CISOs today face three high-stakes conversations that their current toolset was not built for. Defending a security budget in front of a CFO who evaluates every request in expected return per euro not maturity scores. Negotiating cyber insurance coverage when the policy was sized against sector benchmarks rather than the organisation's actual loss curve. And governing GenAI deployments when the risk surface is changing faster than any policy document can track.
In each case, the problem is the same: technical risk data that stops short of the financial translation the decision requires. A maturity score is not a return. A peer benchmark is not an exposure profile. A governance policy is not a risk estimate. The gap between what security teams produce and what business leaders need to act is the gap this series is designed to close.
What Christophe Forêt and Gerry Caroll covered:
- Why security budgets get cut and what specifically changes when the request is denominated in euros rather than maturity scores
- A step-by-step model you can apply to your own control investments
- A one-page budget defence format — three numbers, fully defensible — built to survive CFO scrutiny and procurement negotiation
- A real-world case reference: how a multi-country healthcare group got its full budget approved on first reading after adopting this approach
Key Points Discussed
- Translation gap, not CFO comprehension: The webinar argued that CISOs and CFOs often speak different “languages” and use different units of measure. CFO concerns are frequently about lack of financial returns that can be compared to other requests.
- Why current budget justification fails: Security proposals framed in terms such as maturity scores (e.g., DLP maturity or NIST CSF maturity progression) do not provide a direct financial “unit” for evaluation.
- Evidence and benchmarks: The speakers cited that many digital/security-related initiatives underperform expectations and that when returns are not quantified, it reduces trust in future requests. They also referenced organizations practicing strategic risk management as more likely to successfully defend security budgets.
- Model the right risk in euros (or comparable financial units): Once loss exposure is quantified in financial terms, security controls can be evaluated similarly to other capital allocations in the organization.
- A structured method to shift the conversation: The speakers outlined a repeatable approach to:
- assess current control performance by domain,
- quantify loss across scenarios in currency,
- rank candidate controls by risk removed per unit invested,
- invest in the highest return controls,
- continuously refresh the model (not just annually) as threats and controls evolve.
- Portfolio view for defense-in-depth: Instead of only choosing the “best ROI” control, the webinar described funding a portfolio that can cover both high-frequency/normal events and long-tail, worst-case scenarios, even if some layers yield different return profiles.
> Replay is available: here
.png)