The Total Economic Impact™ of Cisco Duo: 198% ROI and $4.4M NPV
The smartest cybersecurity investments don’t just help businesses avoid losses, they increase productivity and satisfaction at the same time. To measure the value achieved through strong identity security, Cisco commissioned Forrester Consulting to conduct a Total Economic Impact™ (TEI) study for Cisco Duo.
Forrester consultants interviewed seven decision-makers about their experiences with Duo and the benefits, costs, risks, and flexibility of their investments. Following these sessions, Forrester aggregated the results and conducted an in-depth financial analysis for a composite global organization with annual revenues of $2.5B and 10k full-time employees (FTEs).

The resulting TEI study that published in July 2025 showed the composite organization achieved substantial value over a three-year period by investing in Duo.

What the TEI findings mean to you
The bottom line? Duo represents a smart investment.
Forrester writes in the study: “A positive project NPV normally indicates that the investment should be made unless other projects have higher NPVs.” Duo’s 198% ROI and $4.4M net present value (NPV) point to a sound and rewarding investment.
The commissioned study conducted by Forrester Consulting on behalf of Cisco highlights the fact that Duo delivers transformative benefits on three critical fronts: stronger security, higher productivity, and greater operational efficiency.
First things first: Duo strengthens security

Without a centralized identity and access management (IAM) solution, interviewees told Forrester their organizations struggled with security gaps, compliance challenges, and operational complexity. Some reported applying weak MFA processes for critical systems like VPNs, leaving users reliant on vulnerable passwords as their primary method of authentication.
Companies that do not have strong identity security face higher risk from phishing attacks, credential theft, and brute-force intrusions. A single compromised password could give adversaries access to multiple systems and pave the way for lateral movement leading to devastating breaches.
Duo raises the bar with security-first IAM
With its official expansion into the IAM market, Duo overcomes the limitations of traditional IAM solutions that emphasize business enablement over—and at the cost of—robust security. In the study, Forrester notes that Duo is:
A leading IAM solution that takes a security-first approach to address modern identity-based threats without compromising usability. It delivers comprehensive protection through security-first identity, end-to-end phishing resistance, and unified identity intelligence.
After investing to make Duo the cornerstone of their identity strategies, organizations strengthened security by closing visibility gaps and controlling who logs in from where using what devices.
"We’ve used Cisco Duo to drive our Zero Trust [strategy]. If [it detects] odd logins or things that are abnormal, it requires more security, so that’s been helpful. Cisco Duo has evolved, and security has gotten more important, [such] that they [have deployed] additional features that would help us lock down the environment."
IT Security Manager
Transportation Organization
Risk reduction valued at $1.6M
The TEI calculated the overall value of Duo’s cyber risk reduction to the composite organization at $1.6 million citing measurable improvements in breach prevention, identity security, and threat detection. The TEI notes that Duo combines user and device authentication to create layered protection against unauthorized access to resources that includes strong MFA, end-to-end phishing resistance, device verification, and unified identity intelligence. This layered approach helps the composite reduce the likelihood of unauthorized access leading to a breach and minimize breach-related costs such as legal fees, data recovery, and reputational damage if one did occur.
Duo improves security through:
Best-practice logins
Visibility across applications
Threat detection powered by machine learning
Disruption of the attack chain to block lateral movement toward sensitive systems
But while the “killer app” for multi-factor authentication (MFA) is still improving defenses against identity-led attacks, Duo’s ability to enhance productivity has even greater financial impact.
Simplicity boosts productivity
Interviewees told Forrester consultants that Duo reduces the time it takes to log in, simplifies access across all applications, and minimizes disruptions throughout the workday.
The CISO at a technology services company noted:
"[Prior to Duo,] it was not uncommon [to have] a dozen logins a day . . . If you were using a password manager, hopefully it [worked in] a couple of clicks. If you were not signed in to your password manager, at best you would have to hand-type out your password, [which would take] maybe 30 seconds, and then you would have differing degrees of MFA or login challenges."
Improved productivity valued at $4.7M

With Duo helping to mitigate friction and streamline authentication, end-users save time and experience less frustration. Duo Passport and Session Theft Protection extend trust across multiple applications and throughout entire user sessions so employees don’t get interrupted while working to authenticate again.
The TEI calculated the accumulated three-year value of enhanced productivity achieved using Duo at $4.7 million based on improved user experience (UX) saving full-time employees (FTEs) 137,500 hours per year. Instead of managing multiple logins, the study says Duo lets users “get to work faster and stay productive with fewer interruptions.”
Duo’s straightforward, user-friendly MFA simplifies onboarding and reduces login friction with a consistent, simplified experience across all clients, web-based apps, and browsers.
"We looked at multiple different best-of-breed products at the time . . . and Duo was the easiest, both from an administrative and from an end-user perspective.”
Senior VP of IT
Healthcare Organization
Operational efficiencies compound the benefits
Drivers to adopting Duo include a variety of operational benefits including:
Streamlining identity operations to reduce complexity
Seamless integration with SaaS and on-premises applications and VPNs
Support for cloud and hybrid environments
Agility and scale as organizations expand
Out-of-the-box support for third-party tools
Without Duo, SecOps teams battled fragmented authentication systems with limited visibility. Disparate logs and platforms made anomaly detection and incident response (IR) even more challenging.
After investing, the TEI concludes:
Duo helps teams identify and address weak points in the authentication landscape and to scale and improve their security posture without overburdening internal teams. By offloading authentication and simplifying infrastructure, Duo enabled scalable protection with efficiencies for teams across security operations, IAM, and governance, risk, and compliance (GRC).
Optimization valued at $600K per year
Highlights of Duo’s time-savings and workload reduction benefits include:
IR improvements worth $276K — The TEI calculates Duo saves IR teams more than 5,000 hours per year by automating identity risk assessments, reducing false positives, and creating actionable visibility. Focusing on real threats faster reduces authentication-related IR efforts by 50%.
IAM efficiency gains worth $205K — Duo simplifies provisioning and empowers IAM teams to scale securely while maintaining strong administrative oversight across the IAM lifecycle.
Cyber insurance premium reductions worth >$89K — Duo helps IAM leaders navigate complex compliance and cyber insurance requirements, streamlining workflows with audit-ready evidence for a 20% reduction in cyber insurance premiums.
Help desk optimization worth $28K — Duo reduces calls to the help desk to reset passwords and unlock accounts, a substantial time savings for the IT team.

Duo has definitely improved our efficiency in security administration. The enhanced visibility provided by Duo, especially when combined with Cisco Identity Intelligence, allows us to identify and address security gaps proactively. This has led to a significant reduction in false positives and faster investigation times, freeing up our security operations center (SOC) analysts to focus on more critical threats.
A three-fold financial impact: security, simplicity, and streamlined operation
As security and IAM converge, Duo offers the industry’s only security-first IAM solution that makes organizations safer, stronger, and more agile and efficient:

Along with putting security first and delivering a world-class user experience, participants in the TEI highlighted the value of powerful innovations like passwordless, verified Duo Push, Duo Passport, and the ability of Duo Desktop to verify a user’s identity and the security posture of their device before granting access. Since then, Duo has evolved to include end-to-end phishing resistance capabilities for even stronger identity security:
Complete Passwordless Authentication including at initial onboarding and as a fallback
Proximity Verification designed to protect against adversary-in-the-middle attacks
Session Theft Protection that removes vulnerable “remember me” cookies from the authentication process leaving nothing for cybercriminals to steal
Seamless Help Desk Verification enabling identity verification for help desks to guard against social engineering attacks
AI-led insights powered by Cisco Identity Intelligence (CII) help organizations unify IAM and security to build and maintain a fully secure identity infrastructure. Duo offers everything business and IT leaders need to manage and secure identity in one place and an achievable ROI of nearly 200%.
Take the next step
To learn more about potential return on investment your organization might achieve by deploying Duo, read the TEI study.