TL;DR: Security teams often report maturity and operational metrics that finance leaders cannot use to make investment decisions, according to Expel’s webinar and survey of 300 security and finance leaders. The real gap is translation: cybersecurity ROI has to be framed as risk reduction, business enablement, and balance-sheet impact, not technical progress alone.
NHIMG editorial — based on content published by Expel: A CISO’s guide to speaking CFO
By the numbers:
- Our research found that CISOs who engage directly with CFOs report 63% higher alignment versus the overall average of 46%.
- The article is based on research surveying 300 security and finance leaders about working dynamics.
Questions worth separating out
Q: How should security teams measure cybersecurity ROI in a way boards will trust?
A: Use outcome-based measures that connect security controls to reduced loss.
Q: Why do maturity scores often fail to persuade CFOs?
A: Maturity scores describe programme progress, but CFOs need to know what risk is being reduced and what business outcome is being protected.
Q: How should IAM teams prove business value to executives?
A: Focus on measurable outcomes such as reduced standing privilege, fewer audit exceptions, faster application onboarding, and lower manual review effort.
Practitioner guidance
- Recast maturity metrics as financial risk statements Convert internal security scores into statements about expected loss reduction, regulatory exposure, or business continuity impact so finance can compare them with other investments.
- Tie identity controls to business initiatives Link IAM, PAM, and NHI controls directly to product launches, customer-facing applications, or regulated workflows so budget owners see the operational dependency.
- Build a two-layer reporting model Keep operational metrics for the security team, but add an executive layer that explains what those metrics mean for cost, coverage, and downside risk.
What's in the full article
Expel's full webinar and research write-up covers the operational detail this post intentionally leaves for the source:
- The survey instrument and response breakdown from 300 security and finance leaders, useful if you need to validate the sample behind the findings.
- The discussion format and speaker perspective from the Expel and non-Expel panel, which provides more nuance than the summary can capture.
- The specific phrasing security teams can use when translating controls into CFO-ready risk and ROI language.
- The next installment in the series, which expands on why strong security is often judged by business impact rather than technical maturity.
👉 Read Expel's analysis of cybersecurity ROI and the CISO-CFO communication gap →
Cybersecurity ROI and maturity metrics: what finance teams actually need?
Explore further
Maturity reporting is a governance signal, not an investment case. Security programmes often confuse internal progress tracking with external decision support. A maturity score can show that a control framework is becoming more consistent, but it does not explain what financial exposure is being reduced or what business initiative is being enabled. That is why CFOs can dismiss technically accurate reporting as irrelevant. Practitioners should treat maturity as an internal control health indicator, not as proof of value.
A few things that frame the scale:
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time, according to Ultimate Guide to NHIs.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.
A question worth separating out:
Q: What should organisations do when security and finance disagree on priorities?
A: Use a shared risk language and test it in planning sessions, not just during budget season. Put finance leaders into incident or tabletop exercises so they see how access, containment, and recovery decisions affect cost and timing. Once they experience the trade-offs, security priorities are easier to justify as business decisions rather than technical preferences.
👉 Read our full editorial: Cybersecurity ROI fails when security metrics miss CFO decisions