ROI · Secrets and CVEs

Security hygiene

What is flagging a leaked key or a vulnerable dependency before merge worth?

One every two years. A leaked key or an exploitable CVE that reached production.

%

Secrets, static security, Dockerfile/Compose/Kubernetes config (not Terraform) and live CVE data from osv.dev.

$

Response, key rotation, audit, customer communication.

Charged against the result.

min

Read, decide, dismiss or fix.

$

Fully loaded cost of one engineering hour — salary, benefits, overhead. Use your own.

The formula

Nothing on this page is hidden.

loss avoided / year = incidents per year × prevention rate × incident cost
triage / year       = alerts per month × triage minutes ÷ 60 × rate × 12

net / year          = loss avoided − triage

This is an expected value. Most years bring no incident; the year that does costs far more than this figure.

Security findings never move the Architecture Integrity Index, so they are counted here and nowhere else.