Editor's note:George Moser is the Chief Growth Officer at Anomali, a company headquartered in Redwood City, California, that provides AI-driven cybersecurity software. The views expressed in this article are solely those of the author.

Security budgets are facing unprecedented scrutiny. Although cybersecurity remains a board-level priority, the pressure to do more with less is growing, especially for CFOs who need to balance cost discipline with strategic investment.

Data shows that cybersecurity budgets are expected to grow by only 4% on average in 2025, a significant slowdown from 8% in 2024, reflecting heightened economic uncertainty and shifting executive priorities. Meanwhile, AI is reshaping corporate strategy, but not without concerns. About three-quarters of finance leaders believe that AI introduces security and privacy risks that could threaten an organization's financial health. This risk-averse tendency may hinder innovation, even though many CFOs view AI as a key driver of transformation in the coming years.

The opportunity lies in this: CFOs and Chief Information Security Officers (CISOs) have more in common than they might think. Both are guardians of enterprise risk, both report to the board, and both face pressure to quantify outcomes. When they align, cybersecurity can transform from a cost center into a competitive advantage, becoming a lever for resilience, efficiency, and performance.

The Collaboration Gap Between CFOs and CISOs

Despite sharing responsibility for enterprise risk, CFOs and CISOs often fail to collaborate effectively due to differences in language, metrics, and perceptions of value. Viewing cybersecurity merely as an ongoing cost, without strategic vision, is especially problematic when security investments are not clearly linked to business outcomes or operational impact. Without quantifiable metrics that translate risk into financial terms—such as how each dollar invested reduces business disruption, improves system availability, or avoids regulatory and reputational costs—CFOs find it difficult to justify maintaining or increasing spending.

CISOs must move beyond technical jargon and translate cyber risk into metrics that are meaningful to CFOs. At the same time, CFOs need to shift their mindset, viewing cybersecurity as a matter of resilience rather than mere defense. An effective shift is to adopt a value-per-dollar perspective when evaluating security investments, meaning the amount of risk mitigated relative to spending. This enables financial leaders to compare security decisions with other business investments using a familiar ROI framework.

Many Fortune 500 companies already treat security as a strategic advantage, supported by data that CFOs can present to the board. By managing residual risk to mature levels and demonstrating an excellent value-per-dollar ratio, they prove that cybersecurity investments can generate measurable business outcomes.

A Five-Step Action Guide for CFO-CISO Alignment

Here are five key initiatives to improve the CFO-CISO partnership:

  1. Use a Common Language: CISOs need to translate cybersecurity into financial terms (such as cost per incident, ROI on risk reduction, operational impact), while CFOs should understand that not all security value is immediately visible.
  2. Define Shared KPIs: Metrics such as mean time to respond, cost per threat mitigated, or critical asset coverage can foster accountability and alignment across both teams.
  3. Prioritize Integration Projects: Jointly identify overlapping tools and vendor redundancies; consolidation can free up budget and improve visibility, benefiting both finance and security.
  4. Quantify Residual Risk: Defining security investments in terms of risk reduction relative to board-approved thresholds helps justify spending with measurable impact.
  5. Focus on Long-Term Planning: Do not budget merely for compliance; invest in capabilities that scale with the business and reduce long-term costs, such as automation and AI.

The alignment between CFOs and CISOs should be viewed as a competitive advantage. As financial pressures and cyber risks rise in tandem, organizations must treat cybersecurity as a strategic investment rather than a mere cost. The path forward is clear: work together, turn risk into value, and invest in cybersecurity that delivers measurable returns.