Cybersecurity Increasingly Becomes a Core Issue for CFOs: Microsoft Perspective
Microsoft published a new article stating that cybersecurity is evolving from an IT technical issue into a financial risk, requiring CFOs to engage more deeply in cyber risk management. The U.S. recorded 3,322 data breaches in 2025, a 79% year-over-year increase; JLR's sales dropped by 43% due to a cyberattack. IBM data shows the average cost of a U.S. data breach reached $10.22 million, a historic high.

Core Summary
- A recent Microsoft thought leadership article notes that cybersecurity has shifted from an information technology concern to an increasingly financial risk-bearing domain, now falling within the remit of the modern CFO.
- As cyber incidents increasingly translate into financial losses and operational disruptions, the CFO's role in assessing and managing cybersecurity risk has become more central; Microsoft states that recent advances in artificial intelligence have accelerated this trend.
- The article states: "Cybersecurity may have once been quietly managed in the background, but it has now become a visible financial leadership challenge, shaped by regulation, AI acceleration, and rising expectations from boards and investors."
In-Depth Analysis
According to tracking by the nonprofit Identity Theft Resource Center, U.S. cyberattacks reached a new peak in 2025, resulting in a record 3,322 data breaches, a 79% increase over 2020 levels. The organization specializes in tracking and reporting U.S. data breaches and identity theft activity.
SAP Concur's latest CFO Insights report shows that cybersecurity has now surpassed economic conditions and geopolitical tensions to become the top external concern for financial leaders globally. The report states: "Like a giant wave, cyber threats have risen sharply to become the primary external challenge facing financial leaders."
One closely watched case is Jaguar Land Rover, which said in January that a cyber incident disclosed in early September continued to weigh on its sales. According to Cybersecurity Dive, a sister publication of CFO Dive, wholesale volumes fell 43% year-over-year to 59,200 units in the three months ended December 31, compared with a higher figure in the same period a year earlier. JLR CFO Richard Molyneux said on a November earnings call: "The cyber incident meant we had to shut down systems during one of the highest-volume months of the year."
IBM reported last year that the average cost of a U.S. data breach was $10.22 million, a 9% increase over the prior year's level and the highest record for any region. IBM attributed the surge primarily to stricter U.S. regulatory fines and higher detection and escalation costs, while the global average breach cost fell 9% to $4.44 million over the same period.
Microsoft notes that in the current environment, organizations face growing pressure to move cybersecurity out of siloed technical functions and into enterprise-level decision-making processes, including risk management and financial planning. Microsoft says CFOs are increasingly becoming key players in translating cyber risk into financial terms used for planning, governance, and reporting.
The article emphasizes that cybersecurity incidents should be assessed from a business impact perspective, including disruptions to operations, cash flow, and long-term performance. It calls for greater coordination among finance, security, and technology leaders to ensure risks are consistently assessed and communicated at the executive level.
The guidance also stresses the need to embed cybersecurity into enterprise risk management frameworks, especially as organizations scale their AI adoption. The article states: "Leading organizations are beginning to model cyber events the way they model budget or supply chain disruptions—using scenario-based approaches to understand downtime, response costs, regulatory exposure, and potential impacts on cash flow."