1. Enter current expected loss
Use the annual phishing loss from an internal risk model or a comparable scenario.
2. Estimate reduction
Enter the percentage of expected loss the proposed control is expected to remove.
3. Add recurring cost
Include subscriptions, staff time, maintenance, training, and other annual operating costs.
4. Add implementation cost
Enter one-time deployment, integration, migration, and initial training costs.
5. Select the evaluation period
Use a period that matches the expected control life and budgeting horizon.
6. Read the business case
Review ROI together with avoided loss, total cost, and net benefit.