Posts

Showing posts with the label roi

Glutton for ROI Punishment

My previous posts No ROI? No Problem and Security ROI Revisited have been smash hits. The emphasis here is on "smash." At the risk for being branded a glutton for ROI punishment, I present one final scenario to convey my thoughts on this topic. I believe there may be some room for common ground. I am only concerned with the Truth as well as we humans can perceive it. With that, once more unto the breach. It's 1992. Happy Corp. is a collaborative advertisement writing company. A team of writers develop advertisement scripts for TV. Writers exchange ideas and such via hard copy before finalizing their product. Using these methods the company creates an average of 100 advertisement scripts per month, selling them for $1,000 each or a total of $100,000 per month. Happy's IT group proposes Project A. Project A will cost $10,000 to deploy and $1,000 per month to sustain. Project A will provide Happy with email accounts for all writers. As a result of implement...

Security ROI Revisited

One of you responded to my No ROI? No Problem post with this question: Just read your ROI blog, which I found very interesting. ROI is something I've always tried to put my finger on, and you present an interesting approach. Question: Is it not possible to 'make' money with security, or does it still come down to savings? Example: - A hospital implements a security system that allows doctors to access patient data from anywhere. Now, instead of doing 10 patients a day they can do (and charge) 13 patients a day. I'm not trying to sharp shoot you in anyway, I'm just trying to better understand the economics. This is an excellent question. This is exactly the same concept as I stated in my August 2006 post Real Technology ROI . In this case, doctors are more productive at accessing patient data by virtue of a remote access technology. This is like installing radios for faster dispatch in taxis. In both cases security is not causing a productivity gain but ...

No ROI? No Problem

I continue to be surprised by the confusion surrounding the term Return on Investment (ROI). The Wikipedia entry for Rate of Return treats ROI as a synonym, so it's a good place to go if you want to understand ROI as anyone who's taken introductory corporate finance understands it. In its simplest form, ROI is a mechanism used to choose projects. For example, assume you have $1000 in assets to allocate to one of three projects, all of which have the same time period and risk. Invest $1000. Project yields $900 (-10% ROI) Invest $1000. Project yields $1000 (0% ROI) Invest $1000. Project yields $1100 (10% ROI) Clearly, the business should pursue project 3. Businesspeople make decisions using this sort of mindset. I am no stranger to this world. Consider this example from my consulting past, where I have to choose which engagement to accept for the next week. Spend $1000 on travel, meals, and other expenses. Project pays $900 (-10% ROI) Spend $1000 on travel, meals, and ...

One for Ken Belva

I mentioned Ken Belva's thoughts in Thoughts on Virtual Trust last year. If you don't know Ken's thoughts on "virtual trust" please read that post before continuing further. I refrained from pointing a finger at Ken's Apple DRM example after Steve Jobs posted his Thoughts on Music , where DRM won't apply to Apple music (thereby depriving Ken of one of his case studies and questioning his logic). Now I'd really like an answer to this article: Retailers Fuming Over Card Data Security Rules; Claim PCI standard shifts burden to them, could alienate customers . Here are a few excerpts: Several retailers last week bristled at having to comply with the Payment Card Industry (PCI) Data Security Standard, complaining that they carry an unfair burden in securing credit card data. In interviews and speeches at the annual ERIexchange conference here, retail executives also complained that implementing the PCI standard is costly and could alienate customers ......

Security Is Not Refrigeration

Analogies are not the best way to make an argument, but they help when debating abstract concepts like " virtual trust ". Consider the refrigerated train car at left. Refrigeration is definitely a "business enabler." Without refrigeration, food producers on the west coast couldn't sell their goods to consumers on the east coast. Refrigeration opened new markets and keeps them open. However, refrigeration is not the business . Refrigeration is a means to an end -- namely selling food to hungry people. Refrigeration does not generate value; growing and selling food does. (Refrigeration is only the business for those that sell refrigerated train cars and supporting devices.) You might think "security" is like refrigeration. Like refrigeration, security could be said to "enable" business. Like refrigeration, security does not generate value; selling a product or service through a "secure" channel does. So why is "security...

Thoughts on Virtual Trust

I've said before that there is no return on security investment (ROSI). This argument appears to have morphed again in the form of a paper titled Creating Business Through Virtual Trust . A Technorati search will show you other comments on this idea. These are mine. First, I agree with others who say "virtual trust" should not be "virtual" -- it's either "trust" or it's not. That's not a major point though. Second, the thesis for the paper appears to be the following, as shown in the abstract. Business is concerned with the creation of new entities and assets that generate cash. Information security, by contrast, is traditionally concerned with protecting these entities and assets. In this paper we examine a perspective which currently exists but is largely dormant in the information security field. We maintain that information security can be actively involved in the creation of business and that the skills required to create commer...

Mike Rothman Is Right

Mike Rothman is right : I'm here at the Security Standard conference and I'm seeing the pendulum starting to swing back. What pendulum? The pendulum that swings like a metronome between security as a defense and security as an enabler... I'll make it very very clear. Security is not a business enabler. It is a cost of doing business. You cannot do new things because of security. You do open up new revenue streams and add value to customers via new applications that reflect new (or updated) business processes. It may be ill advised to put these new business processes on the web without adequate security, but you CAN do it. In extreme cases of incredible negligence or outright stupidity, a business may deploy an exceptionally insecure application or business process that must be shut down due to overwhelming fraud and theft. Barring those circumstances, however, I agree that businesses are willing to "put these new business processes on the web without adequate securit...

No ROI for Security or Legal

Last night I watched a Dateline NBC story about the fast food industry's defense against lawsuits alleging their products cause obesity. This reminded me that these corporate legal teams are similar to corporate security teams. No one is going to increase funding for their legal department and see improved productivity or higher profits. Yet, legal is still a necessary requirement for doing business -- especially for staying in business. You may remember this earlier comment: Marcus [Ranum] said "security ROI is dead" and "legislation has made security a cost." He predicted "we will be competing with legal for money (or working for them) in the next five to ten years." To hammer the point Marcus then said "there never was a security ROI." I'd enjoy hearing how corporate lawyers justify their budgets.

Security Is Still Loss Avoidance

One of you (who wishes to remain anonymous) sent me a link to the story Value Made Visible in response to my Real Technology ROI post. Here is the CSO magazine core argument. [The] Value Protection [Metric] is [Bruce] Larson's attempt to overcome security's classic problem of seeming like nothing but a drain on the business... The basic Value Protection metric is a ratio that looks like this: Value Protection = Normal Operations Cost ($) – Event Impact ($) / Normal Operations Cost ($)... Larson's metric just subtracts the cost of security events from the normal cost of doing business, then divides by that same operations cost to get a ratio. I'm sure that's been published somewhere before, or at least something very similar. I'm too lazy to check those CISSP books I never open. Here are some examples from the same article: Whether it's based on actual events or potential futures, the Value Protection ratio gives security officers a real metric to presen...

Real Technology ROI

I recently reiterated that there is no ROI for security (except for Road House ). This is obviously not true for all technology. While traveling recently I saw technology with real ROI in a taxi. Think of the effect of deploying radios in taxis. Before this invention, cabs relied on getting assignments through a central dispatcher at their home station. Sure, they could be flagged down by a passer-by, but otherwise they returned to base for a new job. Now spend a little money to install radios in everyone's cab. Suddenly the cab that would previously have to return to home base to get a new assignment can be dynamically re-tasked to a waiting passenger nearby. A cab that only ran two dozen passengers per shift can accommodate double that number, hardly ever returning back to base. That's called an increase in productivity -- the source of real economic growth -- and real ROI. Staying with the taxi scenario, you may have heard of technology to avoid collisions . You mi...

Notes from SC Magazine

The July 2006 SC Magazine features some blogworthy stories. From Working for Gold , we see more opinions that calculating security ROI is a waste of time : In recent years, the acronym of the day was ROSI — return on security investment. Analysts and security managers alike were struggling to find ways to measure security return on investment (ROI) and offer it up as proof to their bosses and executive boards that their money was being maximized. But the magic method to do this has never appeared. And some, such as André Gold, Continental Airlines' information security director, doubt it ever will. "There are a lot of people out there who want to turn the information security department into a profit and loss (P&L) entity and I don't think you can do it," Gold says. "I ran our ecommerce environment for almost seven years and it was really easy to do ROI-type of metrics there. In my opinion you just don't have that in security ." Gold isn't alon...

Return on Security Investment

Just today I mentioned that there is no such thing as return on security investment (ROSI). I was saying this two years ago . As I was reviewing my notes, I remembered one true case of ROSI: the film Road House . If you've never seen it, you're in for a treat. It's amazing that this masterpiece is only separated by four years from Swayze's other classic, Red Dawn . (Best quote from Red Dawn: A member of an elite paramilitary organization: "Eagle Scouts." ) In Road House, Swayze plays a "cooler" -- a bouncer who cleans up unruly bars. He's hired to remove the riff raff from the "Double Deuce," a bar so rough the band is protected by a chicken wire fence! I personally would have hired Jackie Chan, but that's a story for another day. Swayze's character indeed fights his way through a variety of local toughs, in the process allowing classier and richer patrons to frequent the Double Deuce. The owner clearly sees a ROSI; the...

Ripping Into ROI

In April I wrote Calculating Security ROI Is a Waste of Time . The latest print issue of Information Security magazine features a story by Anne Saita that confirms my judgement: "If you find executives resisting your security suggestions, try simply removing the term 'ROI' from the conversation. 'ROI is no longer effective terminology to use in most security justifications,' says Paul Proctor, Vp of security and risk strategies for META Group . [Paul is also author of the excellent book Practical Intrusion Detection , where he correctly said 'there is no such thing as a false positive.'] Executives, he says, interpret ROI as ' quantifiable financial return following investment .' Security professionals view it more like an insurance premium. The C-suite is also wary of the numbers security ROI calculators crunch. 'Bottom line is that most executives are frustrated and no longer interested in hearing this type of justification,' Pro...

Calculating Security ROI Is a Waste of Time

Image
I was pleased to read Infosec Economics by Lawrence Gordon and Robert Richardson in the 1 Apr 04 issue of Network Computing magazine. This duo says: "ROI (or bang for the buck) can't be applied perfectly to information security because often the return on information security purchases and deployments is intangible. Sure, companies invest in some solutions that offer benefits beyond security--faster network throughput in a new router that supports VPNs, for example--and they can calculate the ROI of these indirect benefits. But security requires factoring in the expectation of loss." I've been lucky to have never been tasked with calculating security's "return on investment," because I would have told my supervisor the answer is zero. There is no return to be made on security, because security is a loss avoidance and loss mitigation measure. Security is a way to deal with risk, which is the probability of loss. (I dealt with these definitions in O...