Skip to main content

The Five-Line Cyber Security Budget Your CFO Will Actually Sign

Fourteen lines on a slide is fourteen things with no relationship to each other. Your CFO isn't cutting your budget. They're cutting the lines they can't classify. Here are the five that survive.

Christophe MazzolaChristophe Mazzola· Practicing CISO · Founder of Cyber Academy6 min read
The five-line cyber security budget: run, comply, reduce, capacity and the bad day

Fourteen lines on a slide. Licences, renewals, a pen test, two headcount, awareness training, a SIEM upgrade.

Your CFO looks at it for about eleven seconds.

"Which three would you drop?"

You don't have an answer. So they pick three.

And you have just told them something worse than any number on that slide. You have told them you have no priority order. Now they have one, built out of which words looked least essential to a person who does not work in security.

Your CFO is not cutting your budget. They are cutting the lines they cannot classify.

A CFO will sign two hundred thousand they understand before they sign forty thousand they do not. That is not hostility. That is the job description.

What the Five Lines Are

Not categories of spend. Categories of decision.

  • Run: what we already pay for
  • Comply: what we promised in writing
  • Reduce: the exposures we are buying down this year
  • Capacity: people, days, training
  • The bad day: what we need when it goes wrong

Four of those are not really negotiable, and saying so early is the whole point. It leaves one line to argue about, which is a meeting you can actually win.

Here is each one, and what kills it.

1. Run: What You Already Pay For

Licences, renewals, the managed service, the logging bill, certificate maintenance.

This is not a proposal. It is a renewal. Saying so in the first thirty seconds drains most of the argument before it starts, because nobody debates the electricity.

Tip: Every security budget has a line nobody can explain, usually a tool bought by someone who has since left. Find yours before your CFO does. Walking in having already killed something is the cheapest credibility you will ever buy, and it changes how the rest of the page is read.

2. Comply: What You Promised in Writing

What you committed to contractually, and what the law requires. The certificate. NIS 2. DORA. The security clause in the contract with your largest account.

Cutting here breaks something with a name attached, and finance reads contractual exposure far better than it reads technical exposure.

Tip: Name it. "Regulatory requirement" is invisible. "Clause 8.3 of the contract with our largest client, which renews in March" is not. One is a category. The other is a number your CFO can already picture.

3. Reduce: The Only Line Worth Arguing About

The two or three exposures you are buying down this year, with a figure against each.

This is the only genuinely discretionary line on the page. Which means this is where the conversation should happen, and nowhere else. If you have structured the other four properly, the entire meeting collapses onto this line by design.

The numbers come out of your risk register. Not out of your head, and not out of a vendor deck. If your register is a list of missing controls rather than scenarios with consequences attached, you have nothing to put here.

Tip: Test each entry by starting the sentence with "the risk that". If it still makes sense, it belongs in line three. "No MFA" fails that test. It is a gap, not an exposure, and it will not survive a CFO asking what it costs you.

4. Capacity: The First Cut and the Most Expensive

People. External days. Training.

First cut, hardest to defend, because the cost of not having it shows up as slow rather than as broken. Nobody ever writes an incident report about a team that was too thin to get to the work.

Tip: Attach capacity to something with a date on it. "Two hundred days of external support" dies in the room. "Enough external support to close the internal audit programme before the surveillance visit" survives, because it is now protecting an outcome your CFO already knows exists.

5. The Bad Day: The Line Finance Understands Best

Incident response retainer. Forensics on standby. Legal counsel who already knows your environment.

Finance is where the emergency invoice lands, so this is the line they read fastest. The comparison writes itself: the cost of the retainer, against the cost of buying the same capability at two in the morning during an incident, with no negotiating position and no time to run procurement.

Small, concrete, easy to say yes to. It also moves the register of the whole conversation from spending to insurance, which is a language finance already speaks fluently.

6. Rules for the Room

Bring your own cut. Walk in with the five lines and a second version at sixty percent, and say plainly what the sixty percent version stops doing. You will not be asked to justify your budget in that meeting. You will be asked which version to take, which is a different conversation and one you are now leading.

Every line answers "what if it is zero". If you cannot say what breaks, the line is already dead. Kill it yourself, before the meeting, and count it as a win.

One number per line. Five numbers. Not a spreadsheet. If they want the detail they will ask, and then you are answering a question instead of defending a document. Those feel very different from the other side of the table.

Name the business owner of every reduction. Not you. The person who owns the process you are protecting. A line with an operations director behind it stops being a security cost and becomes a business cost that security happens to manage.

Never say "best practice". Your CFO hears "no business case". Same for "industry standard" and "the auditors expect it". Both are true. Neither is an argument.

You are not competing with no. You are competing with two more salespeople. That is the actual comparison being made in the room, so make it yourself: two sales hires against the thing that stops you losing the account you already have. Finance can price that. Finance cannot price a threat landscape.

Anecdote: The most useful budget meeting I have ever had lasted four minutes. I opened with line one and said we were switching off a tool we had paid for since 2021 that nobody could tie to a decision. Everything after that was read as a serious document rather than a wish list, and line three went through without a question. I have never got more out of giving money back.

7. If They Cut Line Three, Write It Down

They might. It is the discretionary line, and discretionary is exactly what the word means. That is a legitimate business decision and it belongs to them.

It is also a risk acceptance.

So it goes in the register. Dated, described, with their name on it. Not as a threat and not as revenge, but because that is what ISO/IEC 27001 Clause 6.1.3 says happens when a risk owner decides to live with something. Your CFO is a risk owner whether or not anybody has used the phrase in front of them.

Two things change the moment you do that.

The decision stops being a budget line and becomes a governance record, which means it appears in the management review and in front of your auditor. And next year, when the same exposure is still on the page, the conversation starts from a decision they made rather than a request you are repeating.

Those two meetings go very differently.

Tip: Send the register entry the same week, in two sentences, with the acceptance date and a review date. Not a memo, not a warning. A record. If it needs a covering note explaining why you are sending it, you have written it wrong.

Final Thought

Most security budgets fail because they are a shopping list defended by the person who wants to do the shopping. Five lines, each with an owner, is a governance document that happens to have numbers in it.

Same content. Completely different meeting.

"Which three would you drop?"

With fourteen lines, that question ends the conversation. With five, it starts one.

Everything above is CISM Domain 1. Building the business case, aligning security spend with what the organisation is actually trying to do, and reporting to people who do not work in security. Domain 2 is where the numbers in line three come from. If you want to run these conversations from a framework rather than from instinct, that is what we teach in the **CISM: Certified Information Security Manager**. Four days, ISACA accredited, all four domains and the exam. Certified or refunded.

Want the next field note in your inbox?

The GRC Brief newsletter. Five links and one short take, every Monday at 8am CET. Three-minute read.

The Five-Line Cyber Security Budget Your CFO Will Actually Sign · Cyber Academy