The AI Learning Hub Journal

The Business Case, Honestly

Arithmetic you can do on one page — done honestlyyour alert mix and close times are knowable facts — anchor the case in them, not in vendor benchmarksalerts / dayin the classes it touchesminutes saved / alerttoday vs with the productloaded analyst costyour rate, not a benchmarkgross savingbefore the discounts××=THE HONESTY DISCOUNTS — APPLY BEFORE ANYONE SEES THE NUMBERcount only the alert classesthe product genuinely coversramp the benefit over adoptionmonths, not from signaturesaved hours count only wherethey demonstrably goWHAT THE CALCULATOR OMITS+ integration and parser engineering+ tuning time before advertised accuracy+ sampled review of auto-closed alerts+ training and process change+ licence growth as data volume risesauto-closed alerts still need sampled human reviewWHAT IT QUIETLY INFLATES− benchmark savings from customers with ideal telemetry− full adoption assumed from day onerebuild it: their numbers and your costs side by side —the gap between the two totals is itself diligencepresent it back — the reaction is part of the evaluationPRICE BOTH FAILURE DIRECTIONS — AND ASK WHO CONTROLS THE THRESHOLD THAT TRADES THEMTHE COST OF NOISE — PAID NOWanalyst hours and attention — a noisy productretrains the team to dismiss alerts, degradingreal coverage while the dashboards look fineTHE COST OF A MISS — PAID LATERincidents, dwell time, historical breach costin your sector — invisible until the dayit is an incidentsuppression is the easiest metric to improve and the most dangerous — the miss it creates stays invisibleBUILD IT FROM YOUR OWN TICKETING DATA — VOLUMES AND CLOSE TIMES ARE FACTS YOU OWN"analyst hours saved" that nobody reallocates is a number on a slide, not a return
Build the case from your own ticketing data, add the lines vendor calculators omit, and price the miss as carefully as the noise.

Do the Analyst-Hour Arithmetic Yourself

Every AI security business case reduces to arithmetic you can do on one page: alerts per day in the classes the product will actually touch, minutes per alert today, projected minutes with the product, times a loaded analyst cost. Build it from your own ticketing data, not the vendor's benchmarks — your alert mix and close times are knowable facts, and they anchor the case in your reality. Then apply the honesty discounts: the product handles a subset of alert classes, adoption ramps over months rather than day one, and saved minutes only become value if they turn into reduced backlog, deeper investigations, or deferred hiring. "Analyst hours saved" that no one reallocates is a number on a slide, not a return.

  • Source the inputs from your own ticketing system — alert volume and close times are facts you own
  • Count only the alert classes the product genuinely covers, not total SOC volume
  • Ramp the benefit over a realistic adoption curve, not from contract signature
  • Name where saved hours go — backlog, depth, or deferred hiring — or do not count them

What the Vendor Calculator Hides

Vendor ROI calculators are directionally honest and structurally flattering. The standard omissions: integration and parser engineering to get your log sources into shape; tuning time before the advertised accuracy materialises; the ongoing cost of reviewing the product's output — because someone must audit the auto-closed alerts, and that review time nets against the savings; training and process change; and the licence growth curve as data volume rises. The standard inflations: benchmark time-savings from customers with ideal telemetry, and full adoption assumed from day one. Rebuild the model with their numbers and your costs side by side — the gap between the two totals is itself useful diligence, and vendors respond to it with either engagement or discomfort. Both are informative.

  • Add the missing lines: integration, tuning, output review, training, licence growth
  • Auto-closed alerts still need sampled human review — that cost nets against the savings
  • Ask which customer profile produced the benchmark numbers, and how yours differs
  • Present the corrected model back to the vendor; the reaction is part of the evaluation

The Cost of a Miss vs the Cost of Noise

A complete business case prices both failure directions. False positives cost analyst hours and, at scale, attention: a noisy product retrains your team to dismiss alerts, degrading real coverage while the dashboards look fine. False negatives cost incidents, and pricing them means an honest look at your own numbers — breach costs in your sector, dwell time, what a missed intrusion has historically cost you. The two trade against each other through the product's alerting thresholds, so ask where the vendor sets that trade and whether you can move it. Be suspicious of products marketed on alert reduction alone: suppression is the easiest metric to improve and the most dangerous, because the miss it creates is invisible until it is an incident.

  • Price both directions: noise costs attention now, misses cost incidents later
  • Ask how alert reduction is achieved — suppression, deduplication, and triage carry different miss risks
  • Threshold control should sit with you, because you own the consequences of the trade
  • A product judged only on fewer alerts is being judged on the metric easiest to game

Compliance Value: Real or Theatre

Compliance framing appears in nearly every AI security business case, and some of it is real: if the product materially shortens audit evidence collection, closes findings your last assessment raised, or produces the AI-system inventories and audit trails that frameworks like the EU AI Act and NIST AI RMF increasingly expect, that value is quantifiable — count the hours and the findings. The theatre version is framework name-dropping: a slide listing regulations the product is "aligned with", certifications that describe the vendor's own controls rather than anything about your obligations, and "audit-ready" claims no auditor has tested. The test is specificity: which control, in which framework, evidenced how? Real value survives that question in detail. Theatre changes the subject.

  • Real value: hours saved on evidence collection, findings closed, inventories produced
  • The vendor's certifications describe their controls, not your compliance posture
  • Ask: which specific control does this satisfy, and what evidence would I show an auditor?
  • Regulation logos on a slide are marketing until mapped to controls you actually own

Try It Yourself

A business case you did not build yourself is a business case you cannot defend in a budget review. Rebuild one from your own numbers.

◆ Try it yourself

Take one ROI claim — from a vendor deck, a published case study, or a draft of your own business case — and redo the arithmetic with your organisation's real volumes. Then write the one sentence you would say if a CFO asked where the number comes from.

Alerts per day at our volume:        [number]
Minutes an analyst spends per alert: [number]
Fully-loaded analyst cost per hour:  [number]
= Gross hours and money in play:     [work it out]

Now the discounts the deck left out:
- What share of alerts does it handle unaided?  [%]
- What review time does its output still need?  [minutes]
- What does a miss cost, and how likely is one?  [your estimate]

Honest net: [number] — the sentence I would defend it with: [one line]
How you'll know it worked
  • Your net figure is materially different from the vendor's headline number
  • You can name which assumption in their version does the most work
  • The defending sentence survives being read aloud to someone sceptical

Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.