A Quantitative Framework for Return-on-Security-Investment (RoSI) in Secure Software Engineering: Integrating Probabilistic Risk, Lifecycle Dynamics, and Data-Driven Adaptation
Research Article  ·  Published: 12 May 2026
Issue cover
ICCK Journal of Software Engineering
Volume 2, Issue 2, 2026: 121-137
Research Article Open Access

A Quantitative Framework for Return-on-Security-Investment (RoSI) in Secure Software Engineering: Integrating Probabilistic Risk, Lifecycle Dynamics, and Data-Driven Adaptation

1 Department of Computer Science and Engineering, Pragati Engineering College (Autonomous), Surampalem 533437, India
* Corresponding Author: Manas Kumar Yogi, [email protected]
Volume 2, Issue 2

Article Information

Abstract

The concept of Return on Security Investment (RoSI) has evolved from a mere financial indicator into a comprehensive system for informed decision-making. Software-intensive organisations face mounting pressure to justify security expenditure in financially rigorous terms. Existing Return-on-Security-Investment (RoSI) models rely on deterministic approximations that ignore probability distributions over threats, temporal decay of vulnerability windows, and intangible cost categories. This paper presents a probabilistic RoSI framework grounded in the FAIR taxonomy that integrates: (i) expected-loss differentials with Bayesian updating; (ii) shift-left cost amplification across the software development lifecycle; and (iii) a compliance-cost extension for regulatory regimes such as GDPR and HIPAA. Monte Carlo simulation across a representative portfolio of 20 security controls confirms that early detection in the requirements phase yields up to 18× RoSI relative to post-deployment remediation. The framework delivers a tractable decision-support tool for CISOs seeking to optimise security investment under uncertainty.

Graphical Abstract

A Quantitative Framework for Return-on-Security-Investment (RoSI) in Secure Software Engineering: Integrating Probabilistic Risk, Lifecycle Dynamics, and Data-Driven Adaptation

Keywords

Return-on-Security Investment (RoSI) quantitative risk assessment secure software engineering DevSecOps expected loss Bayesian networks security economics shift-left security FAIR framework

Data Availability Statement

Data will be made available on request.

Funding

This work was supported without any funding.

Conflicts of Interest

The authors declare no conflicts of interest.

AI Use Statement

The authors declare that no generative AI was used in the preparation of this manuscript.

Ethical Approval and Consent to Participate

Not applicable.

References

  1. Sonnenreich, W., Albanese, J., & Stout, B. (2006). Return on security investment (ROSI)-a practical quantitative model. Journal of Research and practice in Information Technology, 38(1), 45-56. https://search.informit.org/doi/abs/10.3316/informit.937199632104879
    [Google Scholar]
  2. Żebrowski, P., Couce‐Vieira, A., & Mancuso, A. (2022). A Bayesian framework for the analysis and optimal mitigation of cyber threats to cyber‐physical systems. Risk Analysis, 42(10), 2275-2290.
    [CrossRef] [Google Scholar]
  3. Gordon, L. A., & Loeb, M. P. (2002). The economics of information security investment. ACM Transactions on Information and System Security (TISSEC), 5(4), 438-457.
    [CrossRef] [Google Scholar]
  4. Gordon, L. A., Loeb, M. P., & Zhou, L. (2020). Integrating cost–benefit analysis into the NIST Cybersecurity Framework via the Gordon–Loeb Model. Journal of Cybersecurity, 6(1), tyaa005.
    [CrossRef] [Google Scholar]
  5. Barik, K., Misra, S., Fernandez-Sanz, L., & Koyuncu, M. (2023). RONSI: a framework for calculating return on network security investment. Telecommunication Systems, 84(4), 533-548.
    [CrossRef] [Google Scholar]
  6. Yaqoob, T., Arshad, A., Abbas, H., Amjad, M. F., & Shafqat, N. (2019). Framework for calculating return on security investment (ROSI) for security-oriented organizations. Future Generation Computer Systems, 95, 754-763.
    [CrossRef] [Google Scholar]
  7. Zhao, X., Clear, T., & Lal, R. (2024). Identifying the primary dimensions of DevSecOps: A multi-vocal literature review. Journal of Systems and Software, 214, 112063.
    [CrossRef] [Google Scholar]
  8. Ozment, A., & Schechter, S. E. (2006, July). Milk or wine: does software security improve with age?. In USENIX Security Symposium (Vol. 6, pp. 10-5555). https://www.usenix.org/legacy/events/sec06/tech/full_papers/ozment/ozment.pdf
    [Google Scholar]
  9. Ross, R. S. (2012). Guide for conducting risk assessments (NIST Special Publication 800-30 Revision 1). National Institute of Standards and Technology.
    [CrossRef] [Google Scholar]
  10. Rajapakse, R. N., Zahedi, M., Babar, M. A., & Shen, H. (2022). Challenges and solutions when adopting DevSecOps: A systematic review. Information and software technology, 141, 106700.
    [CrossRef] [Google Scholar]
  11. Saripalli, P., & Walters, B. (2010, July). Quirc: A quantitative impact and risk assessment framework for cloud security. In 2010 IEEE 3rd international conference on cloud computing (pp. 280-288). IEEE.
    [CrossRef] [Google Scholar]
  12. Böhme, R., & Schwartz, G. (2010, June). Modeling cyber-insurance: towards a unifying framework. InWEIS. https://informationsecurity.uibk.ac.at/pdfs/BS2010_Modeling_Cyber-Insurance_WEIS.pdf
    [Google Scholar]
  13. d'Ambrosio, N., Perrone, G., & Romano, S. P. (2023). Including insider threats into risk management through Bayesian threat graph networks. Computers & Security, 133, 103410.
    [CrossRef] [Google Scholar]
  14. Iaiani, M., Tugnoli, A., Bonvicini, S., & Cozzani, V. (2021). Analysis of cybersecurity-related incidents in the process industry. Reliability Engineering & System Safety, 209, 107485.
    [CrossRef] [Google Scholar]
  15. Verizon. (2023). 2023 Data Breach Investigations Report. Verizon Communications. https://www.verizon.com/business/resources/reports/2023-data-breach-investigations-report-dbir.pdf
    [Google Scholar]
  16. Romanosky, S. (2016). Examining the costs and causes of cyber incidents. Journal of Cybersecurity, 2(2), 121-135.
    [CrossRef] [Google Scholar]
  17. Mazzoccoli, A., & Naldi, M. (2020). Robustness of optimal investment decisions in mixed insurance/investment cyber risk management. Risk analysis, 40(3), 550-564.
    [CrossRef] [Google Scholar]
  18. He, Y., Xin, T., & Luo, C. (2025). Enhancing Cybersecurity Investment with FAIR-ROSI: A Responsible Cybersecurity Approach to Digital Society. Information Systems Frontiers, 1-16.
    [CrossRef] [Google Scholar]

Cite This Article

APA Style
Yogi, M. K., & Satwika, N. S. P. (2026). A Quantitative Framework for Return-on-Security-Investment (RoSI) in Secure Software Engineering: Integrating Probabilistic Risk, Lifecycle Dynamics, and Data-Driven Adaptation. ICCK Journal of Software Engineering, 2(2), 121-137. https://doi.org/10.62762/JSE.2026.472228
Export Citation
RIS Format
Compatible with EndNote, Zotero, Mendeley, and other reference managers
TY  - JOUR
AU  - Yogi, Manas Kumar
AU  - Satwika, Nadiminti Sai Priya
PY  - 2026
DA  - 2026/05/12
TI  - A Quantitative Framework for Return-on-Security-Investment (RoSI) in Secure Software Engineering: Integrating Probabilistic Risk, Lifecycle Dynamics, and Data-Driven Adaptation
JO  - ICCK Journal of Software Engineering
T2  - ICCK Journal of Software Engineering
JF  - ICCK Journal of Software Engineering
VL  - 2
IS  - 2
SP  - 121
EP  - 137
DO  - 10.62762/JSE.2026.472228
UR  - https://www.icck.org/article/abs/JSE.2026.472228
KW  - Return-on-Security Investment (RoSI)
KW  - quantitative risk assessment
KW  - secure software engineering
KW  - DevSecOps
KW  - expected loss
KW  - Bayesian networks
KW  - security economics
KW  - shift-left security
KW  - FAIR framework
AB  - The concept of Return on Security Investment (RoSI) has evolved from a mere financial indicator into a comprehensive system for informed decision-making. Software-intensive organisations face mounting pressure to justify security expenditure in financially rigorous terms. Existing Return-on-Security-Investment (RoSI) models rely on deterministic approximations that ignore probability distributions over threats, temporal decay of vulnerability windows, and intangible cost categories. This paper presents a probabilistic RoSI framework grounded in the FAIR taxonomy that integrates: (i) expected-loss differentials with Bayesian updating; (ii) shift-left cost amplification across the software development lifecycle; and (iii) a compliance-cost extension for regulatory regimes such as GDPR and HIPAA. Monte Carlo simulation across a representative portfolio of 20 security controls confirms that early detection in the requirements phase yields up to 18× RoSI relative to post-deployment remediation. The framework delivers a tractable decision-support tool for CISOs seeking to optimise security investment under uncertainty.
SN  - 3069-1834
PB  - Institute of Central Computation and Knowledge
LA  - English
ER  - 
BibTeX Format
Compatible with LaTeX, BibTeX, and other reference managers
@article{Yogi2026A,
  author = {Manas Kumar Yogi and Nadiminti Sai Priya Satwika},
  title = {A Quantitative Framework for Return-on-Security-Investment (RoSI) in Secure Software Engineering: Integrating Probabilistic Risk, Lifecycle Dynamics, and Data-Driven Adaptation},
  journal = {ICCK Journal of Software Engineering},
  year = {2026},
  volume = {2},
  number = {2},
  pages = {121-137},
  doi = {10.62762/JSE.2026.472228},
  url = {https://www.icck.org/article/abs/JSE.2026.472228},
  abstract = {The concept of Return on Security Investment (RoSI) has evolved from a mere financial indicator into a comprehensive system for informed decision-making. Software-intensive organisations face mounting pressure to justify security expenditure in financially rigorous terms. Existing Return-on-Security-Investment (RoSI) models rely on deterministic approximations that ignore probability distributions over threats, temporal decay of vulnerability windows, and intangible cost categories. This paper presents a probabilistic RoSI framework grounded in the FAIR taxonomy that integrates: (i) expected-loss differentials with Bayesian updating; (ii) shift-left cost amplification across the software development lifecycle; and (iii) a compliance-cost extension for regulatory regimes such as GDPR and HIPAA. Monte Carlo simulation across a representative portfolio of 20 security controls confirms that early detection in the requirements phase yields up to 18× RoSI relative to post-deployment remediation. The framework delivers a tractable decision-support tool for CISOs seeking to optimise security investment under uncertainty.},
  keywords = {Return-on-Security Investment (RoSI), quantitative risk assessment, secure software engineering, DevSecOps, expected loss, Bayesian networks, security economics, shift-left security, FAIR framework},
  issn = {3069-1834},
  publisher = {Institute of Central Computation and Knowledge}
}

Article Metrics

Citations
Crossref
0
Scopus
0
Views
563
PDF Downloads
202

Publisher's Note

ICCK stays neutral with regard to jurisdictional claims in published maps and institutional affiliations.

Rights and Permissions

CC BY Copyright © 2026 by the Author(s). Published by Institute of Central Computation and Knowledge. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/), which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made.
ICCK Journal of Software Engineering
ICCK Journal of Software Engineering
ISSN: 3069-1834 (Online)
Portico
Preserved at
Portico