TL;DR: ROI is a backward-looking financial measure that often misstates cybersecurity value because it ignores avoided loss, resilience, compliance pressure, and long payback periods, according to INTIGRITI's analysis. For identity and security programmes, the better question is whether a control reduces exposure, shortens recovery, and limits blast radius when it matters most.
NHIMG editorial — based on content published by INTIGRITI: Cybersecurity: Why ROI isn’t always a meaningful metric
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
Questions worth separating out
Q: How should security teams justify cybersecurity budgets to executives?
A: Security teams should justify budgets by linking each proposed control to a measurable business outcome such as avoided loss, reduced downtime, or lower recovery cost.
Q: Why is ROI especially weak for IAM and NHI controls?
A: IAM and NHI controls often prevent events that never occur, so their value is expressed through avoided compromise, not direct revenue.
Q: How do you know if cybersecurity spending is actually working?
A: Look for narrower attack surface, faster access removal, better credential hygiene, fewer exposed secrets, and shorter recovery from incidents.
Practitioner guidance
- Use risk reduction as the primary control metric Replace single-point ROI arguments with measures such as reduced exposed accounts, shorter credential lifetime, and lower incident blast radius.
- Build identity-specific cost avoidance models Estimate the cost of avoided credential abuse, privilege escalation, and account takeover across IAM and NHI programmes.
- Report control effectiveness, not just spend efficiency Track the percentage of privileged accounts reviewed, revoked, or rotated within policy windows, and show how those controls change exposure.
What's in the full article
INTIGRITI's full article covers the practical framing this post intentionally leaves for the source:
- How the author positions ROI versus ROSI and cost avoidance in board conversations
- The examples used to explain why intangible security benefits resist financial quantification
- The discussion of when ROI can still be useful for smaller, well-scoped cybersecurity decisions
- The operational metrics cited for uptime, incident response time, and recovery performance
👉 Read INTIGRITI's analysis of why ROI is not always a useful cybersecurity metric →
Cybersecurity ROI is the wrong metric for board-level risk decisions?
Explore further
ROI is a useful finance term, but it is a weak security governance model. Cybersecurity controls are designed to prevent loss, not just create measurable profit, so the central value often lives in avoided incidents and preserved continuity. That makes ROI especially misleading for identity programmes, where the control may succeed precisely because nothing happened. Practitioners should treat ROI as one input, not the decision framework.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to Ultimate Guide to NHIs , Key Challenges and Risks.
A question worth separating out:
Q: Who is accountable for proving security controls are effective?
A: Accountability should sit with the control owner, the programme owner, and the leadership team that accepts residual risk. In practice, this means resilience evidence should be part of governance reporting, not left as an informal technical exercise. If a control cannot be proved, its risk should be visible at decision-making level.
👉 Read our full editorial: ROI is the wrong primary metric for cybersecurity governance