Your Security Budget Isn’t a Cost Center – It’s Capital You’re Already Losing

There’s a conversation happening in boardrooms where cybersecurity doesn’t have a seat at the table. Risk registers track credit exposure, supply chain concentration, and litigation, while security findings circulate in a parallel universe of vulnerability counts and CVSS scores that no CFO can price. The consequence is that every security decision, funded or deferred, becomes a capital allocation decision made blind. Courts, regulators, and insurers figured this out years ago; the only holdouts are the organizations themselves.

This piece is about closing that gap. It starts with what unpriced security risk actually costs once the bill arrives, walks through four recent cases where the money left through holes that some basic documents would have plugged, and ends with the framework I use to tie technology directly to revenue, uptime, and written risk appetite. No maturity roadmaps, no platform purchases, and no treatises on NIST framework alignment. Just what failing to integrate looks like in dollars, and the paperwork that prevents it.

Consider what happened when a dental insurer refused a ransom demand.

In March 2023, LockBit demanded $10 million from MCNA Dental. Management refused, the attackers published 700 GB of stolen data two days later, and everyone moved on. Then the invoice arrived three years later in the form of a settlement. Once forensic work, defense litigation, administration, and remediation stacked against the documented ceilings, the reconstructed cost landed between an estimated $16 million and $23 million.

That refusal wasn’t courage. It was a capital allocation decision made without pricing the alternatives. The numbers below are reconstructed from the docket.

What MCNA’s Refusal Actually Cost

Cost ComponentRangeBasis
Forensic investigation$500K – $1.5MEstimate; enterprise IR benchmarks
Defense litigation, 2023-2026$4M – $8MEstimate; anchored to plaintiffs’ lodestar
Post-incident remediation, year one$1M – $2.5MEstimate; engineering list-price
Settlement fees, costs, administrationUp to ~$10MCeilings from preliminary approval order
Estimated total, ex-ransom~$16M – $23MSum of non-overlapping components

The Myth of a Separate Category

There is no separate, magical category called “cyber risk.” There are just business risks, some of which happen to be triggered by computers, and the consequences land in dollars, downtime, courtroom settlements, and regulatory penalties.

Courts and insurers have already made their decision. They evaluate security failures as business failures. The only people still treating “cyber” as a separate category are inside the organization.

That gap is what catches you. The full argument lives in Cyber Risk is a Myth, which traces how terminology created artificial divides between cybersecurity and business risk in the first place.

Four Failures, Four Missing Pieces

Recent incidents from four different corners of the economy show the same pattern, each carrying a price tag and a missing document.

Order Express and the Risk Assessment That Forgot Its Purpose

The New York State Department of Financial Services (NYDFS) issued a $250,000 consent order against the Chicago money transmitter in August 2026. Their risk assessment considered “operational and information technology risks” while excluding cybersecurity threats entirely. With no CISO and no security staff on the org chart, the COO signed the order. The violation wasn’t sophisticated hacking; it was a scoping failure where threats fell outside the frame of whoever ran the process. Read the full breakdown.

OneTouchPoint, the Company That Didn’t Know Its Own Customers

A print vendor serving more than 30 healthcare payers notified 1.1 million people after a 2022 ransomware attack. Two months later, the count revised to 2,651,396. A company in the business of knowing whose name goes on which envelope didn’t know how many people’s data it held, and the bill ran to roughly $9.7 million once four years of litigation settled. The full procedural saga is worth your time.

American Consumer Credit Counseling and the Seven-Figure Mailbox

Attackers held employee mailboxes for 22 days, and detection took another 49. The eventual settlement cost between $1.06 million and $2.15 million, while prevention would have run $40,000 to $90,000 a year, less than the settlement’s fee motion alone. All told, the incident consumed up to 9 percent of a single year’s revenue. The ledger tells the story.

Honeywell, Where Quantum Computing Ran on Windows Defender

On December 14, 2020, monitoring software fired SolarWinds alerts on a network holding Controlled Unclassified Information tied to US intelligence programs. A manager looked at the logs and concluded “I don’t see anything concerning.” Rachel Tenney, the whistleblower who pushed for a real investigation, filed under the False Claims Act and was eventually escorted out of the building. The $2 million settlement resolved allegations only, but the cost stands. The whole thing is on the record.

The Three-Document Fix

None of these failures were unavoidable. Each maps to a missing document and a process that ties technology directly to revenue and uptime. The framework works as a 100-day stabilization exercise rather than a multi-year maturity project, and it starts with conversations instead of control scans.

Document 1. The Business Process Catalog

The record of what the organization actually does, who owns what, and the monetary value per unit of time.

  • Revenue generated per hour or day
  • Maximum tolerable downtime for each process
  • A single accountable owner per process, not a committee

Without those numbers you can’t calculate the cost of anything, which explains why requests like “we need to fix a CVSS 9.2 vulnerability” go nowhere. (CVSS is the Common Vulnerability Scoring System, and 9.2 is bad.) Reframe it as “this patch protects a process generating $200,000 an hour” and watch how fast approval happens. Start with the Business Process Catalog template.

Document 2. The Business Systems Inventory

The bridge between business processes and the technology they’re made of, capturing vendor contacts, contract locations, data flows, and recovery objectives. When a key system fails at 2 AM on a federal holiday, the incident response (IR) team needs the vendor’s phone number, not a scavenger hunt. Download the Business Systems Inventory template.

Document 3. The Component Ledger

Systems are rarely granular enough for operational decisions. A single Salesforce integration might have an API, an identity provider, a data pipeline, and an email service, each with its own vendor, failure mode, and security posture. The ledger decomposes systems into piece parts so that when a vulnerability drops in a software library, you can see which business processes are affected in minutes instead of weeks. Grab the Component Ledger template.

Together the three documents form a cascade.

LayerWhat It Defines
Business Process CatalogBusiness value and revenue exposure
Business Systems InventoryThe load-bearing technology
Component LedgerHidden dependencies and vendor risk

Trace a failed component up through its system to its process, and you arrive at the revenue figure without hand-waving.

Write Down What You Can Afford to Lose

Documents tell you what you have. Appetite statements tell you how much of it you’re willing to risk, and executives argue endlessly about whether a risk is “high” or “medium” impact precisely because nobody wrote the thresholds down. These are boring arguments.

Unrecorded risk decisions are still decisions. Someone at MCNA accepted the risk of unmonitored egress by omission, and it was settled on terms written by LockBit.

A quantitative boundary like “we will not accept system unavailability exceeding 4 hours for customer-facing applications” ends the debate before it starts. The Risk Appetite Statement Development Framework from my book walks through business context, risk categories, appetite statements with quantitative limits, and board approval. It isn’t hard. It’s just work nobody does until after the settlement conference.

The Financial Math Executives Trust

Security investment decisions deserve the same rigor as any other capital allocation, and the math is shorter than most people expect.

  • Annualized loss expectancy (ALE). Multiply the cost of a single incident by its estimated annual probability. A $2 million breach with a 10% annual chance yields a $200,000 ALE.
  • Risk reduction return on investment (ROI). Spend $500,000 to cut ALE from $200,000 to $50,000 and you’ve bought $150,000 of annual risk reduction, a 30% return. Compare that against your CFO’s hurdle rate for capital projects.
  • Realized-loss accounting. Once an incident has already occurred, no probability discount is needed. MCNA didn’t need to estimate the odds of a breach; it needed to pay for it.

For benchmark inputs, IBM’s 2026 Cost of a Data Breach Report puts the average financial services breach at $6.29 million and the average US breach at $11.5 million. The deeper treatment, including how to run the same discipline on inaction, lives in my post on building the business case.

What to Do Monday Morning

Technology made each breach above possible, but business decisions made the costs inevitable. The fix is unglamorous and it fits inside a quarter.

  • Start with your three highest-revenue processes and build the catalog outward
  • Stand up the Systems Inventory and Component Ledger as staff work, not a software purchase
  • Get the risk appetite statement in front of your board before an incident sets the schedule for you

If you want help with any of this, book thirty minutes with me directly, or look at my virtual CISO services. For weekly breakdowns of where cybersecurity, AI regulation, and business risk intersect, subscribe to the Weekly Context newsletter.

FAQ

There’s no separate category called cyber risk. A compromised email account is a potential fraudulent payment, and a data breach is a settlement. Each consequence has an owner somewhere in the business.

Multiply single loss expectancy by annual rate of occurrence. A $2 million incident with a 10% annual chance yields a $200,000 ALE, comparable directly against control costs.

Most breached organizations were compliant at the time of breach, like Anthem, whose unencrypted databases met HIPAA’s requirements before producing a $131 million combined bill. Compliance sets a floor, not a ceiling.

They bridge technical security teams and executive risk committees, translating security findings into business context that drives funding decisions.

The documents define the assets, processes, and dependencies. The appetite statement defines the boundaries for protecting them, and together they enable defensible risk decisions before an incident occurs.

Security Risks ARE Business Risks. Get the Weekly Context.

Every week, I break down the most important intersections of cybersecurity, AI regulation, and business risk. Plus: early access to 'Cyber Risk is a Myth' chapter resources and course updates.

I don’t spam! Read the privacy policy for more info.

Similar Posts