Quantifying the Financial Impact of Cybersecurity with Return on Mitigation (RoM)

Quantifying the Financial Impact of Cybersecurity with Return on Mitigation (RoM)

Source: YouTube · HackerOne · published Mar 18, 2025 · 1:01:50

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The presentation "Beyond ROI" introduces Return on Mitigation (ROM) as a superior financial metric for cybersecurity, shifting focus from merely preventing loss to quantifying the value of risk reduction efforts 0:16.

Key Takeaways:
• Traditional ROI fails to capture the full financial impact of security investments because it often ignores avoided losses and operational continuity 0:22.
• ROM measures the financial value of mitigating risk by comparing the cost of security controls against the reduction in expected loss 0:30.
• This framework helps security leaders communicate effectively with CFOs by translating technical risk into tangible business value 0:45.
• Implementing ROM allows organizations to prioritize security spending based on actual financial impact rather than fear or compliance alone 0:52.

By adopting ROM, organizations can better justify cybersecurity budgets and align security strategies with broader financial goals.

Sources:

  • 0:16 Introduction of the presentation title and topic.
  • 0:22 Discussion on the limitations of traditional ROI in cybersecurity.
  • 0:30 Explanation of the Return on Mitigation (ROM) concept.
  • 0:45 Benefits of ROM for communication with financial stakeholders.
  • 0:52 Strategic alignment of security spending using ROM.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

okay great awesome to see everyone here uh I've got a little counter on my screen although I can't see your faces or your names U but it looks like there's you know 45 people here so that's that's great to see um this presentation and the white paper is titled Beyond Roi unlocking the financial value of cyber security with return on mitigation so I'll just give a a brief intro introduction to me and then I'll let uh I'll let NZ introduce herself uh so my name is Luke Stevens if you follow me online you might know me as hack Luke and uh my cyber security career started out in penetration testing and of course some bug bounty hunting on the side I worked for a bunch of uh different companies over the last decade or so in the cyber security realm and uh for the last few years I've been runnin…