A Quantitative Framework for Return-on-Security-Investment (RoSI) in Secure Software Engineering: Integrating Probabilistic Risk, Lifecycle Dynamics, and Data-Driven Adaptation
Article Information
Abstract
The concept of Return on Security Investment (RoSI) has evolved from a mere financial indicator into a comprehensive system for informed decision-making. Software-intensive organisations face mounting pressure to justify security expenditure in financially rigorous terms. Existing Return-on-Security-Investment (RoSI) models rely on deterministic approximations that ignore probability distributions over threats, temporal decay of vulnerability windows, and intangible cost categories. This paper presents a probabilistic RoSI framework grounded in the FAIR taxonomy that integrates: (i) expected-loss differentials with Bayesian updating; (ii) shift-left cost amplification across the software development lifecycle; and (iii) a compliance-cost extension for regulatory regimes such as GDPR and HIPAA. Monte Carlo simulation across a representative portfolio of 20 security controls confirms that early detection in the requirements phase yields up to 18× RoSI relative to post-deployment remediation. The framework delivers a tractable decision-support tool for CISOs seeking to optimise security investment under uncertainty.
Graphical Abstract
Keywords
Data Availability Statement
Funding
Conflicts of Interest
AI Use Statement
Ethical Approval and Consent to Participate
References
- Sonnenreich, W., Albanese, J., & Stout, B. (2006). Return on security investment (ROSI)-a practical quantitative model. Journal of Research and practice in Information Technology, 38(1), 45-56. https://search.informit.org/doi/abs/10.3316/informit.937199632104879
[Google Scholar] - Żebrowski, P., Couce‐Vieira, A., & Mancuso, A. (2022). A Bayesian framework for the analysis and optimal mitigation of cyber threats to cyber‐physical systems. Risk Analysis, 42(10), 2275-2290.
[CrossRef] [Google Scholar] - Gordon, L. A., & Loeb, M. P. (2002). The economics of information security investment. ACM Transactions on Information and System Security (TISSEC), 5(4), 438-457.
[CrossRef] [Google Scholar] - Gordon, L. A., Loeb, M. P., & Zhou, L. (2020). Integrating cost–benefit analysis into the NIST Cybersecurity Framework via the Gordon–Loeb Model. Journal of Cybersecurity, 6(1), tyaa005.
[CrossRef] [Google Scholar] - Barik, K., Misra, S., Fernandez-Sanz, L., & Koyuncu, M. (2023). RONSI: a framework for calculating return on network security investment. Telecommunication Systems, 84(4), 533-548.
[CrossRef] [Google Scholar] - Yaqoob, T., Arshad, A., Abbas, H., Amjad, M. F., & Shafqat, N. (2019). Framework for calculating return on security investment (ROSI) for security-oriented organizations. Future Generation Computer Systems, 95, 754-763.
[CrossRef] [Google Scholar] - Zhao, X., Clear, T., & Lal, R. (2024). Identifying the primary dimensions of DevSecOps: A multi-vocal literature review. Journal of Systems and Software, 214, 112063.
[CrossRef] [Google Scholar] - Ozment, A., & Schechter, S. E. (2006, July). Milk or wine: does software security improve with age?. In USENIX Security Symposium (Vol. 6, pp. 10-5555). https://www.usenix.org/legacy/events/sec06/tech/full_papers/ozment/ozment.pdf
[Google Scholar] - Ross, R. S. (2012). Guide for conducting risk assessments (NIST Special Publication 800-30 Revision 1). National Institute of Standards and Technology.
[CrossRef] [Google Scholar] - Rajapakse, R. N., Zahedi, M., Babar, M. A., & Shen, H. (2022). Challenges and solutions when adopting DevSecOps: A systematic review. Information and software technology, 141, 106700.
[CrossRef] [Google Scholar] - Saripalli, P., & Walters, B. (2010, July). Quirc: A quantitative impact and risk assessment framework for cloud security. In 2010 IEEE 3rd international conference on cloud computing (pp. 280-288). IEEE.
[CrossRef] [Google Scholar] - Böhme, R., & Schwartz, G. (2010, June). Modeling cyber-insurance: towards a unifying framework. InWEIS. https://informationsecurity.uibk.ac.at/pdfs/BS2010_Modeling_Cyber-Insurance_WEIS.pdf
[Google Scholar] - d'Ambrosio, N., Perrone, G., & Romano, S. P. (2023). Including insider threats into risk management through Bayesian threat graph networks. Computers & Security, 133, 103410.
[CrossRef] [Google Scholar] - Iaiani, M., Tugnoli, A., Bonvicini, S., & Cozzani, V. (2021). Analysis of cybersecurity-related incidents in the process industry. Reliability Engineering & System Safety, 209, 107485.
[CrossRef] [Google Scholar] - Verizon. (2023). 2023 Data Breach Investigations Report. Verizon Communications. https://www.verizon.com/business/resources/reports/2023-data-breach-investigations-report-dbir.pdf
[Google Scholar] - Romanosky, S. (2016). Examining the costs and causes of cyber incidents. Journal of Cybersecurity, 2(2), 121-135.
[CrossRef] [Google Scholar] - Mazzoccoli, A., & Naldi, M. (2020). Robustness of optimal investment decisions in mixed insurance/investment cyber risk management. Risk analysis, 40(3), 550-564.
[CrossRef] [Google Scholar] - He, Y., Xin, T., & Luo, C. (2025). Enhancing Cybersecurity Investment with FAIR-ROSI: A Responsible Cybersecurity Approach to Digital Society. Information Systems Frontiers, 1-16.
[CrossRef] [Google Scholar]
Cite This Article
TY - JOUR AU - Yogi, Manas Kumar AU - Satwika, Nadiminti Sai Priya PY - 2026 DA - 2026/05/12 TI - A Quantitative Framework for Return-on-Security-Investment (RoSI) in Secure Software Engineering: Integrating Probabilistic Risk, Lifecycle Dynamics, and Data-Driven Adaptation JO - ICCK Journal of Software Engineering T2 - ICCK Journal of Software Engineering JF - ICCK Journal of Software Engineering VL - 2 IS - 2 SP - 121 EP - 137 DO - 10.62762/JSE.2026.472228 UR - https://www.icck.org/article/abs/JSE.2026.472228 KW - Return-on-Security Investment (RoSI) KW - quantitative risk assessment KW - secure software engineering KW - DevSecOps KW - expected loss KW - Bayesian networks KW - security economics KW - shift-left security KW - FAIR framework AB - The concept of Return on Security Investment (RoSI) has evolved from a mere financial indicator into a comprehensive system for informed decision-making. Software-intensive organisations face mounting pressure to justify security expenditure in financially rigorous terms. Existing Return-on-Security-Investment (RoSI) models rely on deterministic approximations that ignore probability distributions over threats, temporal decay of vulnerability windows, and intangible cost categories. This paper presents a probabilistic RoSI framework grounded in the FAIR taxonomy that integrates: (i) expected-loss differentials with Bayesian updating; (ii) shift-left cost amplification across the software development lifecycle; and (iii) a compliance-cost extension for regulatory regimes such as GDPR and HIPAA. Monte Carlo simulation across a representative portfolio of 20 security controls confirms that early detection in the requirements phase yields up to 18× RoSI relative to post-deployment remediation. The framework delivers a tractable decision-support tool for CISOs seeking to optimise security investment under uncertainty. SN - 3069-1834 PB - Institute of Central Computation and Knowledge LA - English ER -
@article{Yogi2026A,
author = {Manas Kumar Yogi and Nadiminti Sai Priya Satwika},
title = {A Quantitative Framework for Return-on-Security-Investment (RoSI) in Secure Software Engineering: Integrating Probabilistic Risk, Lifecycle Dynamics, and Data-Driven Adaptation},
journal = {ICCK Journal of Software Engineering},
year = {2026},
volume = {2},
number = {2},
pages = {121-137},
doi = {10.62762/JSE.2026.472228},
url = {https://www.icck.org/article/abs/JSE.2026.472228},
abstract = {The concept of Return on Security Investment (RoSI) has evolved from a mere financial indicator into a comprehensive system for informed decision-making. Software-intensive organisations face mounting pressure to justify security expenditure in financially rigorous terms. Existing Return-on-Security-Investment (RoSI) models rely on deterministic approximations that ignore probability distributions over threats, temporal decay of vulnerability windows, and intangible cost categories. This paper presents a probabilistic RoSI framework grounded in the FAIR taxonomy that integrates: (i) expected-loss differentials with Bayesian updating; (ii) shift-left cost amplification across the software development lifecycle; and (iii) a compliance-cost extension for regulatory regimes such as GDPR and HIPAA. Monte Carlo simulation across a representative portfolio of 20 security controls confirms that early detection in the requirements phase yields up to 18× RoSI relative to post-deployment remediation. The framework delivers a tractable decision-support tool for CISOs seeking to optimise security investment under uncertainty.},
keywords = {Return-on-Security Investment (RoSI), quantitative risk assessment, secure software engineering, DevSecOps, expected loss, Bayesian networks, security economics, shift-left security, FAIR framework},
issn = {3069-1834},
publisher = {Institute of Central Computation and Knowledge}
}
Article Metrics
Publisher's Note
ICCK stays neutral with regard to jurisdictional claims in published maps and institutional affiliations.
Rights and Permissions
Copyright © 2026 by the Author(s). Published by Institute of Central Computation and Knowledge. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/), which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made.
Portico