How to Build a Business Case for Cybersecurity Investments

In August 2026, California’s Department of Financial Protection and Innovation (DFPI) ordered Academy Mortgage to pay $825,000 for failing to protect the personal information of 284,443 people. That penalty was the smallest line on a much larger invoice. My estimate, built from IBM’s 2026 Cost of a Data Breach benchmarks scaled to Academy’s size, puts the true cost of the March 2023 ransomware attack somewhere around $9.8 million. That total includes incident response, notifications for 284,443 individuals, 12 months of identity theft insurance for 34,452 California residents, legal fees, a week of halted lending, and lost business.

The consent order, which I broke down in detail last month, taxes six years of inaction:

  • No formal security audit between 2017 and 2023. Six years.
  • Inadequate risk assessments for 2021 through 2023.
  • No documented asset inventory of systems or data.
  • No current incident response plan.
  • Penetration testing findings with no record of remediation.

Each of those omissions represents a decision not to spend, or a decision to accept risk without measuring it. The DFPI priced all of those into the penalty.

By comparison, audits, current risk assessments, a maintained incident response plan, and a proper forensic engagement would have cost a company of this size maybe $100,000 to $300,000 per year. Pad that to $450,000 for a bad year and it barely moves the comparison. Against $9.8 million, that’s a return any CFO would sign in a heartbeat. So why doesn’t it happen?

Because the prevention spend buys nothing visible until it prevents something. Academy’s executives weren’t facing villains draining the bank account; they were facing the harder problem of approving expenditures whose value shows up only as costs that never appear.

Security Risks Are Business Risks

The thesis of my book Cyber Risk is a Myth (CRC Press, September 2026) is simple enough to quote out of context: there’s no separate category called “cyber risk.” There are only business risks, some of which happen to be triggered by computers. The consequences land in dollars, downtime, courtroom settlements, and regulatory penalties. And when you treat security as a specialist concern with its own vocabulary, accountability fragments and risks fall into the gaps between departments.

Two Court Cases That Settle the Argument

The receipts are recent and specific.

Anthem, historically. The 2015 breach of 80 million records produced a $115 million settlement approved by Judge Lucy H. Koh in August 2018, the largest data breach settlement at the time, and still the largest healthcare data settlement until Change Healthcare’s fallout. On top of that came a $16 million resolution with the Department of Health and Human Services (HHS) for potential violations of the Health Insurance Portability and Accountability Act (HIPAA). Anthem’s unencrypted databases were fully compliant with the law. Compliance was not a defense.

More recently, in June 2026, the Seventh Circuit ruled that the Office of the Special Deputy Receiver couldn’t recover its $4 million business email compromise (BEC) loss from Hartford. I’ve written about why that outcome belongs to finance, but the short version: Judge Kirsch’s panel never discussed email filtering, multi-factor authentication, or security awareness training. The court parsed contract language and dismissed on a motion. The controls that would have stopped the fraud, dual authorization on wire transfers and callback verification to pre-existing phone numbers, live in the finance department’s procedures manual, not the security stack.

Courts, regulators, and insurers have already made their decision: they evaluate security failures as business failures. The only people still treating “cyber” as a separate category are inside the organization, and that’s the gap a business case has to close.

Start with How Executives Evaluate Investments

Every investment proposal in your company, including yours, competes for a finite pool of capital through the same gate: return on investment (ROI), payback period, net present value (NPV), and opportunity cost. A new warehouse, a marketing campaign, and a security platform all get scored with those instruments. Proposals fail when they ignore the gate, not because the people behind the gate are hostile.

Security has two structural disadvantages at this gate, and both deserve honesty rather than complaint:

  • Benefits appear as costs avoided, not revenue gained, so the payoff is invisible on a good day.
  • The worst outcomes are low-probability, high-impact events whose timing nobody can predict, which makes the expected-value math genuinely awkward.

There’s also a visibility problem that no spreadsheet fixes: when security works perfectly, it looks unnecessary. The museum with no burglaries looks overstaffed. Your job in a business case is to make the invisible legible, in financial terms, to people who allocate capital for a living.

Map Every Security Initiative to a Business Objective

If a proposal can’t name the business objective it serves, it’s a feature request, and feature requests lose to projects that can. The tool I use for this, developed for the book, is the Security-Business Alignment Matrix.

The Alignment Matrix

Six columns, filled in for each initiative you’re pitching:

ColumnWhat Goes in It
Business ObjectiveA strategic goal from the annual report or executive priorities
Security InitiativeThe security capability or program you’re proposing
Business ValueHow the initiative enables or protects the objective
Risk ConsequenceThe business impact if the security issue occurs
Quantified ImpactA financial estimate of the opportunity or risk
Timing AlignmentHow this aligns with the business timeline

One worked row from the matrix makes the mechanics obvious:

Business ObjectiveSecurity InitiativeBusiness ValueRisk ConsequenceQuantified ImpactTiming Alignment
Expand into Southeast Asian marketsIdentity and access management platform upgradeSatisfies regulatory requirements for financial services in Malaysia and Singapore; enables secure customer onboardingMarket entry delays; regulatory penalties; competitor advantage$2.4M in delayed revenue per quarter; $800K in compliance costsImplement 60 days before regional expansion

That single row does more persuasion than 50 slides about nation-state threat actors. It converts a platform purchase into a market-entry enabler with a price tag attached to failure, and the executive can locate it instantly inside a strategic priority they already own.

How to Fill in Your Own Matrix

  1. Pull the top three to five objectives from the annual report, investor presentations, or the strategic plan, because those documents are where leadership has already committed publicly to what matters.
  2. Attach at least one metric per initiative that business leaders already track, since executives trust numbers they recognize.
  3. Update the matrix quarterly. Priorities drift, and a stale matrix reads as a stale proposal.

Quantify It, or It’s Just a Feeling

A security business case rests on three calculations, none of which takes a statistics degree. Each one answers a question a CFO is already asking.

Annualized Loss Expectancy

Annualized loss expectancy (ALE) multiplies the cost of a single incident by its estimated annual probability. If a data breach would cost $2 million and carries a 10% annual chance of occurring, the ALE is $200,000 per year. That’s what you’re insuring against, expressed in dollars a CFO can compare against anything else competing for the same dollars.

Benchmark inputs are freely available. IBM’s 2026 report puts the average financial services breach at $6.29 million and the average US breach at $11.5 million. Even the 2023 figure of $4.45 million, which was current when I wrote the book, shows the trend line runs in one direction.

Risk Reduction ROI

Divide the reduction in ALE by the cost of the investment. Spend $500,000 to cut annual loss expectancy from $200,000 to $50,000, and you’ve bought $150,000 of annual risk reduction, a 30% return. Put that next to the hurdle rate your CFO uses for capital projects and let them do the comparison in their head. It’s usually a short calculation.

Total Cost of Ownership

Total cost of ownership (TCO) keeps you honest about your own numbers. Purchase price typically runs 20 to 30% of lifetime cost once implementation, integration, training, maintenance, and replacement are counted. Quoting license fees alone in a proposal is how security leaders lose credibility in year two, when the renewal invoice lands.

How Precise Do You Need to Be?

Going fully quantitative for every risk in the register is a project that dies in workshops at most organizations. In the book, I argue that most companies should run the financial math on their three or four highest-impact exposures, where the effort changes real decisions, and use qualitative high/medium/low ranking for the long tail. Hybrid is not a cop-out; it’s how finite teams get defensible numbers in front of a budget committee before the budget committee meets.

The Four Buckets of the Financial Model

Structure the analysis the way the book’s ROI calculator does, because each bucket forces a different conversation:

BucketWhat It ContainsThe Conversation It Forces
Investment costsInitial purchase, implementation, training, annual maintenance, 3-year TCOAre your own numbers honest?
Risk reduction benefitsCurrent ALE, expected ALE after implementation, annual and 3-year reductionWhat are you insuring against?
Business enablement benefitsEfficiency gains, reduced compliance costs, revenue protection and enablementWhat does this investment make possible?
Financial outputs3-year ROI, payback period, NPV at your discount rateCan this compete with the warehouse?

That third bucket earns its place. Loss-prevention numbers argue that the investment is cheaper than the incident. Business enablement numbers argue something executives find more convincing: the investment lets the company do things it currently can’t, like entering a regulated market or shipping a digital product without adding fraud risk.

The Cost of Doing Nothing

“Do nothing” never appears on the options list in a capital allocation meeting, which is unfortunate, because it’s the option most organizations actually choose. It feels free. It isn’t.

Run the same financial discipline on inaction that you’d run on the investment:

  • What’s the ALE of the unaddressed risk?
  • What compliance gaps does inaction create or preserve?
  • Which strategic initiatives does it quietly block?
  • What could the same capital earn elsewhere?

Place that sheet next to the proposal, line by line. When you compare all three honestly (the investment, the alternatives, and the status quo), the status quo usually loses. In Academy Mortgage’s case, the loss ran to just under 2% of a single year’s revenue on an estimated $521 million.

The Documentation Tax

The Academy order adds a wrinkle most business cases miss, and it’s the one regulators will get really interested in. They treated the absence of documentation as a substantive violation, not a paperwork shortcut. Academy’s forensic consultant delivered a one-page close-out letter, and the DFPI found it insufficient because it never addressed the root cause, contributing factors, or remediation. The principle: when you can’t show your work on risk, regulators assume you didn’t do the work, and they price that assumption accordingly. A business case that survives contact with a consent order needs metrics that document what was assessed, what was decided, and by whom.

Getting Past the Objections

Four objections account for most rejected security proposals I’ve seen. Each has a response pattern that works because it answers in business terms rather than security terms.

ObjectionThe ReframeThe Response That Works
“Nothing bad has happened yet”How do we assess risk without historical incidents?Industry benchmarks (peers breached last year at a known average cost) and near-miss analysis (the attempts your controls blocked last quarter, and the exposure those blocks prevented)
“We’re already compliant”What value does this provide beyond compliance?Most breached organizations were compliant at the time of breach. Compliance is a floor, not a ceiling. Anthem met HIPAA to the letter and still faced a $131 million combined bill
“The cost is too high”How does the ROI compare with our alternatives?Show the ALE, the reduction, the payback period. If the numbers don’t close, phase the rollout to address the highest exposures first
“We have other priorities right now”How does this support current priorities?Attach to the initiative that depends on this capability, quantify the dependency, and integrate the implementation to share resources

On “cost is too high,” one point deserves emphasis: that objection is an invitation, not a rejection, because now the conversation is math. Executives can reject a price; they have a much harder time rejecting a payback period.

And on “other priorities,” a proposal that rides a funded priority inherits its momentum. One that competes against it dies politely in a hallway conversation you don’t attend.

Two tactical points that aren’t objections but decide outcomes anyway. Build the coalition before the meeting: identify the business leaders who benefit from the investment, document how it serves their objectives, and recruit them as advocates ahead of the approval discussion. Then mind the calendar, because mid-year requests face hurdles that budget-cycle proposals don’t, and missing a planning milestone can defer good projects regardless of merit.

The Business Case Is a Living Document

Academy’s consent order taxed six years of decisions. Delta Dental’s $2.25 million settlement with New York’s Department of Financial Services (DFS) in April 2026 taxed three years: the MOVEit zero-day was exploited in May 2023, Progress shipped a patch four days later, and DFS came collecting in 2026 for the gap in between. I covered that settlement here. Both cases punish the same behavior: treating a security business case as finished work. Academy filed its risk decisions in 2017 and paid for them in 2026, a six-year gap. Delta Dental’s MOVEit failure lasted only days, and the regulatory bill still arrived three years after the vulnerability was exploited. Breach costs rise and rules change, so the assumptions behind your business case have a shelf life. Review them annually, or the document slowly stops describing your actual risk.

At minimum, once a year:

  • Refresh the ALE inputs against current breach cost data
  • Retire risks the organization has actually addressed
  • Add the ones that arrived since
  • Reconfirm the business objectives you’re claiming to serve still exist

A business case that’s regularly updated stays aligned with a business that changes. And the discipline of revisiting it builds something more valuable than any single approval: a track record of predictions that turned out approximately right. That’s the currency you’ll spend on the next request.

Security investment decisions are business decisions with business consequences, and they deserve the same rigor as any other capital allocation. When you present them that way, with dollar figures, settlement benchmarks, and a cost attached to inaction, you’ve stopped asking executives to trust you. You’ve given them something they can verify, in familiar terms.

FAQ

It means there’s no separate category called cyber risk. A compromised email account is a potential fraudulent payment, a data breach is a settlement, a missed patch is a consent order. Each consequence has an owner somewhere in the business, and the controls that matter are frequently business controls like dual payment authorization rather than technical ones.

Multiply single loss expectancy (the cost of one incident) by annual rate of occurrence (the estimated yearly probability of that incident). A $2 million incident with a 10% annual chance yields a $200,000 ALE, which can be compared directly against the cost of controls that reduce it.

Divide the reduction in ALE by the investment cost, then multiply by 100. An investment of $500,000 that cuts ALE from $200,000 to $50,000 delivers $150,000 in annual risk reduction, or a 30% annual return.

Replace luck with data: industry benchmarking against comparable organizations, near-miss counts from your own environment, and the rising cost of breaches, which makes reactive spending after an incident far more expensive than preventive controls before one.

Compliance frameworks set a minimum baseline standardized across entire industries, so they can’t address risks specific to your business. Most breached organizations were compliant with relevant standards at the time of the breach, including Anthem, whose unencrypted databases met HIPAA’s requirements before producing a $131 million combined bill.

Security Risks ARE Business Risks. Get the Weekly Context.

Every week, I break down the most important intersections of cybersecurity, AI regulation, and business risk. Plus: early access to 'Cyber Risk is a Myth' chapter resources and course updates.

I don’t spam! Read the privacy policy for more info.

Similar Posts