Is this security control worth the budget line?
Every security certification teaches the same formula: single loss expectancy times annual rate of occurrence equals expected annual loss. The trouble is that every input is a guess, and a point estimate hides how wrong the guess can be. Simulate the guesses instead and the budget request turns into a probability the CFO can act on.
Operations Advanced Monte Carlo Pro engine
After you install, this is the model to open.
Is This Security Control Worth It?
- In your spreadsheet, click the Sortia icon in the strip of icons down the right-hand edge. No strip? Click the arrow at the bottom-right to open it. You can also use Extensions, then Sortia, then Open Sortia.
- Click Start from a template and put that name in the search box.
- Pick the card with that name and click Load this template. It arrives on a new tab with real numbers already in it.
This one runs on a Pro engine, and every free install includes five full-quality runs on your own numbers, shared across all five Pro engines rather than five for each. After that, Pro is $199/year.
The answer
10,000 trials draw from all three ranges at once and price the control against the losses it prevents.
- Expected annual loss, no control
- $99,000 ALE at today's exposure
- Expected ROSI
- $19,000 per year, net of the $45K control cost
- Chance the control pays for itself
- 74% ROSI above zero this year
- Avoided loss per $1 spent
- $1.42 expected return on control spend
In expectation the control avoids $64,000 of annual loss for a $45,000 spend, an expected ROSI of $19,000 and a 74% chance of paying for itself this year. The honest part is the other 26%: in a quiet year the control can finish underwater, and the simulation puts a number on that instead of hiding it. That is the difference between a hand-wave and a budget line that survives review.
The model
A mid-size company runs an $850,000 customer-facing platform and is weighing a $45,000 per year managed detection and MFA program. Loss severity, incident likelihood, and the control's effectiveness all go in as ranges, not points.
| Asset value at risk | $850,000 |
| Exposure factor per incident | 8% – 22% – 40% (uncertain) |
| Annual incident probability, no control | 20% – 45% – 85% (uncertain) |
| Annual control cost | $45,000 |
| Incident probability reduction from control | 40% – 60% – 75% (uncertain) |
| Loss severity reduction from control | 15% |
Once it is in your sheet
- The model arrives with real numbers in it and runs as it stands, so you can press the button first and understand it second.
- Change the numbers to yours. The sheet marks which cells are inputs and which hold formulas, and most labels carry a note explaining the row.
- Press the run button at the bottom of the panel. It is labeled for the tool you are in, and the result lands on its own tab, with a written reading of it beside the figures.
Never used Google Sheets? Start here goes the whole way, in seven steps, and assumes nothing.
Next question
- What does that broken process actually cost per year?What a Broken Process Costs per Year
- How much should you produce each month?Production & Demand Planner
- Which risks stay red after controls?IT Risk: Still Red After Controls?
- Where should your warehouse actually be?Warehouse Location Optimizer
- Which rows in these two lists are the same company?Match Two Customer Lists That Don't Agree
- What do the next four quarters of demand actually look like?Seasonal Demand Forecast
Every model like this one, and the method behind them: Monte Carlo simulation.