TL;DR: A collaboration paradox is emerging in security and finance: 74% of security leaders and 68% of finance leaders say they work together early and often, yet only 52% of finance leaders are very confident security can communicate business impact clearly, according to Expel. The gap is less about budget resistance than mismatched metrics, and it is resolved by translating security into risk, cost avoidance, and business outcomes.
NHIMG editorial — based on content published by Expel: The CISO-CFO disconnect: Why security and finance struggle to align on security investment
By the numbers:
- Expel’s survey of 300 senior-level security and financial professionals found that 74% of security leaders say they collaborate with finance early and often on cybersecurity matters.
- Only 52% of finance leaders are very confident that security can communicate business impact clearly, despite the reported collaboration.
- Just 24% of security leaders regularly collaborate with their CFO, showing that executive-level coordination remains thin.
Questions worth separating out
Q: How should finance and security teams justify identity governance investment?
A: They should tie identity governance to measurable business outcomes such as fewer audit exceptions, shorter remediation cycles, lower privileged-access risk, and reduced operational drag.
Q: Why do security and finance teams often think they are aligned when they are not?
A: Because frequency of meetings can hide the absence of shared decision-making.
Q: What do security teams get wrong when presenting cyber risk to executives?
A: They often lead with technical precision and end without a decision.
Practitioner guidance
- Recast security initiatives in avoided-loss terms Translate your top three security and identity initiatives into dollars of potential loss avoided, using downtime, fraud, audit effort, or breach containment as the basis for the estimate.
- Bring the CFO into recurring strategic reviews Replace annual budget-only conversations with a standing monthly meeting focused on business context, investment trade-offs, and enterprise risk priorities.
- Map IAM and PAM outcomes to business metrics Tie access governance, privileged access controls, and NHI lifecycle work to the business metrics your CFO already tracks, such as customer retention, operational efficiency, and audit readiness.
What's in the full report
Expel's full report covers the survey detail this post intentionally leaves out for the source:
- The full 300-response breakdown across security and finance decision-makers, useful if you need to compare executive perspectives by role.
- The exact survey questions behind the collaboration paradox, which helps teams test whether their own reporting model is creating the same gap.
- The complete set of finance-preferred metrics, including investment efficiency and audit readiness, for building your own executive dashboard.
- The practical recommendations for monthly C-suite engagement and business-case translation, with more context than this analysis includes.
👉 Read Expel's research on the CISO-CFO disconnect and security investment alignment →
CISO-CFO alignment: are security metrics speaking finance's language?
Explore further