How can you justify cybersecurity to the finance department?

An investment in cybersecurity is justified by comparing the expected financial loss before and after the control is implemented. The business case must explain the scenario, probability, impact, total cost, risk reduction, residual risk, and metrics. The finance department does not need any more technical alerts; it needs to decide how much capital to allocate, which exposures to reduce, and which risks to accept.

Taxonomic Definitions

  • Inherent risk. Exposure that exists before additional controls are implemented. It combines the estimated frequency of the event and the magnitude of the resulting loss to revenue, operations, data, customers, obligations, and reputation.
  • Residual risk. Exposure that remains after controls have been implemented. No investment completely eliminates risk; the financial decision involves determining whether the residual level falls within the approved risk appetite and tolerance.
  • Expected annual loss. A financial estimate of the average annual impact of a risk scenario. It is calculated using ranges of frequency and magnitude, not as an exact prediction:

Expected annual loss = estimated annual frequency × loss magnitude

Weak technical proposalFinance-Oriented Business Case
“We need a new security platform”“We need to reduce the annual exposure to the identity compromise scenario”
Contains a number of vulnerabilitiesIt presents the assets, processes, revenues, and obligations listed
Use only CVSS severity scoresCombines probability, financial impact, and business criticality
Report License CostsReports on TCO related to implementation, operation, personnel, and adoption
He promises to stop all attacksEstimates a reduction in frequency, impact, and residual risk
Use a single impact valueIt presents best-case, likely, and worst-case scenarios
He talks about compliance as an absolute argumentQuantify fines, the cost of evidence, and the probability of noncompliance
Track activitiesMeasures reduction in expected losses and operational improvement
Request a quote with no alternativesCompare accepting, mitigating, transferring, or avoiding risk
Shows fearPresent a well-reasoned investment decision

Why the finance department rejects some projects

Cybersecurity competes for funding with expansion, productivity, automation, maintenance, hiring, and debt reduction. The technical importance of the project does not guarantee its approval.

The Finance Department needs to respond:

  • What event are they trying to prevent?
  • What process and income are disclosed?
  • What is the likely loss?
  • How often can this happen?
  • To what extent does the investment reduce risk?
  • What is the total cost over its service life?
  • What alternatives are there?
  • When will evidence of the result be available?
  • What level of risk will the organization continue to accept?

NIST IR 8286 Rev. 1 states that cybersecurity information must be integrated into Enterprise Risk Management so that management can understand the risk posture and technical decision-makers can make decisions that take business objectives into account.

The problem is not usually that the finance department considers cybersecurity unnecessary. The problem is that the project is presented in terms of alerts, controls, or maturity, while decisions are made based on exposure, liquidity, margin, compliance, and capital priorities.

Step 1: Define the loss scenario

A business case should begin with a sentence that links the threat, the asset, and the consequence.

Recommended Structure

Due to [threat], there is a possibility that [asset or process] could be compromised, resulting in [operational and financial impact] during [period], with consequences for [business objectives].

Example:

Due to the compromise of privileged credentials, there is a risk that an attacker could disrupt the ordering platform, resulting in lost sales, extraordinary recovery efforts, contractual breaches, and negative impacts on customers.

Scenarios that can be quantified

  • Ransomware that disrupts production.
  • Identity compromise involving access to sensitive information.
  • Fraud via corporate email.
  • Exploitation of a Vulnerable Application.
  • Intellectual Property Leak.
  • Outage at a cloud provider.
  • Third-Party Commitment.
  • Breach of Data Protection Obligations.
  • Attacks on terminals, point-of-sale systems, or devices.
  • Unauthorized use of artificial intelligence.
  • Commitment to OT Environments.
  • Loss of availability of a critical platform.

We should not construct a single scenario labeled “cyberattack.” Its causes, impacts, and controls are too diverse to yield a useful estimate.

Step 2: Quantify the financial exposure

Calculate the frequency

The frequency can be estimated using:

  • Internal incidents.
  • Confirmed attempts.
  • Exploitable vulnerabilities.
  • Internet exposure.
  • Number of privileged identities.
  • Industry History.
  • Events recorded by third parties.
  • Changes to the architecture.
  • Dependence on suppliers.
  • Actual effectiveness of controls.
  • Structured expert opinion.

The result must be expressed as a range:

  • Once every ten years.
  • Between 0.1 and 0.3 events per year.
  • Annual probability of between 10% and 25%.

The volume of attempts should not be confused with the frequency of losses. Millions of alerts do not mean millions of incidents with financial impact.

Calculate the magnitude

The loss must be broken down into components to avoid double counting.

Operating losses

  • Unrealized contribution margin.
  • Production halted.
  • Unprocessed orders.
  • Rejected transactions.
  • SLA Penalties.
  • Unproductive hours.
  • Manual operation.
  • Loss of inventory or product.

Response and Recovery

  • Forensic scientist.
  • Containment.
  • Restoration.
  • External services.
  • Overtime.
  • Equipment Replacement.
  • Reconfiguration of access points.
  • Crisis Communication.

Impact on Customers

  • Compensation.
  • Cancellations.
  • Discounts.
  • Loss of renewal.
  • Higher purchase price.
  • Exceptional service.
  • Litigation.

Compliance and Third Parties

  • Legal advice.
  • Notifications.
  • Audits.
  • Penalties.
  • Breaches of contract.
  • Additional evidence.
  • Claims from business partners.

Break down EBITDA, cash, and total exposure

Not all costs associated with an incident have the same impact on the financial statements. The business case must distinguish between:

  • Impact on EBITDA: loss of margin, unproductive hours, overtime, and operating costs.
  • Impact on cash flow: immediate disbursements, advance payments to suppliers, recoveries, and compensation.
  • Accounting impact: impairment charges, provisions, and classification of nonrecurring expenses.
  • Financial exposure: loss of customers, reputation, intellectual property, and future opportunities.

Presenting the entire impact as a direct effect on EBITDA undermines the credibility of the proposal.

Step 3: Establish a baseline using internal and external data

Benchmarks do not replace internal calculations, but they help verify that the scenario is not merely theoretical.

IBM reported that the average cost of a data breach in Latin America was US$2.51 million in 2025. The average time to identify and contain a breach was 316 days. Incidents resolved in less than 200 days cost, on average, US$2.21 million, compared to US$2.82 million when they took longer than that period—a difference of US$610,000.

In the same regional study:

  • Organizations with AI-powered security and automation reported savings of up to $900,000.
  • The lifecycle of data breaches was reduced to 111 days compared to organizations that did not use these capabilities.
  • Phishing was the most common and costly initial attack vector in the region, with an average cost of US$2.87 million.
  • Data breaches across multiple technology environments cost an average of US$2.84 million.

Globally, IBM reported an average cost of US$4.44 million in 2025. Organizations that made extensive use of AI and automation in security saved an average of US$1.9 million and reduced the breach lifecycle by 80 days.

Local Evidence for Mexico

The Bank of Mexico published four cyber incidents reported by financial institutions in 2024. The reported impacts on these institutions were:

  • 101.36 million MXN.
  • 16.38 million MXN.
  • 161.99 million MXN.
  • 204.12 million MXN.

The total amounts to MXN 483.85 million. The document clarifies that the figures were provided by the institutions and may be updated as the investigations progress.

These figures should not be used as a default cost estimate for any company. They serve to demonstrate that cyber losses are already appearing in local financial and regulatory reports, not just in international studies.

Step 4: Calculate the risk before and after the check

Inherent risk. Inherent risk = frequency before control × estimated loss before control

Residual risk. Residual risk = frequency after control × estimated loss after control

Some controls reduce the frequency:

  • Phishing-resistant MFA.
  • Vulnerability Management.
  • Segmentation.
  • Hardening.
  • Email Security.
  • Third-Party Management.

Others mainly reduce the magnitude:

  • Immutable backups.
  • Disaster Recovery.
  • Detection and response.
  • Automated containment.
  • Contingency Plans.
  • Cyber insurance.

A single investment may affect both components, but a reduction should not be assumed without evidence.

Expected annual reduction

Risk reduction = expected annual loss before − expected annual loss after

Return on Investment in Security

ROSI = (expected annual reduction − annualized cost of control) / annualized cost of control × 100

The annualized cost must include:

  • Licenses.
  • Implementation.
  • Integrations.
  • Infrastructure.
  • Managed Services.
  • Staff.
  • Training.
  • Support.
  • Maintenance.
  • Renovations.
  • Exchange Costs.
  • Dismantling of previous tools.

ROSI should not be presented as a certainty. It should be calculated for best-case, most likely, and worst-case scenarios.

Step 5: Compare Alternatives

The Finance Department should not receive a request with only one default option.

AlternativeCostExpected reductionResidual riskInvolvement
AcceptBassVoidHighRequires explicit approval of the risk
Basic MitigationLow or mediumMidtermMedium or highHandle priority checks
Comprehensive MitigationMedium or highSign UpLow or mediumIt requires implementation and governance
TransferPremium and deductibleIt reduces some of the impactMaintains operational exposureThe insurance does not cover the procedure
AvoidVariableRemove the specific scenarioBassIt may involve discontinuing a service
Managed ServiceRecurring OPEXIt depends on the scope and SLAVariableReduces the internal capacity gap

NIST recommends prioritizing risks based on their impact on business objectives and including both the selected response and its projected cost in the risk register.

Step 6: Present the business case on one page

Header

  • Decision requested.
  • Amount.
  • Period.
  • Sponsor.
  • Date required.

Risk Scenario

  • Event.
  • Active.
  • Process affected.
  • Consequence.
  • Risk owner.

Exhibition

  • Minimum, probable, and maximum frequency.
  • Minimum, probable, and maximum loss.
  • Expected annual loss.
  • Impact on EBITDA.
  • Need for cash.
  • Regulatory or contractual obligations.

Alternatives

  • Accept.
  • Mitigate.
  • Transfer.
  • Avoid.
  • Implement in phases.

Recommendation

  • Total investment.
  • Expected reduction.
  • Residual risk.
  • Implementation period.
  • Branches.
  • Evidence to be submitted.

Indicators

  • Current level.
  • Goal.
  • Date.
  • Person in Charge.
  • Data source.

Metrics that justify the investment after it has been approved

An investment must generate periodic evidence.

Financial Metrics

  • Expected annual loss.
  • Exposure reduction.
  • Cost per incident.
  • Avoided extraordinary costs.
  • Avoided downtime hours.
  • Penalties Avoided.
  • Total cost of ownership.
  • ROSI by stage.
  • Acceptable residual risk.

Control Metrics

  • Critical assets covered.
  • Protected privileged identities.
  • Unpatched, exploitable vulnerabilities.
  • Retention period for critical findings.
  • Successful restoration rate.
  • Coverage for immutable backups.
  • MFA Coverage.
  • Critical suppliers evaluated.
  • Classified information.
  • Automated use cases.

Response Metrics

  • Mean Time to Detect.
  • Mean Time to Contain.
  • Mean Time to Recover.
  • RTO.
  • RPO.
  • Climbing time.
  • Time to decide.
  • Notification period.
  • Percentage of playbooks executed.

Pulse’s IT SecOps Automation solution combines observability, alerts, playbooks, and specialized support. In a 24/7 logistics case study, the combination of observability with Datadog, alerts, and support resulted in a 50% reduction in response time and 99.99% availability.

Prioritize investments by scenario, not by tool

A cybersecurity financial portfolio can be organized into five groups:

Income Protection

  • Platform Availability.
  • Digital Channel Protection.
  • Point-of-sale security.
  • Production continuity.
  • Fraud prevention.

Margin Protection

  • Automation.
  • Reduced detection times.
  • Less manual labor.
  • Tool Consolidation.
  • Reduction in recurring incidents.

Data Protection

  • Identity.
  • Classification.
  • DLP.
  • Encryption.
  • Privileges.
  • Intellectual Property Protection.

Compliance and Contracts

  • Evidence.
  • Audit.
  • Traceability.
  • Third-Party Management.
  • Withholding.
  • Separation of duties.

Resilience

  • Backups.
  • DRP.
  • Answer.
  • Crisis.
  • Observability.
  • Continuous operation.

This classification allows the finance department to understand which portion of the value generates revenue, which reduces costs, and which mitigates risk.

Incorporate the 2026 risk context

The World Economic Forum reported that 65% of large companies consider third-party and supply chain vulnerabilities to be their main obstacle to cyber resilience, up from 54% the previous year. It also found that 69% of CEOs in Latin America and the Caribbean acknowledge that they do not have all the capabilities necessary to achieve their current cybersecurity goals.

In Latin America and the Caribbean:

  • 95% of organizations believe that AI and machine learning will have the greatest impact on cybersecurity over the next 12 months.
  • 85% report that AI-related risks have increased.
  • 51% do not have processes in place to assess the security of AI tools before deployment.

This changes the budget conversation. Investments should no longer be limited to protecting traditional infrastructure; they must also cover identity, data, vendors, the cloud, automation, and artificial intelligence.

Mistakes That Weaken the Application

  • Rely solely on fear. An alarming statistic may spark a conversation, but it does not prove that the scenario is a real threat to the company.
  • Reporting vulnerabilities without context. Ten critical vulnerabilities in isolated assets may pose less risk than a moderate vulnerability in a revenue-generating process.
  • Promising zero risk. Every investment carries some residual risk. Concealing this reduces credibility and makes it difficult for management to take responsibility.
  • Confusing potential savings with EBITDA. Not every avoided loss is automatically reflected as an improvement in the financial statements. Economic impact, cash flow, and EBITDA must be distinguished from one another.
  • Exclude operating costs. An inexpensive license may require staff, integrations, and maintenance that drive up the TCO.
  • Do not consider adoption. A control that is not used, monitored, or deactivated to avoid friction does not result in the expected reduction in risk.
  • Justifying spending after the incident. Evidence gathered afterward can help secure funding, but it comes after the damage has already been done. IBM reported that only 49% of the affected organizations in its global sample planned to increase security spending after a data breach, compared with 63% the previous year.

How Pulse Translates Cybersecurity into Business Results

Pulse structures the investment case based on:

  • Loss Scenarios.
  • Critical assets and processes.
  • Financial statement.
  • Maturity of controls.
  • Inherent and residual risk.
  • Treatment options.
  • Response costs.
  • Key Performance Indicators.
  • 3-, 6-, and 12-month roadmaps.
  • Governance and monitoring.

Pulse’s Cyber Risk & Compliance offering includes an exposure map, a prioritized log of findings, executive dashboards, and remediation support. What sets it apart is its ability to translate technical findings into impact, accountability, progress, and business decisions, rather than leaving the results confined to a standalone report.

Pulse also integrates business continuity, Secure & Manage 365, IT SecOps Automation, and hybrid cloud operations, so that an investment decision can be evaluated based on its combined impact on security, continuity, compliance, and efficiency.

Predictive Conclusion

Requests based on tools, generic threats, or maturity levels will take a back seat to initiatives that demonstrate financial impact. The expansion of AI, hybrid cloud, third parties, and digital supply chains will force committees to compare cybersecurity with other capital decisions using common criteria.

The discussion will shift from “How much does the solution cost?” to “How much risk does it reduce, what losses does it prevent, what evidence will it provide, and what level of exposure will we continue to accept?” Organizations that answer these questions before requesting a quote will see faster decision-making and clearer executive accountability.

FAQ

  1. What percentage of revenue should be invested in cybersecurity? There is no universal percentage. The investment must be based on loss scenarios, the criticality of processes, obligations, internal capacity, risk appetite, and the cost of security measures. Two companies with similar revenues may have completely different digital and regulatory exposures.
  2. How can you justify the investment if the company has never experienced a serious incident? Use minor incidents, confirmed attempts, findings, asset exposure, test results, and quantified scenarios. External benchmarks help validate the scale of these issues, but the decision must be based on your own processes, revenue, and dependencies.
  3. How is the return on investment in cybersecurity calculated? Estimate the expected annual loss before and after the control, calculate the risk reduction, and subtract the annualized cost. The analysis should present scenarios, TCO, residual risk, and operational benefits, avoiding the presentation of a single figure as a guarantee.

Manage an investment case, not a list of threats. Use Pulse to quantify scenarios, link assets to critical processes, estimate financial exposure, prioritize actions, and build a roadmap with metrics, responsible parties, and residual risk.

Request a Cyber Risk & Compliance assessment with Pulse and turn your cybersecurity needs into a well-founded, prioritized, and measurable financial decision.

Estamos listos para hablar de tu proyecto

CONTACTO

Envíanos tus datos y nos pondremos en contacto contigo sin ningún compromiso