TL;DR: Cybersecurity budget conversations stall because security teams over-index on maturity reporting while finance leaders want strategic alignment, investment efficiency, and clearer business cases, according to Expel’s survey of 300 senior security and finance leaders. The core issue is not disagreement on risk, but translation failure, and that changes how practitioners should justify resilience spend.
At a glance
What this is: This is Expel’s survey-based analysis of why security and finance leaders struggle to align on cybersecurity investment, with the key finding that security metrics often do not match finance’s decision criteria.
Why it matters: It matters to IAM practitioners because identity, NHI, PAM, and access governance programmes increasingly compete for budget on business value, risk reduction, and resilience rather than technical completeness alone.
By the numbers:
- Expel surveyed 300 senior-level security and finance professionals to understand where cybersecurity investment conversations break down.
- 54% of finance leaders say they need to see strategic alignment with enterprise goals.
- 50% of finance leaders want investment efficiency metrics rather than maturity scores.
- Only 24% of security leaders regularly engage with CFOs.
👉 Read Expel's research on the CISO-CFO disconnect and cybersecurity investment
Context
Security investment often stalls when technical teams describe progress in maturity terms while finance leaders need clear business outcomes, cost exposure, and decision-grade evidence. In identity programmes this gap is especially visible because IAM, PAM, and NHI controls are frequently justified as hygiene, even when they directly affect resilience, operational continuity, and fraud exposure.
The article argues that the problem is not a lack of shared intent but a failure to translate risk into the language of budget decisions. That is relevant to identity governance because access control, credential lifecycle, and privileged access are among the few cyber domains where weak control can be tied directly to measurable business disruption.
Key questions
Q: How should finance and security teams justify identity governance investment?
A: They should tie identity governance to measurable business outcomes such as fewer audit exceptions, shorter remediation cycles, lower privileged-access risk, and reduced operational drag. The strongest case is not that identity is technically important, but that weak identity control creates financial loss through compliance work, disruption, and exposure. Link the programme to risk reduction and cost avoidance in the language the board already uses.
Q: Why do security and finance teams disagree on cyber risk?
A: They often use different definitions of value. Security teams may focus on control maturity, while finance teams care about strategic alignment, cost efficiency, and the financial effect of disruption. The result is not usually disagreement about whether risk exists, but disagreement about how to express it in a way that supports funding.
Q: How can IAM leaders make access governance easier for executives to fund?
A: Show how access governance changes the business risk profile. Connect privileged access, lifecycle control, and credential hygiene to continuity, fraud prevention, and recovery effort. If executives can see which losses are reduced and which operations stay online, funding decisions become much easier to defend.
Q: What should finance leaders ask when evaluating cybersecurity budgets?
A: They should ask which business outcomes the spend protects, how much loss it reduces, and what assumptions sit behind the estimate. The best security cases are not just technical descriptions; they are decision models that explain resilience, probability, and the cost of delay.
Technical breakdown
Why maturity metrics fail in budget conversations
Maturity metrics measure whether a programme has adopted certain controls, but they do not explain how those controls change loss exposure. Finance leaders typically need directional answers about probability, impact, and efficiency, not a scorecard that stops at implementation status. In identity security, a completed control can still be misaligned if it does not reduce breach likelihood, access misuse, or operational drag in a way the business can quantify.
Practical implication: map IAM and NHI controls to risk reduction and cost avoidance, not just control adoption.
How finance frames cyber risk differently
CFOs usually treat risk as an economic question, not a technical one. They need to understand which outcomes matter most, what the downside looks like, and how much uncertainty remains after a control is funded. For identity teams, that means translating account compromise, standing privilege, and offboarding gaps into business interruption, fraud loss, or recovery effort instead of relying on purely technical language.
Practical implication: express identity risk in business-impact terms that connect directly to budget decisions.
Why direct executive engagement changes the outcome
The article shows that collaboration improves when security leaders engage CFOs directly rather than relying on intermediary finance directors. That matters because budget decisions are made by the people who own enterprise trade-offs, not by the people who receive translated summaries. For IAM and PAM leaders, the same logic applies when asking for funding for lifecycle governance, privileged access, or NHI controls.
Practical implication: take identity investment cases to executive decision-makers with clear trade-offs and outcome measures.
NHI Mgmt Group analysis
Business translation is now a security control, not a presentation skill. Expel’s findings reinforce a pattern we see across identity programmes: teams often have the evidence but not the vocabulary to convert that evidence into budget authority. A control that cannot be tied to resilience, continuity, or avoided loss will struggle in board and finance discussions. For IAM leaders, the conclusion is straightforward: business translation must be treated as part of governance.
Identity programmes fail politically before they fail technically. IAM, PAM, and NHI controls are often well understood by specialists but under-explained to finance because they are framed as technical hygiene. That framing weakens investment cases even when the controls directly reduce exposure from privilege misuse, orphaned access, or credential abuse. Practitioners should assume that technical correctness alone will not secure funding.
Standing access and unmanaged identity sprawl are budget problems as much as security problems. When organisations cannot show how access governance reduces operational loss, they tend to underfund the controls that matter most. This is where NHI governance intersects with executive alignment: unrotated credentials, over-privilege, and poor lifecycle control create risk that finance can understand as avoidable downtime and recoverable loss. The practical conclusion is to present identity governance as resilience engineering.
The named concept here is security-value translation: the ability to express cyber risk in the business terms executives actually fund. Expel’s survey suggests this is the missing layer between control design and capital allocation. Without it, even strong programmes can be perceived as overhead. Practitioners should build repeatable risk-to-revenue, risk-to-continuity, and risk-to-cost models for identity investment decisions.
For identity leaders, the CFO is not a stakeholder downstream of the story. The CFO is part of the control environment. If access governance affects loss exposure, recovery time, or customer trust, then the funding conversation belongs at the same level as the risk conversation. That makes identity governance a cross-functional discipline rather than a back-office security process. The lesson is to present identity controls as enterprise safeguards, not technical line items.
What this signals
Security teams are moving into a funding environment where technical completeness is no longer enough. The winning case will be the one that can show how identity controls reduce operational loss, shorten recovery, and protect revenue continuity, which is why access governance must be framed alongside business resilience rather than as a standalone hygiene programme.
Security-value translation: the next maturity gap is not missing controls, but missing economic language. Identity leaders who can quantify the impact of privileged access, credential sprawl, and lifecycle failures will have a clearer path to budget support, especially as boards demand evidence that cyber spend changes enterprise outcomes.
For teams dealing with AI agents and machine identities, the translation problem gets sharper because governance gaps scale quickly. The 2026 Infrastructure Identity Survey found that only 44% of organisations have policies for AI agents, even though 92% say governance is critical, which suggests the market is still struggling to turn recognition into funded action.
For practitioners
- Build risk-to-budget narratives for identity controls Tie IAM, PAM, and NHI initiatives to probability of breach, expected loss, recovery cost, and continuity impact so finance can evaluate trade-offs in economic terms.
- Replace maturity reporting with decision metrics Report the three to five business outcomes each identity control affects, such as operational continuity, customer trust, and fraud loss reduction.
- Escalate identity funding cases to the CFO directly Present privileged access, secret lifecycle, and access review investments to the executive owner of capital allocation rather than stopping at director-level summaries.
- Quantify the cost of unmanaged identity sprawl Estimate the business impact of orphaned access, stale credentials, and over-privilege so the finance team can see the cost of inaction.
Key takeaways
- Security leaders lose budget influence when they report maturity instead of business impact.
- Finance teams want alignment, efficiency, and continuity, not technical scorecards.
- Identity governance gets funded faster when it is presented as resilience engineering with measurable loss reduction.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 | Security-finance alignment affects governance and oversight of cyber investment. |
| NIST SP 800-53 Rev 5 | PM-3 | Programme management supports business-case based security investment decisions. |
| ISO/IEC 27001:2022 | A.5.4 | Management responsibilities matter when security funding crosses into finance decisions. |
Tie identity programme funding to governance outcomes and board-level risk oversight.
Key terms
- Security-value translation: The practice of expressing cybersecurity outcomes in business terms that decision-makers can fund and compare. It connects control performance to risk reduction, continuity, customer trust, and cost avoidance so security investment can be evaluated as an enterprise decision rather than a technical preference.
- Business Resilience: The ability of an organisation to continue operating and recover quickly after disruption. In identity security, it means framing access controls in terms of reduced downtime, lower breach cost, and stronger continuity under adverse conditions.
- Access Governance: Access governance is the policy and workflow layer that manages how access is requested, approved, certified, and revoked. In SaaS environments it helps standardise control across many applications, reducing inconsistency between teams. It is most effective when it covers both human accounts and non-human identities.
What's in the full report
Expel's full report covers the operational detail this post intentionally leaves for the source:
- The exact survey framing and response breakdown from 300 senior security and finance professionals
- More detailed guidance on translating security outcomes into financial terms for budget conversations
- The report's full set of collaboration tactics for improving CISO-CFO alignment across the organisation
- Practical examples of how to connect cyber investment to business metrics such as continuity and customer trust
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, secrets management, and access control patterns that matter to identity programmes. It is designed for practitioners who need to connect identity decisions to operational and governance outcomes.
Published by the NHIMG editorial team on August 20, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org