1. Estimate annual loss exposure
Enter the expected annualized ransomware loss before the proposed control.
2. Estimate risk reduction
Use a documented percentage reflecting how much expected loss the control may reduce.
3. Enter control costs
Include initial deployment cost and recurring annual operating cost.
4. Choose an analysis period
Use a period that matches the control lifecycle or budget horizon.
5. Interpret ROI with context
Compare ROI, net benefit, and payback, then stress-test uncertain assumptions.