Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Why does using a return on security investment…
Cyber Security

Why does using a return on security investment model help when boards ask for cybersecurity justification?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Cyber Security

ROSI helps because boards think in business outcomes, while security teams manage risk. The model translates cyber exposure into financial terms, making it easier to compare options and explain why doing nothing is more expensive than investing. It also shifts the discussion from feature pricing to loss reduction, which is usually the real decision criterion for directors.

Why ROSI changes the conversation at board level

ROSI works because it translates a security request into the language directors already use to compare investments, trade-offs, and opportunity cost. That matters when cyber work is competing with revenue, resilience, compliance, and operational spend. A good ROSI model does not claim perfect precision, it creates a defensible decision frame for comparing “do nothing” against risk-reducing actions.

It also helps security leaders avoid the trap of presenting controls as isolated tools. Boards usually do not fund features, they fund outcomes such as reduced loss exposure, lower likelihood of material disruption, and better confidence in governance. NIST Cybersecurity Framework 2.0 is useful here because it reinforces the governance and risk-management lens that board reporting needs.

When the investment case is structured around expected loss, directors can compare alternatives on the same basis. That makes it easier to explain why a control with modest upfront cost may still be better than absorbing repeated incidents, delayed recovery, regulatory scrutiny, or downstream operational drag.

What ROSI makes visible that feature-based arguments miss

Feature pricing asks, “What does the product cost?” ROSI asks, “What loss does this reduce, and by how much?” That shift matters because security controls often look expensive when judged only by licence or implementation cost, but become rational once you include avoided breach impact, reduced recovery effort, and less business interruption.

ROSI also helps separate direct and indirect effects. A control may not stop every incident, but it can reduce blast radius, shorten dwell time, improve detection, or make recovery faster. Those effects are often the real economic benefit, especially in environments where one incident can create multiple costs at once: response, outage, forensics, legal review, and reputational damage.

For practitioners, the model becomes more credible when it uses assumptions the board can interrogate: event frequency, likely impact range, control coverage, and residual exposure. If those inputs are vague, ROSI becomes a story. If they are explicit, it becomes a decision aid.

In identity-heavy environments, the cost of doing nothing is often driven by scale and privilege concentration. NHIs outnumber human identities by 25x to 50x in modern enterprises, and NHI Mgmt Group’s Ultimate Guide to Non-Human Identities notes that 97% of NHIs carry excessive privileges, which helps explain why exposure can become financially material quickly.

How to use ROSI without overstating certainty

ROSI is strongest when it is used as a disciplined estimate, not as a false precision exercise. Boards do not need a single “correct” number so much as a transparent range, a clear set of assumptions, and a visible link between the threat scenario and the financial outcome. That is usually enough to support prioritisation.

What to verify: Confirm that the scenario being modelled is the one the board actually cares about, such as material outage, regulated data exposure, or a repeatable identity compromise path. Then validate whether the control changes frequency, impact, or both, because those are the levers that drive economic justification.

Decision rule: If a cyber action only changes user convenience or tool count, ROSI is weak. If it reduces expected loss, shrinks blast radius, or improves recovery enough to change enterprise risk, it is board-relevant even when the purchase price looks high.

Practitioner takeaway: The strongest ROSI cases do not try to “sell security”, they show how a specific control changes the cost of risk in terms the board already uses to make capital allocation decisions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV — GovernROSI is a governance and risk-communication tool for board decisions.
ID — IdentifyROSI depends on identifying material assets, scenarios, and exposure.
RC — RecoverROSI often values controls by reducing recovery time and business interruption.
Recommendation — Frame cyber spend in enterprise risk terms and track decision ownership at board level. Identify the business services and loss scenarios that ROSI should monetise. Quantify how proposed controls shorten recovery and reduce interruption costs.
CIS Controls v8CIS 17 — Incident Response ManagementROSI often justifies controls by reducing response cost and incident impact.
CIS 6 — Access Control ManagementBoard justification often hinges on controls that reduce exposure and blast radius.
Recommendation — Use incident cost and response data to support control investment cases. Prioritise access controls that measurably reduce likely loss from compromise.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org