The Return on Security Investment
Turn stronger security into lasting business value.
Security investments create value throughout a product’s lifecycle. The benefits rarely appear as a single saving. Instead, they accumulate through avoided vulnerabilities, reduced engineering time for emergency response, and products that remain secure and supportable for longer.
CHERI helps deliver this value by reducing cyber risk, limiting the impact of compromise, and extending the lifetime of critical software investments.
Value Across the Lifecycle
Design
Building security in from the start is usually more effective and less costly than adding it later. CHERI provides hardware-enforced protection and compartmentalisation that help create more resilient system architectures. Like encryption and authentication, CHERI is an essential security capability that can be incorporated into products from the outset.
Development
Finding defects earlier reduces cost and risk. CHERI can help developers discover invalid memory accesses very quickly during development and testing, making some issues easier to diagnose and fix.
Verification
CHERI provides concrete security properties that can be tested, evaluated, and documented, helping organisations demonstrate that appropriate protections are in place.
Operations
By preventing many memory-safety vulnerabilities from becoming successful exploits and limiting the reach of compromised software components, CHERI can help reduce operational risk and improve resilience.
Maintenance
Products often remain in service for many years. CHERI can help reduce support and remediation effort by limiting the consequences of vulnerabilities and improving fault isolation.
Understanding ROI
Adopting CHERI involves an initial investment, which may include new hardware, software adaptation, integration, and training. In many cases, this can be aligned with an existing product or platform refresh cycle.
Depending on the case, this could mean:
- Switching to a CHERI processor when designing a chip
- Porting existing software - which is often a straightforward engineering task
- Changing some development habits for software developers
- Using CHERI chips when designing a product
- Requesting CHERI products instead of less secure ones
The return on CHERI is not measured only by incidents that never happen. Organisations can also benefit from:
- Reduced engineering effort spent investigating vulnerabilities
- Faster remediation and response times
- Lower operational disruption
- Reduced maintenance and support costs
- Reuse of assurance activities across product generations
- Longer useful life for software and platforms
These benefits can often be observed long before a major security incident is avoided.
For product vendors, stronger security can also create value through increased customer confidence, easier procurement conversations, and differentiation in security-conscious markets.
Beyond Cost Reduction
CHERI can also help organisations:
- Meet customer security expectations
- Support secure-by-design objectives
- Respond to emerging regulatory requirements
- Build trust with customers and stakeholders
- Differentiate products in security-conscious markets
As security becomes an increasingly important factor in purchasing, procurement, and regulation, these benefits can translate into commercial advantage as well as risk reduction.
Where the Value Is Strongest
CHERI often delivers the greatest value when:
- Existing C or C++ software is expensive to replace
- Products are widely deployed or difficult to update
- Systems are expected to operate for many years
- Software handles sensitive data or critical functions
- Security incidents have significant operational or financial consequences
The case may be weaker where software is already memory-safe, strong isolation mechanisms already exist, or the protected code has limited access to valuable assets.
A Long-Term Investment in Resilience
CHERI is not a replacement for good development processes, testing, updates, monitoring, or other cybersecurity controls. Its value comes from addressing one of the most persistent sources of software vulnerability while preserving existing software investments.
For organisations building products that must remain secure, reliable, and supportable for years to come, CHERI can create long-term value by reducing risk, lowering operational burden, strengthening assurance, and extending the life of critical software assets.
