← Latest papers
💻 computer science

Assessing the ROI of Cyber Threat Intelligence: An Operational and Financial Evaluation Framework

This paper proposes a comprehensive framework for assessing the Return on Investment of Cyber Threat Intelligence by introducing a Threat Intelligence Effectiveness Index (TIEI) to measure operational maturity and a breakeven-first financial method to quantify investment viability despite the inherent difficulty of measuring prevented cyber incidents.

Original authors: Matteo Strada, Stelvio Cimato

Published 2026-07-17
📖 5 min read🧠 Deep dive

Original authors: Matteo Strada, Stelvio Cimato

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine you are the captain of a massive, high-tech spaceship cruising through the asteroid belt of the internet. Your job is to keep the ship safe from space pirates, rogue asteroids, and sneaky saboteurs. You have a team of lookouts, a radar system, and a shield generator. But here's the tricky part: the best day your team can have is a day where nothing happens. No alarms, no explosions, no damage. The ship just keeps sailing smoothly.

This is the world of Cyber Threat Intelligence (CTI). Think of CTI as the "super-spy network" for your digital ship. Instead of just waiting for an alarm to go off, CTI gathers secret reports from other ships, spies, and sensors to tell you exactly where the pirates are hiding, what kind of weapons they are using, and how they plan to attack. It turns a mountain of confusing noise into a clear, actionable map.

But there's a huge problem for the people paying for this spy network (the ship's owners, or in the real world, company bosses and boards). They want to know: "Is this expensive spy network actually worth the money?" In normal business, if you buy a new engine and the ship goes faster, you can measure the speed. But in cybersecurity, if you buy a spy network and the ship doesn't get attacked, how do you prove you saved money? You can't show a receipt for a disaster that never happened. This is the "Prevention Paradox": the better you are at your job, the less visible your success becomes.

This is where a new study by Matteo Strada and Stelvio Cimato comes in. They are like the ship's engineers trying to build a new kind of calculator. They know you can't just guess the value of a "non-event," so they created a clever two-part system to figure out if your spy network is actually saving you cash.

First, they built a "Threat Intelligence Effectiveness Index" (TIEI). Imagine this as a "Spy School Report Card." Instead of just giving a single grade, it checks four different skills:

  1. Quality: Are the spy reports actually true and useful?
  2. Enrichment: Did the team add extra details to the reports (like connecting a pirate ship to a specific gang)?
  3. Integration: Did the team actually feed these reports into the ship's radar and shields, or did they just sit in a drawer?
  4. Impact: Did the ship react faster? Did the shields block more attacks?

The cool thing about their report card is that it's strict. If your team is amazing at getting reports but terrible at using them, your overall grade tanks. It's like a chain: the whole chain is only as strong as its weakest link. You can't have a perfect score if one part is failing.

Second, they created a "Break-Even Map." Since no one knows exactly how many times a pirate would have attacked if they didn't have the spy network, the authors say: "Let's stop guessing and start mapping." They drew a line on a graph that shows the relationship between two unknowns:

  • How likely is a big attack? (The probability).
  • How much does the spy network stop it? (The mitigation).

The map shows that for your spy network to be worth the cost, these two numbers must multiply to be bigger than a specific "tipping point." For example, in the Finance sector (banks), the study illustrates that if your spy network can stop 20% of potential disasters, your company would need to face a realistic chance of a major attack of at least 34.4% per year to break even. In Healthcare (hospitals), the numbers are similar: you would need a 34.9% chance of a big attack to justify a 20% stop-rate.

Crucially, the authors did not "find" these numbers as universal facts. They are not predictions of what will happen. Instead, they are illustrative stress-test inputs. The study explicitly states that these are hypothetical scenarios used to show how the math works. The numbers change depending on your specific organization's costs and risks.

The authors also ran thousands of computer simulations (like running a video game a million times with different settings) to see how the math holds up under uncertainty. In these simulations, they used the "Spy School Report Card" (TIEI) only as a calibration assumption for a specific reference scenario. They did not conclude that a high TIEI guarantees you will reach break-even in the real world. Instead, they showed that if you assume a mature program (high TIEI), the math suggests a wider range of plausible success rates. If your program is less mature, the range of plausible success rates shrinks.

The big takeaway isn't that they found a magic number that proves CTI is always a winner. Instead, they gave companies a honest tool to stop guessing. They say, "Don't just tell your boss 'we saved you millions' because you can't prove it. Instead, show them your Report Card to prove you are good at your job, and then show them this Map to prove that, given your specific risks and the assumptions you are willing to make, the investment makes sense."

It's a way to turn the invisible art of "preventing bad things" into a clear, logical business decision. It admits that we can't know the future, but it gives us a solid way to plan for it, ensuring that the money spent on spies is actually protecting the ship, rather than just buying expensive, unused maps.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →