Netenrich Blog | Expert Cybersecurity Insights on SecOps, threats & more

Quantifying Cybersecurity ROI: The LIC Scoring Framework

Written by Raju Chekuri | Thu, Sep 10, 2026 @ 05:00 AM

Security is one of the few enterprise functions where significant investment decisions are regularly made without a framework for measuring what those investments produce. Finance tracks ROI. Operations tracks efficiency metrics. Product tracks quality and velocity. Security too often tracks activity - alerts processed, vulnerabilities scanned, incidents resolved - rather than outcomes.

To prove genuine Cybersecurity ROI to executive leadership, security programs must move beyond tracking workload volume and begin quantifying risk reduction.


Comparing Security Measurement Frameworks


Activity-Based Tracking vs. Outcome-Driven Cybersecurity ROI

Evaluation Metric Legacy Activity Tracking Outcome-Driven Cybersecurity ROI (L.I.C)
Primary Focus Volume of tasks completed (e.g., total alerts closed). Measurable reduction in business exposure and financial risk.
Risk Context Static severity scores (High/Medium/Low). Dynamic risk modeling based on active threat intelligence.
Business Alignment Siloed IT metrics disconnected from corporate assets. Impact metrics tied to business critical systems and data assets.
Board Reporting Operational logs that obscure true risk posture. Quantitative framework (L.I.C) demonstrating clear Cybersecurity ROI.


The LIC Scoring Framework: Likelihood, Impact, Confidence

The LIC scoring framework - Likelihood, Impact, Confidence - was built at Netenrich specifically to address this gap. Let me explain what each dimension measures and how they combine.

1. Likelihood (Threat Probability)

Likelihood quantifies the probability that a specific risk will be exploited, given the current threat landscape and the specific exposure characteristics of the asset. Likelihood is not a static assessment. It changes as threat intelligence changes - when active adversary campaigns targeting assets of this type are reported, likelihood increases. It changes as the environment changes - when a vulnerability is discovered on a previously clean system, likelihood increases. Likelihood is a dynamic variable that the system recalculates continuously.

2. Impact (Business Consequence)

Impact quantifies the business consequence of exploitation - drawing on asset criticality classification, data sensitivity ratings, operational dependency mapping, and regulatory exposure. A vulnerability on a payment processing system that handles PCI-scoped transactions has higher impact than the same vulnerability on a development sandbox. Impact connects security risk to business consequence in language that non-security stakeholders can evaluate.

3. Confidence (Analytical Certainty)

Confidence quantifies the analytical certainty behind the assessment - how complete is the underlying data, how reliable are the detection and behavioral models contributing to the score, what is the evidence quality. A finding with high likelihood and high impact but low confidence is a gap to investigate, not a confirmed emergency. Confidence prevents false precision: the framework acknowledges where the analytical foundation is insufficient rather than producing a number that looks authoritative but is not.


Making Risk Scores Actionable for the Board

The combination - L times I times C, normalized - produces a risk score that is actionable in ways that single-dimension threat severity scores are not. Two findings with identical threat severity but different impact and confidence require completely different responses. LIC makes that distinction explicit.

The framework emerged from years of customer engagement - from working with security leaders who needed quantitative language for credible board conversations. Our customers shaped it through their feedback: which metrics helped them make better investment decisions, which helped them explain posture changes to their boards, which were internally useful but externally opaque.

Security outcomes are measurable. The data infrastructure to measure them exists. Building your security program around outcome measurement rather than activity measurement is a choice worth making.

Quantify Your Risk and Prove Cybersecurity ROI

Tired of presenting vanity alert metrics to your board? Netenrich enables their proprietary LIC scoring framework, continuously translating raw, technical telemetry into dynamic business risk metrics you can proudly present to the board. Partner with Netenrich to operationalize true cybersecurity ROI.

*Part of my ongoing series on data science and the future of security operations.*

 
About the Author 


 

Raju Chekuri

A serial Silicon Valley entrepreneur and technology leader, Raju founded Netenrich and leads the company as chairman, president and CEO. Previously, he founded Velio Communications, Inc., and led its acquisition by LSI Logic and Rambus. He also served as chairman of the board at OpsRamp before it was acquired by HPE. He currently serves as an investor and advisor at early-stage startups Two Brothers Organic Farms and the Department of Lore. Raju earned an MBA at St. Mary’s College of California and a Bachelor of Technology at Kakatiya University.

Follow Raju on LinkedIn