The Cost Center Trap
For years, security leaders walked into financial reviews treating budgets like a wishlist of technical tools. That approach is increasingly ineffective. A CFO must weigh competing demands for capital, operating expense, liquidity, and growth; a security request that cannot explain its business purpose is difficult to compare with other investments. The CISO’s task is not to make cyber risk sound frightening. It is to show how a proposed decision changes the organization’s exposure, operating capacity, and ability to meet its objectives.
Cybersecurity is neither simply an IT cost nor a guarantee against loss. It is a portfolio of choices that can reduce the likelihood or impact of disruption, meet obligations, and enable business activity. A productive CISO-CFO partnership turns security priorities into decisions finance can evaluate: what assets and processes are at stake, what risk is being accepted, what response options exist, and how each option consumes resources.
Start With Shared Business Objectives
The relationship works best when it begins before the budget request. CISOs should learn what the CFO and finance organization are trying to accomplish—such as improving efficiency, supporting an acquisition, protecting revenue, or controlling discretionary spending—and identify where security contributes. Finance, in turn, benefits from understanding the dependencies behind the company’s plans: data, identity, technology services, suppliers, and the people needed to operate them.
This requires regular conversations, not a once-a-year presentation. The CISO can ask finance leaders which forecasts, projects, and operational constraints matter most; the CFO can explain how investment decisions are assessed and what evidence makes a proposal credible. These discussions create a common vocabulary and reveal opportunities to solve more than one problem with a shared investment.
Cross-functional relationships matter as much as the direct CISO-CFO connection. CSO’s reporting on cybersecurity investment describes CISOs working with finance, legal, IT, engineering, and business leaders to connect security capabilities with their objectives. For example, a zero-trust initiative may support network modernization as well as access control; privacy work can involve legal and security together; and security monitoring or alerts can be designed to help engineering teams respond to issues. Such examples should be validated in the organization’s own context, rather than assumed to deliver savings automatically. (Source: CSO, “How CISOs can forge the best relationships for cybersecurity investment”.)
Translate Risk Into Choices
Technical findings become useful to finance when they are connected to business consequences. Instead of leading with a list of vulnerabilities or products, explain which essential service, asset, or obligation is affected; how an incident could impair it; and what practical choices leadership has. Keep uncertainty explicit. Estimates of incident probability and loss are not certainties, and false precision can undermine trust. Where reliable numbers are unavailable, describe scenarios, assumptions, and ranges rather than presenting a single figure as fact.
A decision brief can set out the current condition, the plausible business impact, the proposed action, the cost and timing, and the residual risk after implementation. It should include alternatives: accept the exposure for now, reduce it through a specific control or process change, transfer part of the financial impact where appropriate, or invest in recovery capability. The CFO can then see not just a request, but the trade-offs and the consequences of deferring action.
Prioritization should account for the organization’s risk tolerance and strategic plans. A control that protects a critical revenue process or sensitive information may deserve attention before a technically interesting improvement with limited business consequence. The CISO should explain dependencies and sequencing—for instance, whether a program requires staff, process redesign, or infrastructure work before a tool can be effective. A purchase alone rarely constitutes a complete risk treatment.
Build an Investment Case, Not a Shopping List
An effective proposal identifies the outcome sought and how progress will be assessed. Costs should include implementation, ongoing licensing or operation, staffing, training, and any transition burden. Benefits may include reduced exposure, improved detection and recovery, stronger compliance readiness, or support for a business initiative. Avoid claiming that a security investment will prevent all incidents or guarantee a particular financial return. The case is stronger when it states what the measure can and cannot accomplish.
Where a solution supports more than one function, bring those stakeholders into the case. CSO’s reporting emphasizes understanding adjacent leaders’ goals and identifying tools or initiatives that may help achieve shared objectives. Finance may value a proposal that also improves efficiency or avoids duplicated work, but savings should be evidenced rather than asserted. Where benefit estimates rely on assumptions, disclose them and revisit them after deployment.
CISOs should also distinguish between spending that creates a new capability and spending required to sustain one. A security program may have recurring personnel and operating costs, while a one-time implementation still creates long-term obligations. Showing the full lifecycle prevents a low initial price from obscuring future commitments and helps the CFO compare options on a consistent basis.
Make Budget Pressure Visible
Budget conversations can expose conflicting instructions. Leadership may express low tolerance for cyber risk while simultaneously requiring cuts. If those positions cannot both be met under the existing plan, the CISO should make the conflict visible rather than silently promising an impossible outcome. Present the services or safeguards affected by different reduction levels, the resulting exposure, and the decisions that require executive acceptance.
CSO reports EY cybersecurity consulting leader Richard Watson’s observation that CISOs can face this paradox, and his recommendation to surface it with appropriate governance allies, including the audit and risk committee chair. A clear account of the trade-off can help leadership decide whether to fund a measure, preserve current capacity, change the risk target, or formally accept the exposure. It also guards against an unspoken assumption that risk will remain unchanged after resources are removed. (Source: CSO, “How CISOs can forge the best relationships for cybersecurity investment”.)
Cuts should be evaluated by their effect, not merely by a uniform percentage. Leaders can compare which capabilities are essential, which work can be deferred safely, and where process changes or consolidation might reduce cost without removing a critical safeguard. For each proposed cut, document the control or service affected, the likely operational consequence, any compensating measure, and the executive owner of the remaining risk. Avoid implying that every reduction causes an incident; explain instead how it changes preparedness or exposure.
Communicate for the Boardroom
Visibility and credibility are built through ongoing participation in business and risk discussions. The CISO should communicate beyond the technical organization and help leadership understand the threat context relevant to the company. A useful update is concise, consistent, and tied to decisions: what has changed, which business services are most exposed, whether agreed actions are on track, and where leadership must choose among competing priorities.
Metrics should support judgment rather than create a false impression of certainty. Pair activity measures—such as coverage or remediation progress—with outcome-oriented indicators, known limitations, and trends. Explain what a metric does not show. A dashboard full of tool counts may demonstrate activity without explaining whether the company can continue operations or recover when a service is disrupted.
The CISO’s reporting line can influence access to decision-makers and day-to-day understanding of organizational priorities, but structure alone does not ensure alignment. Relationships, business fluency, and a willingness to discuss risk in operational terms are essential regardless of whom the CISO reports to. A trusted adviser raises difficult constraints early, presents evidence fairly, and avoids escalating every issue as an emergency.
Measure Outcomes and Revisit Assumptions
After approval, the partnership should continue. Agree on milestones, owners, and review dates. Compare actual implementation and operating costs with the proposal; measure whether the intended capability is in place; and identify delays or new dependencies. If the threat environment, business strategy, or assumptions change, return to the decision rather than treating the original approval as permanent proof that the risk is solved.
A useful review asks whether the investment reduced the targeted exposure, improved response or recovery, met an obligation, or enabled a business objective. It should also record residual risk and unresolved work. Lessons from incidents, exercises, audits, and operational disruptions can inform the next cycle of prioritization. This is not an argument for measuring security only in dollars: some obligations and resilience goals matter even when a direct financial return cannot be credibly calculated.
A Practical CISO-CFO Operating Rhythm
CISOs and CFOs can establish a simple cadence: a periodic discussion of business priorities and material changes; a shared review of the highest-impact risks and planned treatments; a clear process for evaluating new investment requests; and an agreed escalation path when budget instructions conflict with stated risk tolerance. Each meeting should end with decisions, owners, dates, and any risk leadership has chosen to accept.
The partnership succeeds when finance is not asked to approve a mysterious technical request and security is not left to translate financial priorities after plans are settled. Both leaders bring distinct expertise: the CISO understands threats, controls, and operational resilience; the CFO understands capital allocation, financial constraints, and performance. Combining these perspectives enables better-informed investment choices, makes trade-offs explicit, and supports growth without pretending that risk can be eliminated.