<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Ten Points about Security ROI and ROSI</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=296" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=296</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Rob</title>
		<link>http://spiresecurity.com/?p=296&#038;cpage=1#comment-416</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Tue, 24 Jul 2007 15:47:57 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=296#comment-416</guid>
		<description><![CDATA[The point I tried to make earlier was that there is a portion of operating budget under security that is regarded as a mimimum cost that comes from using inherently flawed IT systems. One does have the choice of spending nothing, but I suppose the time until you were owned, your data was tampered with or not available, your IP stolen and your customer&#039;s trust was stolen might be measureable in hours, if not days.

If you really don&#039;t have an option to opt-out, is it not really a sunk cost, no matter where it appears on the financial statment?
]]></description>
		<content:encoded><![CDATA[<p>The point I tried to make earlier was that there is a portion of operating budget under security that is regarded as a mimimum cost that comes from using inherently flawed IT systems. One does have the choice of spending nothing, but I suppose the time until you were owned, your data was tampered with or not available, your IP stolen and your customer&#8217;s trust was stolen might be measureable in hours, if not days.</p>
<p>If you really don&#8217;t have an option to opt-out, is it not really a sunk cost, no matter where it appears on the financial statment?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Bejtlich</title>
		<link>http://spiresecurity.com/?p=296&#038;cpage=1#comment-415</link>
		<dc:creator>Richard Bejtlich</dc:creator>
		<pubDate>Sat, 21 Jul 2007 18:52:15 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=296#comment-415</guid>
		<description><![CDATA[Hi Pete,

In an earlier post you said &quot;if you don&#039;t want to call it ROI, that is fine - you can perform the same calculations to get to cost/benefit comparisons and TCO differences.&quot;

Given that caveat I think I agree with everything you&#039;ve written in those earlier posts and this one too.
]]></description>
		<content:encoded><![CDATA[<p>Hi Pete,</p>
<p>In an earlier post you said &#8220;if you don&#8217;t want to call it ROI, that is fine &#8211; you can perform the same calculations to get to cost/benefit comparisons and TCO differences.&#8221;</p>
<p>Given that caveat I think I agree with everything you&#8217;ve written in those earlier posts and this one too.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
