How Should a CFO Evaluate Cybersecurity Investment ROI?
By Tom Hermstad · HD Tech

How should a CFO evaluate cybersecurity investment ROI?
A CFO evaluating cybersecurity investment ROI should compare the annual expected loss from a breach — probability multiplied by impact — against the cost of prevention. For Orange County SMBs, IBM's 2024 Cost of a Data Breach Report puts the average breach cost for organizations under 500 employees at $3.31 million, a year-over-year increase. A fully loaded managed cybersecurity program typically costs a fraction of that. The math isn't close.
What does the cost of doing nothing actually look like?
Start here, because this is where the real risk lives.
IBM's 2024 Cost of a Data Breach Report puts the global average breach cost at $4.88 million — up 10% from the prior year. Even for smaller businesses, Microsoft's SMB Cybersecurity Report found an average per-attack cost of $254,445, with worst-case SMB incidents reaching $7 million when you factor in investigation, downtime, lost revenue, and recovery.
Those numbers include more than IT cleanup. The dominant cost drivers are:
- Incident response and forensics — identifying the breach and stopping the bleed
- Legal and regulatory exposure — notification requirements, potential fines, civil liability
- Downtime and lost revenue — the hours or days production stops
- Reputation damage — client attrition and lost pipeline that doesn't show up on an incident report
For a manufacturing firm in Orange County running significant annual revenue, a week of downtime isn't just an IT problem. It's a P&L event.
It's not if, it's when — and the CFO's job is to quantify that exposure before approving — or rejecting — the security budget.
The ROI framework: four metrics that matter
1. Risk-adjusted ROI (the core calculation)
The standard approach:
Annual Expected Loss (AEL) = Breach Probability × Breach Impact
Use industry breach probability estimates from Verizon's 2024 Data Breach Investigations Report — small businesses face meaningful annual breach probability, and the impact for a sub-500-employee firm averages $3.31M per IBM's 2024 data.
Then compare AEL to your annual cybersecurity spend. If your expected annual loss exposure — based on a breach probability applied to a $3.31M average impact — significantly exceeds what a managed security program costs per year, the risk-adjusted ROI is clear before you touch a spreadsheet.
This isn't hypothetical — it's the same framework CFOs apply to property and casualty insurance. Cybersecurity is that, with a far higher probability of a claim.
2. Cost avoidance — the most undervalued line item
Cybersecurity spend doesn't generate revenue. It eliminates costs you'd otherwise incur. That distinction matters for how you model it.
Cost avoidance categories to include:
- Avoided breach response costs (forensics, legal, notification): the vast majority of SMB incidents carry substantial response costs
- Avoided regulatory fines: HIPAA violations can run approximately $145 to $73,011 per violation; CMMC non-compliance puts defense contractors' contracts at serious risk
- Avoided downtime costs: calculate revenue per hour × hours of average recovery time
- Avoided ransom payments: Verizon DBIR data shows ransomware remains a top SMB threat vector, with ransom plus recovery pushing total impact into significant territory for regional firms
When you add these to the risk-adjusted ROI model, the "cost" of cybersecurity becomes a cost-avoidance vehicle — and the payback period shortens considerably.
3. Compliance value — liability reduction as a financial metric
If your business operates under HIPAA, SOC 2, or CMMC, security controls aren't optional. They're contractual and regulatory obligations. The question isn't whether to comply — it's whether to build that compliance infrastructure in-house or through a managed provider.
Consider what compliance failures actually cost:
- HIPAA: HHS can assess fines of approximately $145 to $73,011 per violation, with annual caps around $2,190,294 for the highest tier
- CMMC: defense contractors without certification lose access to DoD contracts — a revenue event, not just an IT one
- SOC 2: failing an audit delays enterprise sales cycles and can kill deals outright
A managed security program that maps controls to these frameworks — and produces audit-ready documentation — reduces your external audit hours, cuts legal exposure, and shortens your compliance timeline. That has a dollar value. Build it into the model.
For healthcare and construction firms in Orange County specifically, this compliance angle often closes the ROI case on its own. If you work in either of those sectors, see our breakdowns on healthcare IT security in Orange County and construction cybersecurity compliance.
4. Operational efficiency — the productivity gains CFOs overlook
Unplanned downtime is a direct revenue cost. IBM's 2024 data identifies mean time to detect and respond as a major driver of total breach cost — organizations that detect and contain faster pay significantly less.
A managed IT and cybersecurity program with 24/7 monitoring reduces:
- Mean time to detect (MTTD): catching threats before they become incidents
- Mean time to respond (MTTR): resolving issues before production stops
- Helpdesk drag: employees waiting on IT support instead of working
At HD Tech, our helpdesk response target is under four minutes. When Raul Ortega at Custom Wheel House describes getting "chat assistance instantly or call in to speak with a live person," that's not a customer service metric — it's a productivity metric. Faster resolution means less downtime, and less downtime means lower operational cost.
Flat monthly fee vs. in-house IT: what does the CFO's cost model actually show?
One reason cybersecurity ROI calculations go sideways is that the comparison isn't apples-to-apples. In-house security has fully loaded costs most CFOs underestimate:
| Cost element | In-house | Managed program |
|---|---|---|
| Salary + benefits (security analyst) | Significant annual expense | Included |
| Training and certifications | Additional annual expense | Included |
| Security tooling (licenses) | Additional annual expense | Included |
| 24/7 coverage | Requires additional headcount | Included |
| Scalability | Linear with headcount | Subscription-based |
A flat monthly managed cybersecurity fee converts a variable, unpredictable capital expense into a predictable operating line item. That's not just easier to budget — it eliminates the surprise invoices that typically follow an incident response engagement.
Kathleen Urquidez, President and Managing Partner at Urquidez & Associates CPAs in Long Beach, put it plainly: "Downtime means lost billing — with HD Tech on our side we have close to no interruptions. Data security is always a large concern, but with HD Tech on our side, we know we are doing everything we can to avoid a data breach and we rest easier."
That's the CFO outcome. Predictable cost. Quantified risk reduction. Fewer surprises.
How should a CFO evaluate and vet a cybersecurity provider?
Once the ROI framework justifies the investment, provider selection comes down to accountability and transparency. Trust, yet verify — ask any candidate these questions before you sign anything:
- What is your average helpdesk response time?
- Do you provide monthly reporting tied to business outcomes — not just ticket counts?
- Can you map your controls to HIPAA, SOC 2, or CMMC as applicable to our business?
- What does your incident response process look like — and what's the SLA? (See HD Tech's cyber incident response approach.)
- Is pricing flat and all-inclusive, or will I see variable invoices after an incident?
A provider who answers those questions clearly, in plain English, without deflecting — that's the partner, not the vendor.
For a deeper look at how to evaluate IT investment across your full technology stack, our guide on how CFOs can evaluate IT ROI more effectively in 2026 walks through the full framework.
Frequently Asked Questions
Calculate your Annual Expected Loss — breach probability multiplied by average breach impact for your business size. For SMBs under 500 employees, IBM's 2024 data puts average breach cost at $3.31 million. Compare that expected loss against your annual cybersecurity spend. Include cost avoidance (avoided downtime, legal fees, fines) and compliance value. If expected loss exceeds program cost, the ROI is positive.
According to IBM's 2024 Cost of a Data Breach Report, organizations with under 500 employees face an average breach cost of $3.31 million. Microsoft's SMB research found average per-attack costs of $254,445, with severe incidents reaching $7 million. Costs include incident response, legal, regulatory fines, downtime, and lost revenue — not just technical cleanup.
For most SMBs, yes. A single qualified security analyst carries substantial salary costs — before benefits, tooling, training, and the reality that one person can't provide 24/7 coverage. A managed cybersecurity program delivers 24/7 monitoring, enterprise-grade tooling, and documented compliance support at a flat monthly fee that's typically a fraction of fully loaded in-house costs.
Cybersecurity controls map directly to compliance requirements under HIPAA, SOC 2, and CMMC. A managed program that documents those controls reduces external audit hours, lowers the risk of regulatory fines, and shortens compliance timelines. HIPAA fines currently run approximately $145 to $73,011 per violation, with annual caps around $2,190,294 for the highest tier; CMMC non-compliance can put defense contractors' DoD contracts at serious risk. Compliance value alone often justifies the investment.
Ask for average helpdesk response time, monthly business-outcome reporting, framework-specific compliance mapping, incident response SLAs, and flat all-inclusive pricing. A credible provider answers all five clearly. If response times are excessive, reporting is purely technical, or pricing includes variable incident fees, keep looking.
If you want to run the numbers for your specific business — breach probability, expected loss, and what a managed program would cost relative to your risk profile — book a free 15-minute Discovery Call with HD Tech. You'll spend a few minutes with a 30-year veteran who will walk you through your current cyber posture and hand you the three biggest things you can do right now to improve your security standing. No jargon, no sales pitch — just a clear picture of where you stand and a path forward.

Tom Hermstad
President & CMO, HD Tech
Tom Hermstad has led HD Tech since 1995, building one of Southern California's most trusted managed IT and cybersecurity firms. He specializes in helping Orange County businesses eliminate IT headaches and stay ahead of evolving cyber threats — in plain English.
