Expel Survey: CFOs and CISOs Significantly Divided on Cybersecurity Investment
A report released by Expel points out that CFOs and CISOs have significant disagreements in cybersecurity investment decisions, primarily stemming from differences in metrics and decision-making logic. The report recommends that both parties educate each other and translate technical risks into financial language to promote strategic alignment.

Key Takeaways
- A survey by cybersecurity firm Expel reveals significant misalignment between CFOs and Chief Information Security Officers (CISOs) regarding cybersecurity investment goals and priorities.Misalignment。
- The report, released this month, points to a mismatch in metrics and decision-making logic as the source of the divergence. Security leaders typically base decisions on industry best practices, compliance requirements, and ease of integration, while finance executives focus on cost avoidance and risk reduction.
- The report states: "Rather than repeatedly emphasizing metrics that the other party does not value or understand, CISOs and CFOs should educate each other. By bridging the knowledge gap, finance and security leaders can achieve better alignment, clearer communication, and drive more strategic cybersecurity investments."
Deeper Insights
Expel says these findings come at a time when escalating threats are forcing companies to increase strategic cybersecurity investments.
Cyberattacks are expected to surge this year, with attackers continuously exploring new avenues to leverage advances in artificial intelligence.
Global information services company Experian notes in its 2026 Data Breach Forecast: "Today,new AI-driven threat vectorscould expand the scope, frequency, and cost of data breaches."
As cyber threats become increasingly sophisticated and the financial impact of data breaches rises, CFOs are increasinglytaking a proactive role in cybersecurity strategy and investment decisions. Jack McCullough, President and Founder of the CFO Leadership Council, said in a recent blog post: "This goes beyond simple budget approval; it involves understanding business continuity impacts and ensuring the organization is adequately protected." He emphasized: "Success depends on collaborating with CISOs and IT leaders to translate technology risks into language that boards and investors can understand, maintaining transparency about vulnerabilities and incident response capabilities, and being agile in responding to emerging threats."
The Expel report shows that security and finance leaders report good collaboration, with 74% and 68% of respondents respectively saying the two sides work together early and frequently. However, the research still reveals disconnects.
Security leaders say that when seeking funding from finance, they often encounter obstacles such as the finance side's limited understanding of cybersecurity risks. Finance leaders, on the other hand, want specific, quantifiable data before approving cybersecurity investments, with 40% of respondents saying that if risk reduction could be quantified, it would be easier to justify increased spending.
More than four in ten (over 40%) finance executives believe that better translating technology risks into financial terms would improve collaboration between the two teams.
Expel points out that to align the two sides, they must learn to speak the same language. The report suggests: "Security leaders may need to translate metrics into measures that finance leaders can relate to. For example, 'ease of integration' can be converted into time or cost metrics, while 'meeting compliance requirements' can be translated into avoiding fines."
The report is based on a survey of 136 cybersecurity leaders and 164 finance executives, Expel said.