By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: ExpelPublished January 22, 2026

TL;DR: A collaboration paradox is emerging in security and finance: 74% of security leaders and 68% of finance leaders say they work together early and often, yet only 52% of finance leaders are very confident security can communicate business impact clearly, according to Expel. The gap is less about budget resistance than mismatched metrics, and it is resolved by translating security into risk, cost avoidance, and business outcomes.


At a glance

What this is: Expel’s survey argues that CISO-CFO friction is not mainly about disagreement on security value, but about using different decision frameworks and reporting metrics.

Why it matters: For IAM, NHI, PAM, and broader security teams, the lesson is that access governance and risk controls will be funded more reliably when they are tied to business impact, not just technical maturity.

By the numbers:

👉 Read Expel's research on the CISO-CFO disconnect and security investment alignment


Context

The security and finance divide is usually described as a budget problem, but the underlying issue is governance language. Security teams often present maturity, control coverage, and risk posture, while finance leaders need to see enterprise impact, avoided loss, and investment efficiency. That mismatch becomes especially visible in identity programmes, where IAM, PAM, NHI governance, and agentic AI controls are rarely translated into the financial terms executives use to prioritise capital.

Expel’s research shows that the collaboration problem is structural rather than personal. Regular meetings do not guarantee shared decision-making, and director-level conversations can mask the absence of true C-suite alignment. That pattern is common across identity and security programmes when teams can describe controls but cannot tie them to business resilience, audit outcomes, or operational savings.


Key questions

Q: How should finance and security teams justify identity governance investment?

A: They should tie identity governance to measurable business outcomes such as fewer audit exceptions, shorter remediation cycles, lower privileged-access risk, and reduced operational drag. The strongest case is not that identity is technically important, but that weak identity control creates financial loss through compliance work, disruption, and exposure. Link the programme to risk reduction and cost avoidance in the language the board already uses.

Q: Why do security and finance teams often think they are aligned when they are not?

A: Because frequency of meetings can hide the absence of shared decision-making. Teams may discuss cybersecurity regularly while still using different metrics, different time horizons, and different approval paths. That creates a collaboration paradox in which everyone agrees to cooperate, but no one is evaluating trade-offs in the same way.

Q: What do security teams get wrong when presenting cyber risk to executives?

A: They often lead with technical precision and end without a decision. A board does not need every detail of the finding first. It needs to know what can happen, how likely the path is, and what the organisation gains by acting now.

Q: Who should own security investment decisions in organisations with mature IAM and NHI programmes?

A: The decision should be shared by security, finance, and the business, but it must happen at C-suite level rather than through director-level proxy conversations. IAM and NHI programmes affect risk, operations, compliance, and productivity, so funding decisions should be tied to enterprise priorities, not just technical roadmaps.


Technical breakdown

Why reporting cadence is not the same as decision alignment

Frequent meetings can still leave organisations misaligned if the discussion happens below the level where spending decisions are made. In practice, quarterly or annual check-ins often produce status updates, not trade-off decisions. That is especially problematic for identity and access governance, where risk reduction depends on lifecycle discipline, privileged access constraints, and control exceptions that finance teams will not fund unless the business case is explicit.

Practical implication: move identity and security investment discussions to C-suite forums where risk, cost, and business priority can be decided together.

Why security maturity metrics do not satisfy finance

Security maturity scores, benchmark comparisons, and control counts are useful internally, but they rarely answer the question finance is asking: what loss does this prevent, and what value does it unlock? A control can be technically sound and still fail to earn priority if it cannot be expressed as avoided downtime, reduced manual work, or lower breach exposure. That is true for IAM too, especially where access review or secrets management is framed as hygiene instead of loss prevention.

Practical implication: convert maturity reporting into cost avoidance, audit-readiness, and operational efficiency metrics before budget review.

How access governance becomes a business-risk narrative

Identity controls become finance-relevant when they are linked to incident containment, audit outcomes, and productivity. For example, stronger privileged access management can reduce the blast radius of misuse, while better lifecycle governance can cut manual remediation work and audit exceptions. The control is still technical, but the decision to fund it is financial. That bridge matters more as organisations add NHI and agentic AI systems that expand the number of identities finance must indirectly underwrite.

Practical implication: map IAM, PAM, and NHI controls to avoided loss, audit time saved, and reduced manual intervention.


NHI Mgmt Group analysis

Translation, not persuasion, is the real security leadership skill: finance teams are not rejecting cyber risk, they are rejecting undefined risk language. When security teams talk about maturity without quantifying exposure, they force finance to infer value from abstract control narratives. That is a governance failure because budgets follow measurable business outcomes, not internal comfort. Practitioners should reframe security investment as decision support, not awareness raising.

Identity programmes need a financial model, not just a control model: IAM, PAM, NHI governance, and agentic AI oversight all create measurable reductions in breach likelihood, audit friction, and manual operations. The field still treats these as technical capabilities that happen to support compliance. In reality, they are enterprise risk controls whose value depends on how clearly they can be tied to loss avoidance and productivity gain. Practitioners should present identity as a capital allocation issue.

Collaboration paradox: regular meetings can coexist with deep organisational misalignment when the people in the room cannot make or approve the same trade-offs. That is the more useful concept here than simple communication breakdown. It explains why organisations can claim strong partnership while still failing to fund the right controls. Practitioners should inspect who actually participates in security investment decisions, not just how often the meetings occur.

Agentic AI and NHI adoption will intensify the CISO-CFO gap if identity risk stays untranslated: as machine identities and autonomous systems proliferate, the cost of weak governance shifts from a technical concern to a recurring operating expense. Finance leaders will increasingly ask why new identity classes are being added faster than the organisation can control them. Practitioners should expect funding scrutiny to rise unless identity risk is expressed in business terms.

What this signals

Decision quality will matter more than control volume: as boards and finance leaders demand clearer return on security spend, IAM and NHI teams will need to show how access controls reduce outage risk, audit effort, and manual remediation. That shifts identity governance from a technical programme to a business-performance function.

Least privilege becomes a budget language issue, not just an engineering principle: if privileged access, service account sprawl, and AI agent permissions cannot be translated into avoided loss and operational savings, they will be underfunded even when the technical risk is obvious. Practitioners should prepare reporting that ties identity scope directly to business exposure and productivity.

The challenge is not that finance is unsympathetic to cybersecurity. The challenge is that executive decisions require a shared metric model, and identity teams still too often report outputs instead of outcomes.


For practitioners

  • Recast security initiatives in avoided-loss terms Translate your top three security and identity initiatives into dollars of potential loss avoided, using downtime, fraud, audit effort, or breach containment as the basis for the estimate.
  • Bring the CFO into recurring strategic reviews Replace annual budget-only conversations with a standing monthly meeting focused on business context, investment trade-offs, and enterprise risk priorities.
  • Map IAM and PAM outcomes to business metrics Tie access governance, privileged access controls, and NHI lifecycle work to the business metrics your CFO already tracks, such as customer retention, operational efficiency, and audit readiness.
  • Retire maturity-only reporting for executive audiences Keep maturity scores for internal programme management, but lead executive reporting with quantified risk reduction, coverage, and time saved from manual review.

Key takeaways

  • The core problem is not hostility between security and finance, but a mismatch between control language and investment language.
  • Executive alignment improves when IAM, PAM, and NHI outcomes are expressed as avoided loss, audit efficiency, and operational resilience.
  • Security leaders who want better funding decisions need to change the reporting model before they change the meeting cadence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01Risk communication and prioritisation are central to the CISO-CFO alignment gap.
NIST SP 800-53 Rev 5PM-9Information system risk assessment and reporting need executive-readable metrics.
CIS Controls v8CIS-17 , Incident Response ManagementFinance wants quantified incident impact, which depends on response readiness.
ISO/IEC 27001:2022A.5.1Governance expectations require management direction and aligned security objectives.

Align security objectives with business goals and document decision ownership at the executive level.


Key terms

  • Collaboration paradox: A situation where two groups report frequent communication and cooperation but still fail to make aligned decisions. In security governance, it usually means meetings are happening, but the metrics, authority, and incentives driving those meetings are not shared.
  • Business impact reporting: The practice of expressing security outcomes in terms executives can use to allocate capital, manage risk, and compare investment options. It translates technical controls into avoided loss, productivity gain, audit readiness, or enterprise resilience.
  • Executive alignment: A state in which security, finance, and business leaders evaluate cyber risk using the same decision framework. It requires shared metrics, shared timing, and participation from people who can actually approve trade-offs.
  • Investment efficiency: A measure of how well a security control converts spend into risk reduction, coverage, or operational value. In practice, it is the bridge between technical programme planning and finance-led budget prioritisation.

What's in the full report

Expel's full report covers the survey detail this post intentionally leaves out for the source:

  • The full 300-response breakdown across security and finance decision-makers, useful if you need to compare executive perspectives by role.
  • The exact survey questions behind the collaboration paradox, which helps teams test whether their own reporting model is creating the same gap.
  • The complete set of finance-preferred metrics, including investment efficiency and audit readiness, for building your own executive dashboard.
  • The practical recommendations for monthly C-suite engagement and business-case translation, with more context than this analysis includes.

👉 Expel's full report includes the survey detail, metric preferences, and executive alignment recommendations.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security and identity practitioners translate identity risk into the operational decisions their programmes must support.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 20, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org