Every budget cycle, in some conference room, a security leader is losing an argument they were set up to lose. They walk in with a slide of threats — ransomware crews, nation-state actors, the breach that took a competitor offline last quarter — and they ask for more money to hold the line. The CFO nods, discounts the fear by whatever factor they discount fear, and funds the program flat. Not because they don't believe in the threats. Because fear is not a number they can put in a model, and everything else in the room is a number.
I've been on both sides of that table — building the ask, and watching better-funded functions win the same dollars with better stories. The pattern is consistent. The security budget is the one line on the operating plan defended with an emotion, and emotions depreciate. The threat that terrified everyone in January is background noise by June, and a budget built on it erodes on exactly that schedule.
There's a discipline that already solved this problem, and it isn't ours. It's insurance. An underwriter does not fund fear. They price expected loss, they price the cost of the controls that reduce it, and they charge the difference. That is the frame the security budget needs. Stop defending it like a line item someone might cut. Underwrite it like a loss you are choosing to buy down.
Price the exposure, don't invoke the fear
The first move is to convert the threats on your scary slide into a range of dollars, because a range of dollars is the only language the rest of the plan is written in. This is loss quantification, and the mature version of it is the FAIR model — Factor Analysis of Information Risk — which decomposes a risk into how often a loss event is likely to happen and how much it's likely to cost when it does. Loss event frequency times loss magnitude. Primary loss — your own response, recovery, downtime — plus secondary loss, the fines, the churn, the reputational tax that lands months later.
The point is not the arithmetic. The point is the shape of the answer. The crude ancestor of this is annualized loss expectancy — single loss expectancy times an annual rate of occurrence — and its fatal flaw is the false precision of point estimates. Nobody believes "$4.2M in expected annual loss," because nobody can defend the second decimal. FAIR's contribution is to replace the point estimate with a calibrated range and make the uncertainty explicit. "Somewhere between two and eleven million in annualized exposure from account-takeover fraud, most likely around five" is a sentence a CFO can actually reason about. It invites the right question — how much of that can we buy down, and for what — instead of the wrong one, which is whether you're exaggerating to protect your headcount.
The objection I hear is that these numbers are invented. They are estimates, and estimates feel like the opposite of the rigor security is supposed to bring. But calibrated estimation is a real discipline. You build the ranges from the data you do have — documented incidents in your sector, the frequency and cost figures the public threat reporting will actually support — and you widen the range to honestly reflect what you don't know. An honest wide range beats a confident wrong point every time, and a good CFO knows the difference. The other half of defensibility is co-ownership: build the model with finance, not at them. When the loss magnitudes carry your controller's own assumptions about downtime cost and customer churn, the exposure stops being "the security team's scary numbers" and becomes a shared figure the whole plan is measured against.
And the loss side has grown more legible, not less, which works in your favor. A material cybersecurity incident is now a disclosure event on a clock — the SEC's four-day rule under Item 1.05 turns a breach into a filing obligation and a market-facing number, not a private embarrassment you manage quietly. The ransomware scenario carries a sanctions dimension: OFAC's guidance is that facilitating a payment to a sanctioned actor can itself be a violation, so "we'll just pay it" is not the clean exit executives imagine. And in regulated finance — I run security in a fintech serving more than 1,500 financial institutions — the secondary loss includes examiner findings and the erosion of banking-partner trust that took years to build. Each of those is a real, citable component of loss magnitude. Put them in the model. They make the exposure larger and far harder to wave away.
A control is a loss-reduction instrument, not a wish
Once the exposure is priced, every line of your budget stops being a thing you want and becomes an instrument that buys down a specific, quantified loss. That reframing is the whole game, because it changes what a budget line has to prove. It no longer has to prove that security is important. It has to prove that this dollar reduces more expected loss than the same dollar spent somewhere else on the plan.
So build the ask the way an underwriter builds a book. For every control you're funding or renewing, be able to state four things:
- The exposure it touches. Which quantified loss scenario this control reduces — named, priced, and tied to the model, not to a framework checkbox.
- The marginal loss it buys down. How much the expected loss for that scenario falls with the control in place versus without it. Ranges are fine; direction and magnitude are what matter.
- The cost per unit of reduction. Loss reduced per dollar spent, so controls compete against each other honestly and the cheap, boring, high-leverage ones win the way they should.
- The external price signal. What your cyber-insurance carrier already thinks. Your premium and retention are a market underwriter's live opinion of your posture, and a control that measurably lowers either one is ROI that documents itself.
That last point is the one security leaders leave on the table. The cyber-insurance market has already done the exercise you're avoiding — it priced your controls. When a carrier drops your premium or your retention because you deployed phishing-resistant MFA and can show tested backups, you have an independent party putting a dollar value on the exact spend you're defending. Bring that number to the budget meeting. It turns "trust me" into "the market agrees with me."
Count the revenue the controls unlock, not only the losses they prevent
Loss avoidance is only half the underwriting, and it's the defensive half. The other half is that some of your security spend is not insurance at all. It's a revenue precondition, and it belongs in the growth column of the plan, not the cost column.
In any market built on trust — and regulated finance is the purest one — provable security is a gate the deal has to clear before it can close. The SOC 2 a buyer's vendor-risk team demands. The attestation that lets you into the enterprise segment at all. The diligence questionnaire you clear in three days instead of six weeks while a competitor is still drafting hedged prose. Those controls don't reduce a loss; they open a market. Attribute them that way. When a control is the reason a whole class of deals is even reachable, funding it is not an expense the CFO tolerates — it's an investment with a revenue line behind it, and it should be argued next to the other investments that carry one.
This is where a cost-transparency discipline earns its keep. Technology Business Management — TBM — exists to map technology spend to the business capability it enables, and the same taxonomy works on a security budget. Some of your spend maps to loss bought down. Some maps to revenue enabled. Present both columns. The CFO who sees a security budget split into "here is the annualized loss this buys down" and "here is the revenue this makes reachable" is looking at a plan, not a plea. The fear slide never gave them that, which is exactly why the fear slide never won.
Grow the envelope without growing the headcount
Here's the part that surprises people: once the budget is underwritten this way, growing it gets easier — and you can grow it without hiring a single new body. The CFO's objection was never to the dollars. It was to dollars that bought an unmeasured feeling. Dollars that buy a quantified reduction in a filing-worthy loss, or that unlock a reachable market, are dollars a rational CFO wants to spend more of, as long as each incremental one still clears the bar the last one cleared.
Headcount is usually the wrong lever anyway, and reaching for it first is how security budgets get capped. Three moves grow the program's effect without growing the org chart. Consolidate the overlapping tools — most security stacks carry two or three products doing one job, and retiring the redundancy frees dollars you redeploy against your highest exposure-per-dollar gap. Automate the toil so coverage per person climbs, instead of demanding another person for every unit of new coverage. And govern the leverage you already have: we built AgentOS, our internal agent platform, precisely so that capability could scale through a control plane rather than through linear hiring — the same posture that lets a small platform team hold guardrails across a large surface. Each of those is a story about buying more loss reduction with the same or fewer people, which is exactly the story a budget-conscious CFO is primed to fund.
I'm a security and platform leader reasoning toward how a CFO has to think, not a controller — so treat the accounting specifics as shape, not gospel. Where a given control lands as operating expense versus something capitalizable is a conversation for your finance team, not a claim to make from my seat. But the shape holds regardless of how it books: a budget defended as quantified loss reduction and revenue enablement grows on its merits. A budget defended as fear gets flat-funded and slowly starved, and the starving looks responsible right up until the loss it was quietly pricing actually arrives.
Underwrite it before the next cycle
So do the underwriter's work before you walk into the room. Price your top loss scenarios in ranges, not point estimates, and put the SEC clock, the OFAC exposure, and the examiner risk into the magnitude. Map every control line to the exposure it reduces and the revenue it unlocks, and let your insurance premium corroborate the ones it can. Grow the envelope through consolidation, automation, and leverage before you ever grow it through headcount. Lead with the number, not the nightmare.
If you've carried a security budget into a CFO or a board built on loss exposure instead of fear, I want to hear where the math held and where it broke — especially the loss magnitudes you couldn't defend and the revenue attribution finance pushed back on, because that seam is where this gets genuinely hard. Tell me in the comments.
