TL;DR: Cybersecurity budget conversations stall because security teams over-index on maturity reporting while finance leaders want strategic alignment, investment efficiency, and clearer business cases, according to Expel’s survey of 300 senior security and finance leaders. The core issue is not disagreement on risk, but translation failure, and that changes how practitioners should justify resilience spend.
NHIMG editorial — based on content published by Expel: The CISO-CFO disconnect: Why security and finance struggle to align on security investment
By the numbers:
- 54% of finance leaders say they need to see strategic alignment with enterprise goals.
- Only 24% of security leaders regularly engage with CFOs.
Questions worth separating out
Q: How should finance and security teams justify identity governance investment?
A: They should tie identity governance to measurable business outcomes such as fewer audit exceptions, shorter remediation cycles, lower privileged-access risk, and reduced operational drag.
Q: Why do security and finance teams disagree on cyber risk?
A: They often use different definitions of value.
Q: How can IAM leaders make access governance easier for executives to fund?
A: Show how access governance changes the business risk profile.
Practitioner guidance
- Build risk-to-budget narratives for identity controls Tie IAM, PAM, and NHI initiatives to probability of breach, expected loss, recovery cost, and continuity impact so finance can evaluate trade-offs in economic terms.
- Replace maturity reporting with decision metrics Report the three to five business outcomes each identity control affects, such as operational continuity, customer trust, and fraud loss reduction.
- Escalate identity funding cases to the CFO directly Present privileged access, secret lifecycle, and access review investments to the executive owner of capital allocation rather than stopping at director-level summaries.
What's in the full report
Expel's full report covers the operational detail this post intentionally leaves for the source:
- The exact survey framing and response breakdown from 300 senior security and finance professionals
- More detailed guidance on translating security outcomes into financial terms for budget conversations
- The report's full set of collaboration tactics for improving CISO-CFO alignment across the organisation
- Practical examples of how to connect cyber investment to business metrics such as continuity and customer trust
👉 Read Expel's research on the CISO-CFO disconnect and cybersecurity investment →
Security metrics and finance alignment: what is the real gap?
Explore further
Business translation is now a security control, not a presentation skill. Expel’s findings reinforce a pattern we see across identity programmes: teams often have the evidence but not the vocabulary to convert that evidence into budget authority. A control that cannot be tied to resilience, continuity, or avoided loss will struggle in board and finance discussions. For IAM leaders, the conclusion is straightforward: business translation must be treated as part of governance.
A question worth separating out:
Q: What should finance leaders ask when evaluating cybersecurity budgets?
A: They should ask which business outcomes the spend protects, how much loss it reduces, and what assumptions sit behind the estimate. The best security cases are not just technical descriptions; they are decision models that explain resilience, probability, and the cost of delay.
👉 Read our full editorial: CISO-CFO alignment fails when security metrics miss business value