Security ROI isn't impossible, we suck at measuring
As of late I’ve been seeing a lot of grumbling that security return on investment (ROI) is impossible. This is of course nonsense. Understanding your ROI is one of the most important things you can do as a business leader. You have to understand if what you’re doing makes sense. By the very nature of business, some of the things we do have more value than other things. Some things even have negative value. If we don’t know which things are the most important, we’re just doing voodoo security. ...