Security Investment

Sure, determining ROSI (return on security investment) is difficult. But it's also the key to selling your budget. Here's our three-step guide to getting started.

By Scott Berinato

Page 8

ROSI is empirical, but in many ways it's emotional, believe it or not. It is about coming up with numbers, but those numbers are only useful in the context of how executives feel about them. ROSI is risk economics that paints a picture of your organization's attitude toward security. What level of risk is the enterprise comfortable with? How does the company prioritize its limited resources? Is technology or awareness more valuable as a tool? Suddenly you're answering business questions based on the security numbers.

"The numbers right now show patch management automation doesn't provide a positive return for this organization," Nigriny says. "So why would I do it? It just doesn't make sense." Just by coincidence, it seems, ROSI has aligned Nigriny with the business.

Other stories by Scott Berinato

return on security investment

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors