The return on investment (ROI) in cybersecurity is a complex issue for Chief Information Officers (CIOs) and Chief Security Officers (CSOs). These leaders are trying to measure the cost of cyberattacks and justify their budgets, especially as threats have become more advanced with the rise of artificial intelligence (AI). Traditionally, cybersecurity strategies focused on avoiding costs from attacks, but today’s challenge is to value security investments more broadly. Despite efforts to predict and detect risks, the lack of precise data on AI-enhanced threats and the financial damage from attacks makes it hard to justify budgets. Cybersecurity spending often only increases after an attack has already occurred. According to the 2026 CESIN Barometer, 90% of organizations now monitor cyber risk at least once a year, showing that board members are more aware of these issues. Initially, this awareness led to increased budgets for CIOs, but recent trends show that budgets have stabilized as companies focus on improving existing security measures. Many CSOs report that they must regularly justify their spending, with the threat of budget cuts if they fail. Measuring the value of security expenditures is challenging because the current model emphasizes avoiding losses from undetected attacks. CSOs often explain that their spending has prevented financial loss, trying to quantify "what did not happen." However, calculating the impact of a cyberattack—whether through ransom demands or operational disruptions—remains a complex task. These impacts could serve as benchmarks if the right evaluation scale is used. The real difficulty lies in measuring indirect costs, particularly those from business interruptions, which can result in widely varying estimates. Additional complexity comes from potential regulatory penalties, such as those imposed by the GDPR and NIS2 directive in Europe, where fines are based on a percentage of revenue for companies that neglect data protection. Indirect costs, such as the damage to a company's brand image from a cyberattack, can have both immediate and long-term effects. Beyond these calculations, cybersecurity investments often provide business value that goes beyond just security. For example, firewalls can improve service quality management, URL filtering, and link management, ensuring better connectivity for critical operations. Functions such as SSL or IPsec Virtual Private Networks (VPNs) enable remote work and maintenance, offering clear productivity benefits. By modernizing these tools, security measures free companies from physical limitations. Moreover, cyber maturity, enhanced by AI technologies, has become a significant factor in tenders. Cybersecurity is now a key selection criterion and a strong competitive advantage. Quantifying the financial impact of a potential cyber incident is crucial for risk management and budget decisions. However, calculating ROI is difficult because of the confidentiality surrounding the sector. Organizations often lack reliable data to create solid financial models. High-profile incidents costing hundreds of millions of euros are frequently reported in the news, but these only represent a small part of the overall problem. Conversely, many small and medium-sized enterprises (SMEs), which are especially vulnerable, are hesitant to disclose the costs of attacks they have suffered. This lack of transparency makes it difficult to create accurate financial projections. Despite these challenges, solutions exist. The ANSSI, France’s national agency for information systems security, developed the EBIOS Risk Manager method in 2018 to help organizations identify and understand their specific risks. Each type of attack is cataloged, evaluated based on its impact, and assigned a cost. Companies can then create a quantifiable risk management plan and evaluate ROI by subtracting the investment from expected losses. Once this calculation is done, it is essential to measure the effectiveness of the risk management plan through a control process. However, if no incidents occur despite the use of detection tools, it is unclear whether the solution is effective or if no attack actually occurred. While regular reports listing attack attempts provide some clarity, uncertainty remains. The traditional risk-based approach also involves rationalizing protective measures. A new challenge for cybersecurity is to optimize security without sacrificing diversity and multiple layers of defense. Focusing too strictly on financial ROI might overlook the broader picture, as the cyber landscape is evolving rapidly. Regulatory pressure, particularly from the NIS2 directive, is making security a critical governance issue that directly involves executives. Protection is also becoming a key component of Corporate Social Responsibility (CSR), forming the foundation of digital trust for customers and partners. The rapid development of AI is expected to change the equation by automating attacks, making traditional risk calculations less relevant. Beyond the financial return of a tool, the board of directors must now take on a global responsibility that includes legal, ethical, and technological aspects. As threats evolve, the very sustainability of the organization and its role in a trust-based ecosystem depend on this shift.