ROI and business value

describes dashboard widgets related to ROI and business value

ROI settings are described at the end of this article.

See important notes for updating ROI settings in Update configuration settings in the Dashboard settings and system-wide defaults article.

Automation ROI summary

Displays: A high-level executive summary demonstrating the business value and return on investment from your security automation efforts.

Business Value: Quantifies the tangible benefits of automation in terms of time saved, cost savings, and efficiency gains.

Metrics Displayed:

  • Resolved Events: Total number of security events that have been closed

  • Mean Dwell Time: Average time events stay in the system from creation to resolution

  • Mean Time To Resolution: Average time to completely resolve an event

  • Time Saved (optional): Total time saved through automation

    Time Saved = Total Actions Executed × Average Time Per Action

    • Total Actions Executed: Sum of all automated and manual actions run during the period

    • Average Time Per Action: Configurable setting (default: 4 minutes per action)

    Example: If 1,000 actions were executed and each action saves 4 minutes:
    • Time Saved = 1,000 × 4 minutes = 4,000 minutes = 66.7 hours

  • Money Saved (optional): Dollar value of time saved

    Money Saved = (Time Saved in Hours) × Hourly Rate

    • Hourly rate: Calculated from annual salary setting divided by annual work hours

    Example: If 66.7 hours were saved and the hourly rate is $75/hour:
    • Money Saved = 66.7 × 75=75=5,002.50

  • FTE Gained (optional): Full-Time Equivalent staff capacity freed up by automation

    FTE Gained = Hours Saved ÷ Expected Work Hours in Period

    Example: If 200 hours were saved in a 30-day period:

    • Expected work hours per person = 30 days × 8 hours/day = 240 hours

    • FTE Gained = 200 ÷ 240 = 0.83 FTE (83% of one person's capacity)

ROI stats

Displays: Time-series graphs showing ROI metrics trending over time, providing visibility into automation effectiveness and cost savings across multiple dimensions.

Business Value: Tracks automation ROI trends to identify patterns, justify investment, and demonstrate continuous improvement.

Metrics Displayed:

Each metric is calculated per time period (hour/day/month) and displayed as a trend line.

  • Actions Run from Playbooks: Automated actions executed

  • Actions Run (Manual): Manual actions executed

  • Total Actions Run: Combined automated and manual

  • Containers Closed: Events resolved during the period

  • Hours Saved: Cumulative time savings

  • Dollars Saved: Cumulative cost savings

  • Hours Saved by Playbooks: Time saved specifically from automation

  • Hours Saved by Actions: Time saved from manual actions

ROI settings

These settings affect the ROI Summary and ROI Stats widgets and are used to calculate time and cost savings from automation.

Storage Location: System Settings database table

Configuration Path: Administration > Company Settings > Company ROI Settings

Annual Salary

  • Purpose: Used to calculate hourly rate for cost savings calculations

  • Default Value: $135,000 USD per year

  • How It's Used: Divided by total annual work hours to get hourly rate

  • Formula: Hourly Rate = Annual Salary ÷ 52 weeks ÷ 7 days ÷ Hours per Day

  • Example: 135,000÷52÷7÷8=135,000÷52÷7÷8=46.44 per hour

Currency

  • Purpose: Display format for monetary values

  • Default Value: "USD"

  • Available Options: USD ($), EUR (€), GBP (£)

  • How It's Used: Determines currency symbol in dollar savings displays

Display Options (Toggle Visibility)

  • Purpose: Controls which ROI metrics appear in the ROI Summary widget

  • FTE Gained: "on" or "off" (default: "on")

  • Time Saved: "on" or "off" (default: "on")

  • Money Saved: "on" or "off" (default: "on")

Minutes per Action

  • Purpose: Average time saved by each automated action

  • Default Value: 4 minutes

  • How It's Used: Multiplied by total actions to calculate time saved

  • Example: 1,000 actions × 4 minutes = 4,000 minutes (66.7 hours saved)

  • Recommendation: Adjust based on your actual action complexity

Hours Worked per Day

  • Purpose: Expected work hours per analyst per day

  • Default Value: 8 hours

  • How It's Used: Calculates expected work hours for FTE calculations

  • Formula: Expected Hours = (End Date - Start Date) × Hours per Day

  • Example: 30 days × 8 hours = 240 expected work hours

How Settings Are Retrieved:

  • Settings are cached for performance

  • Stored in the system settings database

Example Calculation with Custom Settings:

CODE
Settings:
- Annual Salary: $150,000
- Minutes per Action: 5
- Hours per Day: 8
- Period: 30 days
- Actions Executed: 2,000
Calculations:
1. Hourly Rate = $150,000 ÷ 52 ÷ 7 ÷ 8 = $51.27/hour
2. Time Saved = 2,000 actions × 5 minutes = 10,000 minutes = 166.7 hours
3. Money Saved = 166.7 hours × $51.27 = $8,546.71
4. Expected Hours = 30 days × 8 hours = 240 hours
5. FTE Gained = 166.7 ÷ 240 = 0.69 FTE (69% of one person)