There’s been some comment discussion in
about security ROI.
Ken Belva’s point is that you can have a security ROI,
to which I have agreed (twice).
Iang says he’s already addressed this topic, in a blog entry
in which he points out that
Calculating ROI is wrong, it should be NPV. If you are not using NPV then you’re out of court, because so much of security investment is future-oriented.Iang’s entry also says that we can’t even really do Net Present Value (NPV) because we have no way to calculate or predict actual costs with any accuracy. He also says that security people need to learn about business, which I’ve also been harping on. I bet if many security people knew what NPV was, they’d be claiming they had it as much as they’re claiming they have ROI. Continue reading— ROI: security people counting with fingers? Iang, Financial Cryptography, July 20, 2007