Dr. Chuvakin has an interesting post about the ROI of security. This is what he says:

"First, bear with me since I am still trying to build a coherent picture of security ROI for myself from all the diverse sources of info, some as smart as Pete Lindstrom :-) In general, I am leaning towards "there is no ROI for security; there are only cost savings."

I could not agree with him any less. You have a step throat and being concerned about it, you decide to go to a doctor. The doctor treats you and you pay for the service. The doctor tells you that the doctor's service provided you ROI - you were cured in 3 days without  the doctor's service it would have taken 7 days, thus adding 4 additional days for your productivity.

EPD= Your Earning Per Day in $

Your ROI=4*EPD- (Doctor Fees)

Do doctors have to justify ROI for treating you?

Which one would you value most: your cure or your ROI?

Why should security professionals need to demonstrate ROI when they address the ailments/threats for a company's health?