Quantifying the ROI of Cyber Threat Intelligence: A Data-Driven Approach
Matteo Strada

TL;DR
This paper presents a novel data-driven framework to quantify the ROI of Cyber Threat Intelligence by integrating economic models, performance indicators, and a new composite metric, enabling organizations to justify CTI investments effectively.
Contribution
It introduces the Threat Intelligence Effectiveness Index (TIEI) and extends existing security economic models to better measure CTI's impact on risk mitigation.
Findings
TIEI effectively captures CTI performance across multiple dimensions.
Empirical case studies demonstrate significant improvements in detection and response metrics.
The framework enables organizations to justify CTI investments through measurable ROI.
Abstract
The valuation of Cyber Threat Intelligence (CTI) remains a persistent challenge due to the problem of negative evidence: successful threat prevention results in non-events that generate minimal observable financial impact, making CTI expenditures difficult to justify within traditional cost-benefit frameworks. This study introduces a data-driven methodology for quantifying the return on investment (ROI) of CTI, thereby reframing it as a measurable contributor to risk mitigation. The proposed framework extends established models in security economics, including the Gordon-Loeb and FAIR models, to account for CTI's complex influence on both the probability of security breaches and the severity of associated losses. The framework is operationalized through empirically grounded performance indicators, such as reductions in mean time to detect (MTTD), mean time to respond (MTTR), and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Intelligence, Security, War Strategy · Network Security and Intrusion Detection
