Internal Rate of Return (IRR)

IRR is the discount rate that makes an investment's net present value equal to zero, meaning the present value of future cash inflows exactly matches the present value of cash outflows. It reflects the project's implied annual return; when comparing similar projects, the one with the higher IRR is usually preferred.

Key Points

  • IRR is the rate that sets NPV to zero (PV of inflows equals PV of outflows).
  • Decision rule: accept if IRR is greater than the required return or hurdle rate; among comparable options, higher IRR is better.
  • Limitations: nonconventional cash flows can produce multiple IRRs, and IRR can conflict with NPV or favor smaller, quicker returns.
  • Useful in agile portfolios to compare epics/features in a business case, alongside metrics like NPV and payback.

Example

Project A needs an upfront investment of USD 100,000 and returns 40,000 at the end of each of the next three years; its IRR is about 10%. Project B also needs USD 100,000 but returns 20,000, then 60,000, then 60,000; its IRR is about 16%. If the hurdle rate is 12% and risks are similar, choose Project B because its IRR is higher than the requirement and higher than Project A's IRR.

PMP Example Question

Your organization requires a minimum return of 12% on new initiatives. A proposed project has an IRR of 14%. What should the project manager recommend?

  1. Proceed, because IRR exceeds the required return.
  2. Reject, because IRR does not measure total profit.
  3. Defer, until the payback period can be shortened.
  4. Reject, because NPV must be zero to approve the project.

Correct Answer: A — Approve because the project's expected return (IRR) is above the hurdle rate.

Explanation: IRR represents the rate at which NPV equals zero. If IRR is greater than the organization's required return, the project meets the acceptance criterion.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build an ICS/OT cybersecurity foundation that fits the real environment

Standard IT controls can disrupt the industrial systems they are meant to protect. Learn how to assess OT risk, design zones and conduits, apply IEC 62443 security levels, use MITRE ATT&CK for ICS, and establish passive asset visibility without risking production. Eight reconstructed incidents connect attacker techniques to the controls that failed, giving you the vocabulary and judgment to make credible security decisions from day one.

Explore the Course