Most cybersecurity risk programs overlook finance departments: Qualys study reveals business alignment gap
Cybersecurity company Qualys released the "2025 State of Cyber Risk" research report, indicating that most organizations still treat cybersecurity as a purely IT issue, with low finance department involvement (22%) and insufficient alignment of risk programs with business objectives (30%). The research emphasizes that only 14% of organizations link integrated risk scenarios to financial metrics, making it difficult for security investments to effectively reduce risk.

Key Takeaways
- Most organizations still treat cybersecurity as an IT matter,with insufficient attention to financial and other business considerations. This conclusion comes from a recent study commissioned by cybersecurity firm Qualys.
- The study shows that only 22% of organizations include finance teams in cybersecurity risk discussions. While 49% of respondents said their organizations have established formal cybersecurity risk programs, only 30% reported that these programs are prioritized based on business objectives.
- "Security programs that fail to align with operational, financial, and regulatory risks are essentially ineffective," said Mayuresh Ektare, vice president of product management at Qualys, in a blog post about the study.
Deeper Insights
According to the blog post, the vast majority (71%) of organizations believe their cyber risk levels are rising or staying flat, indicating that many security investments are not effectively changing the risk landscape. Qualys found that only 14% of organizations adopt a cyber risk approach that combines integrated risk scenarios with financial metrics.
"Clearly, simply spending more on tools or talent will not change the situation unless organizations have a risk-centric operating model—one that prioritizes business context, continuously assesses controls, and communicates risk in business language," Ektare noted.
Data from the U.S. Federal Bureau of Investigation's Internet Crime Complaint Center shows that 859,532 suspected cybercrime complaints were received in 2024,with reported losses exceeding $16 billion, up 33% from the previous year. The data comes from a report released in April.
"Cybersecurity is not just an IT issue or a crisis scenario in emergency plans, but a continuously growing business concern with real financial impacts, including potential costs such as incident response, legal liability, reputational damage, and revenue loss due to loss of consumer trust," wrote Tunde Lawson and Jaime Kipnes, cybersecurity advisors at Ernst & Young, in an article on a related topic in April.(Original link)
The two authors said that mitigating cyber risk and integrating it into an organization's long-term financial strategy is a mission shared by multiple C-suite executives, including the CFO. The CFO "is uniquely positioned to quantify these risks and estimate the costs of incidents."
They wrote that when CFOs work in tandem with CISOs, they can "gain a deeper understanding of the probability and exposure of risks, set metrics for spending and return on investment, and recommend communication priorities for cybersecurity spending."