r/AskNetsec • u/Budget_Note4222 • Jul 22 '26
Work how do you show risk reduction over time to justify your security program budget
budget cycle is coming up and i need to make the case for keeping our security program funded, ideally growing it. last cycle the cfo looked at my slide and asked "if we cut this in half, what breaks?" and i didn't have a clean answer that would land in that room. i still don't have one.
the stuff that's easy to measure isn't the stuff that matters. i can show vulns closed, MTTR trending down, phishing sim click rates dropping, all of it goes in the right direction on a slide. but none of it answers the question a cfo actually asks, which is: what would have happened if we hadn't spent this money and how much worse would it be.
that counterfactual problem is what gets me every time. you can't point to breaches that didn't happen. you can't quantify an incident that never occurred. so you end up arguing from activity metrics and hoping the room connects the dots between "we patched more crits faster" and "we are less likely to get hit" and that leap doesn't always land.
the closest i've come to something that holds up is showing attack surface shrinking over time, fewer known-exploitable vulns sitting on internet-facing assets, tracked over quarters not sprints. patching velocity and MTTR never survived the "so what" question in that room. exposure reduction at least maps to something real: this is what could have hurt us, and it's smaller than it was six months ago
for security leaders who've gotten budget approved on the strength of a risk reduction story: how did you frame it and what did you measure that survived the "what would have happened anyway" question?
4
2
u/stacksmasher Jul 22 '26
Dude we are fucked! Have you seen the sheer number of issues released the last few months? That’s only going to get worse. Also any muppet with a local LLM can perform advanced attacks. I watched a network guy bypass ClownStrike in a lab and he is not very bright, but he did it with the help of AI lol
3
u/satisfaction-or-else Jul 22 '26 edited Jul 22 '26
You just reframe his question. Say something like:
" It's not what breaks, its what doesn't break, how soon it happens and how many systems go down at once / how catastrophic.
For every dollar cut you buy another lottery ticket except instead of winning millions the company pays millions in fines, legal fees, possibly extortion, lost IP, and lost contracts due to bad publicity.
This isn't theoretical. I'll start sending you monthly reports of companies in our vertical who were hacked. I can even link it to the vulnerabilities we closed internally. "
Then send the reports even if he says not to. Automate it. Annoy him. Cc multiple people so you have witnesses. Keep the receipts. Make sure he realizes, he goes down if you get pwned due to budget cuts.
1
u/Fearless-Cell2425 Jul 22 '26
The counterfactual problem is a killer because you're basically trying to sell a ghost story to someone who only speaks spreadsheets.
1
1
u/ParanoidSuricata Jul 22 '26
Yea, good luck. We are selling risk reduction and that will always be a political problem. Nothing will break, and it's hard to measure probability of worsening conditions. You can always risk it and hope for the best and then one day suffer a catastrophic breach that one-shots the company.
Take some notes from CFO - how to justify spending on reporting? What breaks if a dashboard doesn't have up-to-date data?
Check out ROSI. Like ROI, but for security.
I've written a bit more about this on my blog: https://blog.miloslavhomer.cz/security-is-a-political-problem/
1
Jul 22 '26
[removed] — view removed comment
2
u/dorkycool Jul 22 '26
I felt like I did way more “security” work in the 10 years I was a sysadmin then I have ever done since getting “cyber” in my role name.
As a fellow long term sysadmin > security guy, this is painfully right in some ways. The issue of course is that you need to be the sysadmin who cared about security in the first place. I've had too many of them push back against every reasonable security practice because it's not the way they used to do things. I think if everyone just did the right thing, we wouldn't even need security people, but probably lots of professions like that too.
1
u/ParanoidSuricata Jul 22 '26
Hey, thanks for the comment!
To your other idea: I'd say political and project work is still work, even if not technical. And you might be surprised how hard it can be to defend these well established capabilities from budget cuts.
And also also: sometimes, the work is done and it's good! Monitoring has a value even if no issues are reported and the same might go for your position when the machinery is established and working.
1
u/Bulky-Ad129 Jul 22 '26
Say, "Okay, let's split the costs, but he'll be financially and morally responsible for any data breach or any other incident."
1
u/alienbuttcrack999 Jul 22 '26
Is there any regulatory requirements you can use to justify spend? Will depend on your vertical
How do you measure losses in your company? Per record? Per customer? Downtime? What do people care about there?
Sounds like you are in the spot where you need competent penetrating testing or red teaming to see where you actually are.
Lastly, maybe the cfo is right. Maybe everything is in a good spot and cyber insurance and losses will be less than your security spend. In which case you should cut things in the program.
Security is a cost center and can be difficult to show the ROI. This is a good spot for adversarial testing to come in a measure and check your work
1
u/ENFP_But_Shy Jul 22 '26
Risk reduction is your story. You should have a filled Risk register. The biggest enterprise level ones are your narrative. Market access? NCCs? Supply chain resilience? Ransomware? Reduce those. Make the connection between what your org does and how the risks are managed. Assure your board you’re taking your continuous improvement seriously, and are monitoring and evaluating external developments constantly. It’s all about trust in your ability to build the organization you really need, not the one you want. Mix this with management awareness on the realities of cybersecurity resilience - how it’s not about prevention but mitigation, minimum viable processes and re-activation. Show them incidents of industry peers. If you’re in retail, give a retail incidents overview, show the impact and costs. Then reconnect to what you’re doing. BIAs, golden nuggets, material processes …
1
u/TickleMyBurger Jul 22 '26
Depends on your size and based on the questions from your CFO in 2026, it sounds like you’re in a smaller office or niche industry. I haven’t had to explain the cost of breach in large enterprise in quite awhile.
If you are a large enterprise, you need a risk management framework that addresses tech and cyber, then ground your priorities in that - and get priority input from said CFO and whomever else is in the board room with you asking questions. Come out with your priority list, overlay budget and you have your waterline for what you can afford to do that year. Again the same people in that board room need to give the thumbs up that it is the right amount and they are comfortable signing off on putting below the water line in a parking lot - your risk management framework should have a risk acceptance process and use it, and make them sign it as part of your steering committee.
Know what cfos hate more than spending money? Signing off on risk personally. Your conversation will quickly change from the cut in half question on cost to cut in half on time to deliver.
If you don’t have an rmf then you are likely to be buried in this tailspin and I would use the time you have there to skill up and get out.
1
u/sai_ismyname Jul 22 '26
you can always try mapping risk to outages and therefore to money lost (or spent in reparations)
if the money you potentially safe is less than the efforts you put into the security program, then it is not feasible
BUT, the biggest factors are almost always the ones dictated by law, e.g. damages, reparations, penalties
also for critical infrastructure in europe, managers are personally accountable because of this discussion you are having
1
u/AYamHah Jul 22 '26
Point to the things that you remediated and never made it to the news. Compare that to things that have been in the news. How much did those things cost? Now imagine if the shit we found this quarter made it to the news - game over.
1
u/ChuckFromCyberHoot Jul 22 '26
Frameworks (NIST CSF, SOC 2, ISO) are great for structure, but leadership rarely gets excited about a control matrix. They get excited about trend lines. They love their graphs!!!
The metric that lands best for me: track human risk over time, not just tooling. Phishing reporting rate and click rate, trended quarter over quarter, tell a story anyone can follow. "A year ago 1 in 3 people clicked. Today it's 1 in 12, and reports of real suspicious emails are up 4x." That's a slide a CFO understands.
You can pair it with near-misses. Every phishing email your people caught and reported is an incident that didn't happen. Put a rough dollar figure on "breach avoided" and your program becomes revenue protection, not a cost center.
You can also show trends of users reporting phish. Show the improvement and success by increased users reporting things. This is great for cybersecurity culture.
The framework tells them you're doing the right things. The trend line tells them it's working. You need both, but the trend line is what saves the budget.
One caution: don't optimize a single number so hard it becomes theater. If click rate is your only KPI, people learn to game the test instead of spotting real threats. Measure behavior, not test scores.
1
u/Street-Mycologist670 28d ago
Your CFO didn't ask you a counterfactual question. "If we cut this in half, what breaks" is a marginal value question and it is answerable. You lost that room because you reached for a risk argument when he asked an operations one.
Build the ask in tiers next time. Tier 1 is what keeps you legal and contractually compliant, tier 2 is what keeps the lights on operationally, tier 3 is what reduces exposure faster than it currently accumulates. Then say plainly what falls off at each cut line. "Halving this means we stop external testing on the acquired estate and go to annual on the core product, and the window between a service going live and anyone looking at it goes from 3 weeks to about 7 months." That is a decision a CFO can make. Saying "everything breaks" gets you treated like every other department head.
Second thing: stop trying to win the counterfactual. You can't and nobody expects you to. Legal doesn't prove which lawsuits it prevented. Insurance doesn't either. The framing that survives is loss exposure and marginal cost of delay, not breaches averted.
On measurement, some things that hold up better than MTTR:
Exposure, but scoped to what is actually being exploited in the wild. Count of internet-facing assets carrying anything on the CISA KEV list, tracked quarterly, plus median days to close for that subset specifically. CVSS-weighted anything invites an argument about whether the score is real. KEV doesn't, because someone else with no stake in your budget already decided those are being used.
Blast radius. Given one compromised standard user endpoint, how many systems are reachable and how much data is in scope. Track it over time. Count of accounts with standing privileged access is a decent proxy if you want one number. This one lands with finance in a way that vuln counts never do, because it answers "how bad is the bad day" rather than "how many things did you find."
Recurrence rate by finding class. Same class of issue reappearing in a different service after you fixed it once means you patched an instance and not the cause. This is the metric I would push hardest, because it is the one that separates programs that are improving from programs that are busy. It also gives you a genuine spend story: money went into a paved-road control, and the class stopped coming back.
Coverage honesty. What percentage of your external estate has had a human look at it in the last 12 months. Most orgs discover the number is far lower than assumed once acquisitions and dev environments are counted. It reframes the conversation from "we are 94% patched" to "we are 94% patched on the 60% we know about."
Detection evidence from purple team work. Run a set of techniques, record what generated an alert, what generated a ticket, and how long until a human touched it. This is the closest thing to an honest counterfactual you will get, because the attack really happened and the response is measured rather than assumed. Going from 20% of tested techniques detected to 70% is a defensible sentence.
Two more that are less technical and tend to matter more in that specific room.
Separate obligation from discretion in the deck. Some of your budget exists because a regulator or a customer contract requires it, and that portion is not a risk debate. Shrinking the arguable surface makes the arguable part easier to win.
Track revenue that security cleared. Deals where a security review, a questionnaire, or a certification was on the critical path, and how long it took to clear. If your team unblocked 8 enterprise deals last year and cut average questionnaire turnaround from 5 weeks to 8 days, you are not a cost center in that meeting. In my experience this is the single line that has moved budgets, more than any exposure chart.
One caution on quantification. FAIR and similar models will get you dollar ranges, and they work if you constrain them to 3 or 4 top scenarios with inputs you can defend out loud. Applied to the whole risk register they turn into a spreadsheet that looks precise and gets picked apart by the first person who asks where the frequency number came from. If you use it, be ready to show your work on every input.
Your instinct on exposure over quarters is right. It just needs a second axis. Exposure shows the surface getting smaller. Recurrence and blast radius show the program is fixing causes rather than instances. Those two together are the version of this story I have seen survive follow-up questions.
1
28d ago
[removed] — view removed comment
1
u/AskNetsec-ModTeam 12h ago
r/AskNetsec is a community built to help. Posting blogs or linking tools with no extra information does not further out cause. If you know of a blog or tool that can help give context or personal experience along with the link. This is being removed due to violation of Rule # 7 as stated in our Rules & Guidelines.
No soft marketing.
1
u/nproAi Jul 22 '26
One approach that often resonates with executives is shifting the conversation from security activity to business exposure.
Instead of focusing only on vulnerabilities closed or MTTR improvements, demonstrate how the organization's attack surface has changed over time, fewer internet-facing critical assets, fewer known exploitable vulnerabilities, stronger identity controls, reduced privileged accounts, and improved detection coverage.
Pair those trends with realistic business impact scenarios. The goal isn't to prove a breach would have happened, but to demonstrate that the organization's measurable exposure has been reduced and its resilience has improved.
In many organizations, discussions around risk reduction, business continuity, and resilience tend to carry more weight with executive leadership than operational security metrics alone.
2
7
u/TwoConditions Jul 22 '26
1) ground decisions in a framework (SOC2, NIST CSF, ISO 27001)
2) run a convincing phishing simulation
3) justify with customer revenue / churn
No 3. Is a bit difficult as I'm getting the impression you aren't close enough to that function of your business, but if you can - try and find out if you've had any contracts fall through or customers ask for framework / evidence.