You Approved the Budget. Can You Explain What It Protects?

Many of us have seen the following situation many times, but little has changed over the years.

You sit in the budget meeting. The security team presents the annual request. The numbers are significant. You ask a few questions, adjust the total slightly, and approve it.

Now for a different question. Not from the meeting. From me, right now.

What does that budget actually protect?

I am not looking for an answer in technical terms. Instead, I am looking for it in business terms and this may require a little more thinking to answer.

Which specific parts of your business would survive a serious attack, and which would not? Which revenue streams are covered? Which are exposed? What happens to your operations, your customers, and your regulatory standing if the wrong system fails at the wrong moment?

If you cannot answer those questions, you are not alone. In 40+ years of working with organizations across five continents, I have found this to be one of the most consistent patterns I have observed in business leadership. The budget gets approved. The outcome of the budget expenditure largely remains undefined.

This Is Not a Technology Problem

The cybersecurity industry has spent decades framing this problem as a technology challenge. Buy the right tools. Hire the right people. Pass the right audits. This has become the standard mantra. The vendors, the consultants, and the frameworks all point in the same direction: buy more technology, increase solution complexity, and spend more to gain this feature or this improvement. It has proven to be an extraordinarily profitable business model.

The problem is not the technology. The problem truly starts before technology is considered. The source of the problem is in the decision-making that precedes the technology.

Security spending not connected to specific business assets and specific business outcomes rarely if ever results in a strong, robust, manageable security program. It could be categorized as an expense with a hope attached.

The Conversation That Should Happen, and Rarely Does

Consider two versions of the same budget meeting.

Version one. The CISO requests $800,000 for enhanced monitoring. The CFO asks why. The CISO cites industry best practice and compliance requirements. The CFO asks whether $400,000 would do. The CISO says such a low investment would not be adequate. Nothing gets resolved.

Net Result. The CFO either approves the full amount without understanding it, cuts it without knowing what gets left unprotected, or delays the decision entirely.

That is not a security conversation. It is a haggling session.

Version two. The CISO requests $800,000 for enhanced monitoring that protects eight specific asset-outcome combinations. The CFO asks which ones. The CISO names them: customer transaction processing, payment data protection, production system availability, regulatory audit readiness. The CFO asks what gets left unprotected at $400,000. The CISO identifies the four combinations that would be uncovered, including customer breach detection and production availability. The CFO asks what the business impact of those gaps looks like in dollar terms. The CISO answers: regulatory exposure of $15 million and production disruption risk averaging $500,000 per month.

Net Result. The CFO approves $800,000 in under five minutes.

The difference between those two conversations is not the technology. It is the business clarity that preceded the technology decision.

The One Question That Changes Everything

There is really only one question that matters in cybersecurity. Everything else exists to make it answerable.

What are you protecting?

Until you can answer that question in specific business terms, every security decision that follows it is built on guesswork. Not bad guesswork necessarily, but guesswork (sometimes called estimates) nonetheless.

Your security team may be, and probably is, doing excellent technical work. The security controls in use may be well-designed. The monitoring may be thorough. But if no one has connected that work to the specific assets your business cannot afford to lose, you have no way to evaluate whether the spending is right, too much, or dangerously insufficient.

What Business-Driven Cybersecurity Looks Like

Business-Driven Cybersecurity starts where every good business decision starts. With a clear understanding of what matters most and what happens if you lose it.

It identifies the specific assets your business depends on for revenue, operations, regulatory standing, and competitive position. It defines the measurable outcomes your security program must deliver to protect those assets. It connects every dollar of security spending to a specific business result.

And it gives business leaders the language and the framework to hold that conversation with confidence, without ever needing to become cybersecurity experts.

If this describes a problem you recognize, I wrote the Governance Gap whitepaper specifically for you. It names the structural issue precisely and outlines what a business-driven approach looks like in practice. It is free and available now.

Download it at TorsettiLabs.com


Dr. Stuart Broderick is the founder of Torsetti Labs and the author of the Business-Driven Cybersecurity series. He has 40 years of practitioner experience across five continents.

Share:

More Posts

Send Us A Message