He, Ying and Xin, Tong and Luo, Cunjin (2025) Enhancing Cybersecurity Investment with FAIR-ROSI: A Responsible Cybersecurity Approach to Digital Society. Information Systems Frontiers. DOI https://doi.org/10.1007/s10796-025-10625-y
He, Ying and Xin, Tong and Luo, Cunjin (2025) Enhancing Cybersecurity Investment with FAIR-ROSI: A Responsible Cybersecurity Approach to Digital Society. Information Systems Frontiers. DOI https://doi.org/10.1007/s10796-025-10625-y
He, Ying and Xin, Tong and Luo, Cunjin (2025) Enhancing Cybersecurity Investment with FAIR-ROSI: A Responsible Cybersecurity Approach to Digital Society. Information Systems Frontiers. DOI https://doi.org/10.1007/s10796-025-10625-y
Abstract
Investment in cybersecurity is critical to protect information system security, preserve organizational interests, and fulfil social responsibilities. However, due to the lack of a transparent process, investors often struggle to assess the effectiveness of their investments. Traditional return on security investment (ROSI) can be considered as an economic indicator which reflects investment efficiency, but it often emphasizes investment costs and anticipated returns while overlooks cybersecurity related metrics. This paper proposes the FAIR-ROSI model that integrates five qualitative and quantitative cybersecurity metrics with the Factor Analysis of Information Risk (FAIR) model. It combines practical qualitative and quantitative indicators to enhance the granularity of the traditional ROSI model. We then use a case study to evaluate the FAIR-ROSI model. The results from pre and post control measures shows a narrow margin between actual and projected loss values and a significantly higher ROI compared to the total security expenditure.
Item Type: | Article |
---|---|
Uncontrolled Keywords: | Risk Assessment; Return on Security Investment (ROSI); Factor Analysis of Information Risk (FAIR); FAIR-ROSI Model; Cybersecurity Qualitative Metrics; Cybersecurity Quantitative Metrics |
Divisions: | Faculty of Science and Health Faculty of Science and Health > Computer Science and Electronic Engineering, School of |
SWORD Depositor: | Unnamed user with email elements@essex.ac.uk |
Depositing User: | Unnamed user with email elements@essex.ac.uk |
Date Deposited: | 21 Jul 2025 07:25 |
Last Modified: | 21 Jul 2025 07:25 |
URI: | http://repository.essex.ac.uk/id/eprint/41281 |
Available files
Filename: s10796-025-10625-y (3).pdf