Is this security control worth the budget line?

Every security certification teaches the same formula: single loss expectancy times annual rate of occurrence equals expected annual loss. The trouble is that every input is a guess, and a point estimate hides how wrong the guess can be. Simulate the guesses instead and the budget request turns into a probability the CFO can act on.

Operations Advanced Monte Carlo Pro engine

After you install, this is the model to open.

Is This Security Control Worth It?

  1. In your spreadsheet, click the Sortia icon in the strip of icons down the right-hand edge. No strip? Click the arrow at the bottom-right to open it. You can also use Extensions, then Sortia, then Open Sortia.
  2. Click Start from a template and put that name in the search box.
  3. Pick the card with that name and click Load this template. It arrives on a new tab with real numbers already in it.

This one runs on a Pro engine, and every free install includes five full-quality runs on your own numbers, shared across all five Pro engines rather than five for each. After that, Pro is $199/year.

The answer

10,000 trials draw from all three ranges at once and price the control against the losses it prevents.

Expected annual loss, no control
$99,000 ALE at today's exposure
Expected ROSI
$19,000 per year, net of the $45K control cost
Chance the control pays for itself
74% ROSI above zero this year
Avoided loss per $1 spent
$1.42 expected return on control spend
-$11K downside (P10)$15K median ROSI$55K upside (P90)

In expectation the control avoids $64,000 of annual loss for a $45,000 spend, an expected ROSI of $19,000 and a 74% chance of paying for itself this year. The honest part is the other 26%: in a quiet year the control can finish underwater, and the simulation puts a number on that instead of hiding it. That is the difference between a hand-wave and a budget line that survives review.

The model

A mid-size company runs an $850,000 customer-facing platform and is weighing a $45,000 per year managed detection and MFA program. Loss severity, incident likelihood, and the control's effectiveness all go in as ranges, not points.

Asset value at risk$850,000
Exposure factor per incident8% – 22% – 40% (uncertain)
Annual incident probability, no control20% – 45% – 85% (uncertain)
Annual control cost$45,000
Incident probability reduction from control40% – 60% – 75% (uncertain)
Loss severity reduction from control15%

Once it is in your sheet

  1. The model arrives with real numbers in it and runs as it stands, so you can press the button first and understand it second.
  2. Change the numbers to yours. The sheet marks which cells are inputs and which hold formulas, and most labels carry a note explaining the row.
  3. Press the run button at the bottom of the panel. It is labeled for the tool you are in, and the result lands on its own tab, with a written reading of it beside the figures.

Never used Google Sheets? Start here goes the whole way, in seven steps, and assumes nothing.