
Every CISO has sat in the same meeting. The slide shows a heat map red, amber, green with identity risk sitting somewhere in the upper right, “critical.” The CFO looks at it, nods politely, and asks the question that ends the conversation: “What does this cost us if it happens, and what does it cost us to fix?”
Silence. Or worse, a number that everyone in the room quietly knows was reverse-engineered from the budget ask rather than the other way around.
This scene plays out constantly, and it’s not because security leaders don’t understand their risk. It’s because most of them have never had to price it. A recently commissioned survey of 312 senior security and IT leaders at U.S. enterprises, found that 41% have no defensible, methodology-backed dollar estimate of their identity risk exposure. Ninety-four percent, meanwhile, call a financially quantified view of identity risk a top or high priority. And tellingly, even among the majority who claim to have one, “lack of financial context to justify remediation investment” remains a top-cited barrier to getting anything funded.
That’s not a visibility problem. Security teams have more visibility into identity risk than ever. It’s a translation problem. We’ve built an entire discipline around describing identity risk in a language the business doesn’t speak, and then we’re surprised when the business doesn’t act on it.
Qualitative scores don’t survive a budget conversation
Risk heat maps, 1-to-5 severity scales, and “critical/high/medium/low” labels are useful for prioritizing a backlog. They are not useful for competing against every other line item on a CFO’s desk; a plant expansion, a pricing initiative, a competitor’s product launch. All these items show up with a projected return, a payback period, or at minimum a hard number attached to the downside of inaction.
When identity risk shows up as “critical” with no dollar figure behind it, it isn’t wrong, it’s just incomplete in the one dimension that matters to the person who controls the budget. CFOs are trained to evaluate risk the way they evaluate any other capital allocation decision: probability, magnitude, and time horizon, expressed in currency. A color on a chart doesn’t clear that bar. It gets acknowledged, filed, and revisited only after something breaks, at which point the organization is funding remediation under duress, at a materially worse price than if it had funded prevention on its own timeline.
This is the core dysfunction the survey data points to. It’s not that leaders lack conviction about identity risk. It’s that conviction, expressed qualitatively, is not a currency the CFO can spend against.
An “estimate” is not the same as a defensible figure
Here’s where a lot of well-intentioned efforts fall short: producing “a” number isn’t the same as producing a number that holds up. A dollar figure pulled from a single breach benchmark report, an industry average, or a back-of-envelope calculation from last year’s incident will not survive scrutiny in a budget cycle, and shouldn’t. CFOs and boards are increasingly financially literate about cyber risk, and a soft number gets picked apart as quickly as a soft qualitative score.
Treat event frequency, vulnerability, and loss magnitude, each with documented assumptions that can be defended, challenged, and updated as conditions change. The transparency of the method is what earns a CFO’s trust; the specific model matters far less. For identity risk specifically, that means quantifying exposure across dimensions like the number of privileged and non-human identities outside strong authentication, the blast radius of a compromised credential given current segmentation and access controls, and the realistic cost of detection, response, and downtime if that credential is used maliciously.
The output isn’t a scarier number than the heat map produced, it’s often a more credible one, because it shows its work. A range of “$4.2M to $11.8M in expected annual loss exposure, driven primarily by unmanaged machine identity sprawl” is something a CFO can model against a remediation cost, a cyber insurance premium, or a competing capital project. “Critical” is not.
Building the financial narrative before the incident, not after
The organizations that get identity risk funded proactively share a pattern: they’ve stopped asking for budget and started presenting an investment case. That shift requires three things.
First, translate exposure into the same units the CFO already uses. If your finance team models revenue risk in dollars, your security risk needs to show up the same way, on the same scale, so it can be compared honestly rather than qualitatively gestured at.
Second, connect the number to a specific, costed remediation path, not a general appeal for more identity tooling. “We can reduce expected annual loss exposure by an estimated $6M by extending phishing-resistant authentication to our top 200 privileged and non-human identities, at a cost of $X” is a proposal a CFO can approve. “We need to mature our identity program” is not.
Third, treat the figure as a living input, not a one-time slide. Identity attack surface changes constantly, new SaaS integrations, new machine identities, new third-party access. A defensible risk figure updated quarterly does two things a static number can’t: it demonstrates the program is being actively managed, and it gives finance a reason to keep the conversation open rather than treating security funding as a once-a-year negotiation.
None of this replaces good security engineering. But it does something engineering alone can’t, it gets that engineering funded on the organization’s terms, before an incident forces the issue on much worse ones. The number is not the end of the work. It is what finally lets you decide which exposures to fix first and route that fix to the people who own it. The 41% of leaders without a defensible number aren’t behind on maturity. They’re behind on a translation exercise that has a well-established methodology sitting right there, waiting to be used.
The CFO was never the obstacle. The missing dollar sign was.
Join our LinkedIn group Information Security Community!










