I would like to hear some readers’ experiences, stories and tips about how they have been able to use security metrics, develop a credible ROI, create a business case or otherwise quantify information security projects and investments. I have heard some rational anecdotes about reducing annualized loss exposure related to data breaches, creating operational efficiencies with IdM and a few others, but I would definitely like a bigger war chest.
I have three copies of Dan Geer’s “Economics & Strategies of Data Security” that I will hand out to the lucky winners! You can email me at jim@reavis.org.
P.S. This book, How to Measure Anything has been recommended by multiple people as useful resource for risk professionals trying to think through this problem.








