Working Through the Security Benefits Worksheet
Most people who run into Lines 6a and 6b on a security benefits worksheet don't realize what trips them up until they've already filled out the first five lines and hit a wall. The worksheet itself is a structured way to quantify the return on security controls, but Lines 6a and 6b are where the actual judgment happens. Lines 1 through 5 cover things like baseline costs, identified threats, and control selections. That's the straightforward part. Lines 6a and 6b ask you to separate tangible benefits from intangible ones and then assign a confidence level to each number. That's where things get messy. Line 6a is your tangible benefit calculation. This is the dollar amount you can directly point to and say this is what we save or avoid per year. Common entries here include reduced incident response costs, lower insurance premiums after controls are in place, avoided regulatory fines, and decreased downtime costs. Line 6b is your intangible benefit line. Brand reputation protection, improved customer trust, competitive advantage, employee morale — things that matter but resist neat dollar signs. The most common mistake I see is people trying to force everything into Line 6a because it looks better on a presentation. Executives prefer clean numbers. That's fine, but if you put a vague intangible benefit into the tangible line, your whole calculation becomes unreliable. The model breaks when the inputs are speculative.
I ran into this exact problem last year when I was working through a worksheet for a mid-size healthcare provider. They had a new encryption control going in, and I needed to justify the annual cost against projected benefits. The tangible side was straightforward — fewer breach-related incident costs, some insurance savings. But the real driver was HIPAA compliance confidence, which is fundamentally intangible. If I'd stuffed that into Line 6a, the ROI would have looked absurdly high. Instead I put it in Line 6b with a confidence rating and moved on. Here's the part nobody emphasizes enough: the confidence score on Line 6b matters more than the dollar amount. A well-justified intangible benefit at medium confidence beats a vague tangible number at high confidence every time. Auditors and review boards can see when someone has hand-waved a figure. Document the assumption chain. Show where the number came from. Reference historical incident data or industry benchmarks when possible. If you can't find a benchmark, say so and adjust the confidence level accordingly. Another nuance people miss is the relationship between Lines 6a and 6b and the rest of the worksheet. The sum of both lines feeds into your overall benefit calculation, but they don't carry equal weight in every decision framework. Some organizations use a multiplier on tangible benefits before comparing against control costs. Others require that tangible benefits alone cover at least 60 percent of the control cost. Check your internal policy or compliance requirements before finalizing. The formula you use to combine these lines varies by organization.
There's also the issue of double counting. I've seen worksheets where the same avoided cost appears in both a tangible line earlier in the document and again in Line 6a. It happens when the same control mitigates multiple risks that share underlying cost factors. When you're mapping benefits back to specific controls, keep a tracking sheet. It takes an extra fifteen minutes and saves you from having to rebuild the whole thing when someone asks for a revision. One practical tip for filling these lines efficiently: start with the worst-case scenario and work backward. Estimate the total annual loss exposure without the control, then subtract the residual risk after implementation. The difference is your benefit pool. Split that pool between Lines 6a and 6b based on how directly measurable each portion is. This approach prevents you from accidentally inflating the tangible line to make the numbers look acceptable.
Get the Full Details

Where This Process Actually Fails
The worksheet isn't a magic bullet. It produces a single composite number that looks precise but rests on a stack of assumptions. If your incident frequency data comes from a three-year window during unusually low attack activity, your baseline is wrong and every line downstream is wrong too. You're not going to fix that by filling out more rows. You'd need to go back to Line 1 and adjust the input data. Small organizations especially struggle with this because they lack historical data. If you've never had a security incident, you can't honestly estimate incident costs. In those cases, lean heavily on industry reports and peer benchmarks, document which sources you used, and mark your confidence as low to medium. That honesty will serve you better than an overly confident projection. When the calculations consistently show that security controls cost more than their combined Lines 6a and 6b benefits, you have a real problem. The worksheet isn't wrong — it's telling you something important. Either the controls are poorly chosen, the benefits are underestimated, or the organization shouldn't be investing in this particular control set. Running a sensitivity analysis on your key assumptions usually reveals which lever matters most. Shift your incident probability up or down by twenty percent and see how the result changes. That tells you where your estimates are fragile.