
At some point in the budget meeting, someone asks the question nobody is prepared for: "What do we actually get for our security spend?" The CFO looks at the head of IT, the head of IT looks at his list of licenses, and the most honest answer in the room would be: "We don't know exactly."
The question is fair. Wanting to measure cyber security ROI is normal diligence for a budget line that grows year after year in many SMEs. The trouble starts with the common answers to the question: they don't add up.
We sit in these conversations regularly, on both sides of the table, sometimes next to the CFO, sometimes next to IT. Hence this post: what you can honestly measure about the value of security spend, what is theater, and where you can start tomorrow.
Why the ROI formula doesn't add up
The industry's standard answer goes like this: estimate how likely an incident is, estimate what it would cost, multiply the two and compare the result with the cost of the measure. On slides this is called "risk reduction in francs" and looks like business economics.
Look at the ingredients. The probability of occurrence is an estimate; there is no reliable data for your specific company. The damage amount is also an estimate, usually taken from international studies whose averages have little to do with a Swiss SME. Two estimates multiplied together do not produce a measurement. They produce a number with decimal places that radiates a precision that isn't there.
Behind this sits a more fundamental problem: the "return" on security is the incident that didn't happen. It shows up in no set of accounts. At the end of the year you cannot look up how many attacks your firewall prevented and what they would have cost. Anyone who presents you with a precise return figure anyway usually wants to sell you something that is justified with that figure.
The more honest frame: security spend is a running cost for keeping your risk within a range you have consciously accepted. It yields a return about as much as an insurance policy or the brakes on your car do. With insurance, you never ask about ROI either. You ask whether the coverage matches your risk and whether the premium is in line with the market.
You can ask exactly these two questions about security. And both are measurable.
The second wrong turn: the industry benchmark
When the return calculation doesn't work, many reach for the nearest substitute: the benchmark. What percentage of the IT budget do comparable companies spend on security? Is our ratio in line with the industry average?
That feels solid, but it answers the wrong question. An industry average tells you what others spend. It tells you nothing about whether those others use their money sensibly, and even less about whether their risks resemble yours. A fiduciary firm with twenty employees and a supplier with a networked production floor can have identical IT budgets and still face completely different security situations. Anyone who steers by the average can overspend and underspend at the same time: too much on tools that don't match their risk, too little on the one gap that concerns them.
The benchmark has one legitimate use: as a rough plausibility check on whether your order of magnitude is completely out of line. As a steering instrument it is no good. Steering requires looking at your own line items and your own risks. And that is exactly where we look next.
What you can measure instead
If the return isn't measurable, the question shifts: away from "What does it earn us?" toward "Does it cover the right risk, does it work in operation, and are we paying a reasonable price for it?". That sounds less spectacular than a return figure. In exchange, the answers hold up.
Three levels on which the value of your security spend can be judged:
Coverage. Every item on your security cost list should map to a named risk. Not "endpoint protection is important", but: this tool addresses the risk that a compromised laptop leads to the encryption of the file servers. In our experience this first step already fails for a share of the items, and rarely because the risk is missing. Mostly, nobody ever wrote it down. A tool without an assigned risk is a candidate for the cut list, no matter how good its data sheet sounds.
Operation. A tool that nobody operates has a value of zero, at full cost. The test questions are simple: Is it fully configured, or is it running on default settings? Does anyone look at the alerts, and what happened with the last real alert? When was restoring from backup last tested, not the backup itself, the restore? These answers are binary and immediately verifiable. They say more about your security posture than any return slide. The classic from our assessments: a monitoring tool whose alerts have been flowing for months into a mailbox that nobody reads anymore. On paper, the company was monitored. In operation it wasn't, and it paid anyway.
Price. Only on the third level do we calculate, and with real numbers: total cost per year including licenses, operation and service providers, spread across the risks covered. Add the question of duplication: How many of your tools do the same thing? Three products with overlapping functions mean triple the cost for single protection. We described how to find such overlaps systematically in our post on consolidating security tools.
The cross-check is also part of the measurement: Are there risks that matter to you that no single item pays into? In our experience, the most common example is recovery after a total outage. Plenty of money flows into defense, but whether the business is running again three days or three weeks after an encryption event has never been tested. A gap at this point matters more than any optimization of the existing tools.
Anyone who can answer these three levels plus the cross-check cleanly has measured the value of their security spend. Without a single estimated probability of occurrence.
The one-hour exercise for your next budget meeting
You don't need a project or a consultant for this. You need your security cost list and one hour.
Take the five largest items. For each one, answer three questions, in writing, one sentence each:
- Which specific risk does this item cover?
- Who operates it, and how would we notice that it works?
- What would happen if we cancelled it at the end of the year?
In our experience, one or two out of five items have no clear answer to at least one of the three questions. No need to get upset about that. It is a finding you can work with. An item without a named risk belongs under review. An item without operation should either be operated or cancelled. And the cancellation question often reveals that nobody can name the consequence, which usually means: there wouldn't be one.
The result of this hour is exactly the document that was missing from the budget meeting. Instead of a return fantasy, you put a table on the table: item, risk, operating status, annual cost. The CFO gets an answer in his language, and you get something more valuable than a bigger budget: the credibility that every franc on the list has a named purpose. We wrote about where freed-up money flows sensibly in our post on distributing the security budget correctly.
If the exercise produces more open answers than you expected: that is the normal case. Security stacks grow over years, every purchase had a reason at the time, and nobody has the job of checking backwards regularly. That is why, for us, this review belongs at the start of every budget discussion, before the question of whether the budget should grow or shrink. For more on why right-sizing comes before topping up, see right-sizing IT security.
The ROI that does exist
A return figure for security remains theater. There are still two things you can show in black and white at the end of the year.
First, the costs that are gone: cancelled duplicates, cut tools without a risk, reduced license tiers. That is real money instead of an avoided hypothesis. In our experience, this part regularly more than covers the cost of the cleanup work. One of our clients cut their security spend by around a third after exactly this kind of review and was better off afterwards, because the remaining tools were finally fully configured and operated. Fewer items, each of them taken seriously.
Second, documented diligence: a list on which every security item is assigned to a risk, with operating status and cost. If an insurer, a large customer or, in the worst case, a court ever asks how your company steers its security spend, this list is the answer.
Once you have done the one-hour exercise and want to put the results in perspective, talk to us. An initial conversation is non-binding, and often it is enough to separate the cut list from the review list.
One thing interests us in particular: For which of your five largest security items could you not answer the cancellation question?




