Finance and security leaders are odds over cyber priorities, and it’s harming enterprises
Poor relations between the departments can be solved by CISOs talking in a language CFOs understand
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
Finance leaders have a poor opinion of the performance of CISOs, believing that they can't always communicate clearly and aren't fully aligned with business needs.
A new survey of 300 CISOs, directors of cybersecurity, CFOs, and finance leaders by threat-hunting firm Expel found less than half (46%) of security leaders think their finance counterparts are highly aligned with the security team’s priorities.
Finance leaders, though, are less convinced, with only 35% believing that their security counterparts are highly aligned with the finance team’s priorities.
These conflicting perceptions on both sides of the divide further exacerbate existing issues with alignment, the study noted.
Crucially, there's a similar pattern when it comes to risk tolerance and budget expectations. While 71% of surveyed security leaders say that security and finance teams are fully or very aligned, finance decision-makers are much less positive, with only 58% saying the same.
"While most finance decision-makers see security as business-critical, they demonstrate a lower level of assurance in some of their security teams’ abilities," the researchers said.
Only half of surveyed finance leaders said they were very confident that their security team can communicate business impact clearly or protect the organization from major cyber events, while only four-in-ten express full confidence in security’s ability to align with business strategy.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Security decision-makers, meanwhile, are suspicious that they're perceived negatively by finance, with 36% saying they're seen as a cost center and 35% as no more than an operational necessity.
"The real issue isn't that finance sees security as a cost center — it's that too many security leaders haven't learned to articulate value in terms finance understands," said Greg Notch, Expel chief security officer.
"Security leaders should spend their time showing how that cost translates to business protection. Finance teams make cost-benefit decisions all day long. They're not afraid of costs; they're afraid of costs they can't quantify or understand."
How cyber leaders can shake up communication
When reporting results to finance, surveyed security leaders typically prioritize metrics like business impact of actual security incidents at 18%, cost of control versus potential losses at 17%, security program maturity level at 16%, and risk reduction score at 15%.
However, researchers found these metrics don't align with what finance actually requires for making strategic decisions. In fact, program maturity level versus industry benchmarks is the second least popular metric among finance leaders.
"Instead of falling back on maturity metrics, leaders need to communicate in the language of risk, especially when justifying security spend," advised Notch.
The calculation, he said, means taking the percentage - or percentage range - of likelihood that the organization will experience a breach, and the cost of that breach.
From there, you can determine that an investment that costs $x will likely lower your percentage likelihood of breach by x%.
"Cybersecurity teams have to understand the KPIs that matter to the business and how their operations ladder up into those," he said.
"It’s all about cybersecurity teams being able to communicate how their impact is contributing to those KPIs in the language of the business — which is all about dollars and cents."
FOLLOW US ON SOCIAL MEDIA
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Salesforce targets telco gains with new agentic AI toolsNews Telecoms operators can draw on an array of pre-built agents to automate and streamline tasks
-
Four national compute resources launched for cutting-edge science and researchNews The new national compute centers will receive a total of £76 million in funding
-
UK Government says it’s ‘cut cyber attack fix times by 84%’ with new vulnerability monitoring serviceNews A new scanning service spots weaknesses in government DNS records for 6,000 UK public sector bodies
-
Nationwide forges closer ties with AWS in cloud transformation pushNews The building society is “consolidating and modernizing” cloud infrastructure and focusing heavily on internal skills development
-
Productivity gains on the menu as CFOs target bullish tech spending in 2026News Findings from Deloitte’s Q4 CFO Survey show 59% of firms have now changed their tune on the potential performance improvements unlocked by AI.
-
ServiceNow to acquire Veza in major identity security playNews Veza’s AI-native identity security platform will be integrated into ServiceNow’s AI Control Tower to strengthen its identity and access controls
-
Pax8 and Microsoft are teaming up to supercharge MSP growthNews The new agreement includes integration between Pax8 and Microsoft Marketplace alongside a new OneCloud Guided Growth enablement initiative
-
Cyber Security and Resilience Bill: Security experts question practicality, scope of new legislationNews The new legislation aims to shore up critical infrastructure defenses, but questions remain over compliance and scope
-
How AI is reshaping the role of spreadsheets in accountingIndustry insights Modernizing spreadsheets can enable secure and AI-ready accounting and finance functions
-
Implementation and atychiphobia: helping SMEs overcome fearIndustry Insights Fear of failure stalls SME system upgrades, but resellers can calm concerns and build confidence
