Free Return On Security Investment (ROSI) Calculator Launched

Tool aims to calculate whether potential decrease of security incidents will outweigh investment in security measures

June 4, 2011

1 Min Read


June 2, 2011 – Information Security & Business Continuity Academy, the largest online resource for the implementation of ISO 27001 and BS 25999-2 standards has launched its free Return on Security Investment (ROSI) Calculator at

This Calculator will help to solve one of the biggest problems information security and IT professionals have – how to prove to the top management that an investment in information security makes sense.

This is the most detailed ROSI Calculator that can be found on the Internet, and it aims to calculate as precisely as possible whether the potential decrease of security incidents (i.e. the risk mitigation) will outweigh the investment in security measures. The calculation is performed in two steps:

Step #1 - the costs of an incident are calculated by taking into account all the relevant costs if an incident occurs and the probability of incident occurrence.

Step #2 - the costs of security measures/controls are calculated, and the level to which the risk of this incident would decrease because of such mitigation.

The final result (after Step #2) is the calculation whether the gain (the risk decrease) is higher than the needed investment (security measures/controls).

The use this Calculator requires no expert knowledge about information security or finance, and it requires to gather existing data on costs within the company, security measures and potential incidents. It can be used by both IT and security professionals, and finance analysts.

Use of the ROSI Calculator is completely free – it can be found at

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like

More Insights