This article discusses a framework to evaluate the costs and benefits of IT security solutions using a company s risk profile. This method uses an unconventional concept of benefit based on risk avoided rather than increased productivity.