About this calculator
Cybersecurity ROI calculator: what it estimates
Two modes. The ROI modeestimates the annual dollars a growing company spends on its compliance program — the security questionnaires you answer for enterprise deals, the policy work, the consultant hours you buy to keep up, and the deal-discount risk when buyers ask for security documentation you don’t have yet — and shows what that number becomes when a platform absorbs the routine work. The Risk mode estimates cyber risk exposure in dollars using a FAIR-style loss model: expected annual loss and a P95 probable-maximum loss, decomposed across the categories that most commonly drive breach cost for companies at your size and framework posture. Both outputs land in dollars, not vibes.
What the inputs mean
Each input is a lever your board or CFO would recognize:
- Industry & framework— sets the base-rate loss assumptions and the audit-workload profile. A healthcare company operating under HIPAA carries different exposure and questionnaire volume than a marketing agency working under SOC 2.
- Company size(employees) — scales the breach-cost estimates (loss-per-record and business-interruption windows grow with headcount) and the internal-hours multiplier on the compliance program.
- Average hourly cost— the fully-loaded blended rate of the people currently doing the compliance work. Used to convert manual questionnaire and policy hours into dollars.
- Security questionnaires per year— the count of enterprise-buyer questionnaires you complete annually. Typical questionnaires (SIG Lite, CAIQ Lite, custom vendor questionnaires) take 40–80 hours each to complete from scratch; the calculator multiplies your input by that midpoint.
- Consultant hours per year— external cyber advisory hours you buy currently. Priced at the rate you paid last, this is what a fractional CISO retainer or hourly independent consultant costs you in a year.
- Enterprise deal size— the average annual contract value of an enterprise deal your security posture blocks or discounts. The deal-protection line item quantifies what happens when security answers arrive too late or arrive too weak.
How the numbers are calculated
ROI modestarts with the direct dollar cost of your current compliance program: internal hours × hourly rate for questionnaires and policy work, plus your consultant spend, plus a deal-discount factor derived from the enterprise-deal count and size. That is the “without a platform” number. The “with vCISO Lite” number applies platform-absorption assumptions from our own operational data (roughly a 70% reduction in questionnaire hours, 50–60% reduction in policy hours, and a meaningful consultant-spend reduction because the platform absorbs the routine work that used to fill those consultant hours).
Risk modeuses a FAIR-style loss model: expected annual loss (LEF × LM) plus a P95 probable-maximum loss for tail-risk scenarios. Base rates for breach frequency and loss magnitude come from IBM’s Cost of a Data Breach report, Verizon’s DBIR, and Ponemon Institute survey data. Your framework selection and current-posture inputs adjust the base rates up or down. The “with vCISO Lite in place” view applies conservative risk-reduction factors from the specific controls the platform implements (evidence tamper-resistance, continuous monitoring, faster incident detection windows).
A worked example
A 40-person marketing agency running two enterprise deals through security review this quarter, answering roughly six questionnaires per year, buying 100 hours of external cyber-advisory time at a $300 per hour blended rate. In ROI mode, this profile shows a current annual cost around $80,000 to $100,000 across questionnaires, policy work, consultant fees, and deal-discount risk. In Risk mode, the same profile shows an expected annual loss of $50,000 to $75,000 and a P95 loss of $400,000 to $600,000 depending on the questionnaire responses and posture inputs. Numbers move with your inputs; the goal is to make the shape of the exposure visible in dollars your CFO can actually plan against.
How to interpret the output for your board
The dollar figures land as a single number your board can discuss the same way they discuss any other risk-adjusted line item: what would need to change to move the number down 30%, what is the cost of not moving it, and what is the confidence interval. The methodology section inside the calculator lists the specific assumptions and citations for every input so a skeptical audit-committee member can trace where a number came from. The output PDF bundles the inputs, outputs, and methodology into a single briefing document you can share ahead of the meeting rather than reconstruct during it.