Why Cyber Incidents Are a Budgeting Problem, Not an IT Problem

by | Cybersecurity / Cyber Insurance

Most CFOs I talk to still think of cybersecurity as an IT line item. A cost center. Something you fund just enough to keep the lights on. That framing used to work. It doesn’t anymore. Not with the way incidents unfold today. The financial impact is too direct and too immediate to treat cybersecurity as a technical expense.

Cyber incidents have become budgeting events, and the CFO is the one left holding the bag when the numbers stop making sense. That connection runs deeper than most realize – understanding the cybersecurity impact on financial projections is now a core competency for any finance leader serious about protecting the organization.

Let me show you what this looks like in the real world.

1. Incidents now trigger real, unplanned cash outflows

A few months ago, a mid‑sized property group called me after a vendor’s compromised account sent fraudulent invoices to their AP team. Nothing exotic. No nation‑state attacker. Just a simple email compromise that slipped past a busy staff. By the time they realized what happened, two payments were already out the door. The next week was a scramble of legal review, tenant communication, insurance notifications, emergency IT response, and forensic work.

The CFO told me, “This incident cost more in five days than our entire annual IT spend.”
That’s the new reality.

Emergency IT response becomes the first bill

The moment an incident hits, the organization is paying for containment, triage, and technical recovery. None of this is planned, and none of it is cheap. And keep in mind, an insurance claim isn’t a guarantee that whatever happens will be eventually reimbursed. That’s a risk in itself.

Legal review adds thousands in unavoidable incident costs

Queue up the lawyers. Your legal counsel has to determine exposure, notification requirements, and liability. Even a short engagement can add thousands to the incident cost.

Insurance notification requirements create immediate operational costs

Your cyber liability insurance carrier requires immediate reporting, documentation, and evidence. Every hour spent gathering that information is an operational cost. Before you even get to that point, there are cyber liability facts CFOs must know – because most finance leaders don’t realize how dramatically the rules have changed until a claim is already in jeopardy.

Before you assume coverage kicks in, it’s worth asking: will your insurance cover a cyber attack? The answer is more conditional than most CFOs realize.

And your carrier becomes a big factor in the next item…

Forensics becomes a mandatory step

Someone has to determine what happened, how far it spread, and what data was touched. This is rarely optional and never inexpensive. Your IT services provider is your first line of defense here, but your insurance carrier may well want their own forensic person to validate the details.

This is where it’s so critical to know what commitments you made in your insurance application – and that you continue to adhere to those commitments.

Tenant communication becomes a reputational moment

Even if the incident didn’t involve tenant data, tenants expect transparency. Staff time shifts from operations to reassurance. In other words, you’ve got to let the people who rely on you know what happened – even if you feel like it doesn’t make you look good.

I’ve found words to live by – “bad news doesn’t get better with age” – and choosing to not disclose an incident could come back to bite you at some point in the future. Always disclose. State what happened, what you’ve done to remediate it, and what you’re doing to keep it from happening again.

System restoration disrupts everything else

Teams stop their normal work to rebuild systems, reissue credentials, and verify integrity. Productivity drops across the board, because your user community can’t access what isn’t available yet. Depending on the type of breach, it could be days before your systems, software, and automated processes are available again. (You’ll have an internal marketing need that develops here, too. Don’t forget to actively communicate with your people, even if you have to send them text messages to keep them apprised of what’s happening.)

These are operational costs, not IT costs.
And they land squarely on the CFO’s desk.

2. Insurance is no longer a safety net

Cyber liability carriers have changed the rules. They’re denying claims for basic control failures. They’re reducing payouts. They’re raising premiums at a pace that would make any finance team pause. They’re adding exclusions faster than most companies can keep up. Understanding cyber insurance claims and budget exposure is now as important as understanding the policy itself.

I worked with a firm last year that had a legitimate ransomware claim denied because they couldn’t prove multi‑factor authentication was enforced on every account. Not most accounts. Every account. The CFO had to walk into a board meeting and explain why the company was now self‑funding a six‑figure incident.

He told me afterward, “I thought insurance was the backstop. Turns out I was the backstop.”

That kind of denial isn’t an anomaly – it’s a pattern, and this material misrepresentation case study shows exactly how it unfolds when what you told your carrier doesn’t match what was actually in place.

Carriers are denying claims over single missing security controls

Carriers are enforcing technical requirements with zero flexibility. If you miss one control, the claim is at risk. For example, if your application states that you have multi-factor authentication (MFA) on every application, and they find an application that isn’t using MFA, your claim could be denied – even if that lack of MFA on that one application isn’t the cause of the breach.

Cyber insurance premiums are rising faster than most CFO budgets

Many CFOs are seeing double‑digit increases year over year, even without filing a claim. When insurance companies started offering cyber liability insurance, the world was a very different place – and claims were far less frequent. With the notion that more than 50% of American businesses WILL get hit this year, the costs to cover claims is rising exponentially. That means 1) higher premiums and 2) more scrutiny on submitted claims.

Policy exclusions are expanding, leaving organizations unknowingly exposed

Carriers are carving out entire categories of incidents, leaving organizations exposed without realizing it. It’s critical that you understand what your policy might be excluding so you can be proactive in your cyber defense posture. This is especially true for organizations operating under federal contracts or handling regulated data, where federal compliance gaps that trigger claim denials are often invisible until a carrier invokes them.

Insurance used to be the parachute.
Now it’s a checklist.
Miss one box and you’re falling without one.

3. The financial exposure is bigger than the technical failure

A compromised email account isn’t an IT problem. It’s a fraud risk. A wire‑transfer risk. A tenant‑trust risk. A regulatory risk. Every one of those has a dollar figure attached. And that exposure grows even larger when you factor in the hidden data risks that inflate financial exposure – particularly as everyday AI tools quietly move sensitive information outside your control.

I’ve seen a single compromised mailbox lead to $300,000 in attempted wire fraud. I’ve seen a vendor breach force a property group to notify more than a thousand tenants. I’ve seen a misconfigured system trigger a compliance review that consumed six weeks of staff time. I’ve seen ransomware delay a major lease signing because the building systems were offline.

Business email compromise triggers immediate wire fraud exposure

Attackers use compromised accounts to impersonate vendors, request wire changes, or send fraudulent invoices. The financial exposure is immediate. Business email compromise (BEC) is the catch-phrase that describes this particular type of incident – and you can get hit even if the compromise happens with one of your partners – not you.

Tenant trust becomes fragile

Even if tenant data wasn’t touched, the perception of risk affects renewals, satisfaction, and communication workload. Again, that’s why I advocate disclosure based on the formula I learned in “The One Minute Apology” by Ken Blanchard – here’s what happened, here is how it happened, and here’s what we’re doing to ensure it doesn’t happen again.

Regulatory compliance reviews consume staff time long after the breach

Compliance reviews, documentation requests, and follow‑up audits consume staff time long after the technical issue is resolved. And regulatory requirements vary by state as well as by business type. For example, HIPAA only impacts healthcare, while the NY SHIELD Act applies to companies with clients or customers in the state of New York.

Operational delays across leasing, accounting, and management are costly

When systems go down, leasing, maintenance, accounting, and management all feel the impact. The IT fix is the cheap part. The business fallout is the expensive part. Having a solid incident response plan is the most critical piece of your recovery – and that has to kick in immediately when you have or learn of a new incident.

4. Budgeting without cyber context is now irresponsible

A budget that doesn’t account for cyber risk is a budget built on assumptions. And assumptions are expensive. That’s exactly why more finance leaders are turning to executive-owned cybersecurity guardrails – structured boundaries that make cyber risk visible, measurable, and defensible in any budget conversation.

I sat with a CFO recently who said, “We’ve never had a major incident, so we’re probably fine.” When we mapped their environment, we found gaps everywhere.

Missing MFA on vendor accounts is one of the most exploited gaps

This is one of the most common failure points and one of the easiest for attackers to exploit. Ensure that any systems you connect to are following the appropriate security protocols. This same blind spot extends to the hidden financial costs of shadow IT – unauthorized tools and systems that bypass security controls entirely, often without finance ever knowing they exist.

No documented recovery plan means downtime costs double

Without a plan, recovery time doubles and costs rise with every hour of downtime. This is the next step following your incident response plan (IRP). Your IRP tells you what to do in the moment. Your recovery plan tells you what to do next.

Skipping access reviews leaves stale credentials as open attack vectors

Old accounts, former employees, and vendor credentials linger far longer than anyone realizes. It’s incumbent on the management team to direct the relevant internal teams to properly off-board everything from no-longer-used connected software systems to separated employees, and retired vendors. These processes must not only exist, they must be consistently owned and consistently applied.

Default email security settings are not sufficient protection

Most attacks still start with email. Default settings are not protection. Check your security settings on your email server, if you still have one in-house. If you’re using a cloud service like Microsoft 365 or Google Workspace (or whatever they rename it to next), ensure that you have gone through those security settings thoroughly.

Without monitoring on critical systems, breaches go undetected

If no one is watching, no one knows when something goes wrong. Establish an internal process – that is owned by a team – to test your critical systems on a regular basis, ensuring that orders flow, deposits land where they’re supposed to, invoices have the right remit-to address, etc. Proactive protection can save you thousands in hard money and in reputational equity.

Controls must continuously match your cyber insurance policy requirements

Controls must match the policy. Most organizations don’t check. If you say you’re doing X, you need to be consistently and continuously doing X. The fact that you were doing it when you said you were means nothing if you have a breach and you’re not doing it any longer.

Untrained staff remain the biggest human risk factor in cyber incidents

Human behavior is still the biggest risk factor. Training doesn’t have to be laborious. We have systems today that give your user community a quick test that you can give them monthly – a short video, or a quiz – something that keeps your people mindful of risks and acting as your first line of defense.

Third-party vendor oversight is now a critical CFO responsibility

Third‑party access is one of the fastest‑growing sources of incidents. Someone on your team needs the responsibility to stay on top of vendor compliance. That oversight gap is exactly what happens when your IT provider becomes a hidden liability – trusted by default, scrutinized by no one.

That CFO’s organization? Not fine at all.
They were lucky.
And luck is not a budgeting strategy.

Cyber risk is now a financial variable.
If you don’t account for it, it will account for itself — usually at the worst possible time.

5. The CFO is now the de facto risk officer

Whether they want the title or not, CFOs are now at the center of cyber risk because the consequences are financial, not technical. That shift toward CFO-led cyber governance and financial resilience is reshaping how organizations build and fund their entire security posture. As the finance leader of your organization, that means YOU are on the hook for more decisions with regard to cybersecurity than you ever thought you’d be.

CFOs control the budgets that determine cyber resilience

They decide what gets funded and what doesn’t. From IT services contracts to vendors to software acquisitions to personnel – the budget is the structure that guides decisions. The budget is also what takes a hit – potentially a catastrophic hit – if funding doesn’t land where it’s needed.

CFOs must own cyber insurance negotiations, not delegate them to IT

They negotiate premiums, understand exclusions, and handle claims. They also guide the application process, though in the past that has certainly involved either “answer yes to everything” input from the insurance seller or “pass it off to IT to answer” because it’s been “an IT issue.” It’s not an IT issue any longer. For CFOs ready to take that ownership seriously, a CFO’s blueprint for closing the IT skills gap offers a practical framework for translating that responsibility into concrete risk controls.

CFOs must present cyber risk exposure and recovery costs to ownership

They explain exposure, losses, and recovery timelines. You need to get buy-in for your decisions, particularly if you’ve decided funding additional services or security systems are necessary. You need to provide risk information backed by solid information on what losses could be incurred as well as what it would take to recover from different types of incidents – and the internal processes that need to be implemented to help protect the organization.

That starts with understanding the IT contract exclusions that shift risk to you – because what your provider isn’t covering is exactly what your insurance carrier will ask about.

CFOs absorb every hour of downtime cost during incident recovery

Every hour of downtime has a cost that rolls up to finance – and a cost that rolls up to the organization as a whole. “Reputational equity” is not just a buzzword. Especially in the age of online reviews and social media, a cyber scandal or a system outage can take a company to its knees, even after systems are back up again.

CFOs must evaluate vendor security posture, not just functional fit

They determine which partners reduce risk and which introduce it – and the CFO partner “scorecard” must have different metrics on it than any regular procurement scorecard. For example, while a piece of software might meet functional needs and pass the marketing department’s scorecard, the CFO needs to understand the security posture of that partner as well as normal financial details.

This risk compounds quickly when technology is acquired without finance’s full visibility – a dynamic that plays out in sharp relief when AI procurement gaps become finance’s liability.

This holds true for software vendors just like other partners – and why it is so critical that the finance team is trained to monitor credit card statements and expense reports for un-sanctioned software subscriptions or vendor payments.

CFOs must justify cyber spend as operational and financial protection

They connect cyber investments to operational stability and financial protection.

One CFO told me, “I used to think cybersecurity was an IT problem. Now I realize IT is just the first domino.”
That’s exactly right.

Cybersecurity is now a financial risk discipline, not an IT problem

Cybersecurity isn’t an IT project anymore.
It’s a financial risk discipline.

CFOs who treat it that way stay ahead of the curve. They budget smarter. They negotiate insurance better. They reduce exposure. They avoid surprises. They protect the organization’s credibility.

CFOs who don’t end up paying for the same incident twice — once in cash, and again in trust.

Frequently Asked Questions

Why should CFOs treat cybersecurity as a financial risk issue rather than an IT problem?

Cyber incidents have become budgeting events, and the CFO is the one left holding the bag when the numbers stop making sense. The financial impact is too direct and too immediate to treat cybersecurity as a technical expense. CFOs who treat it as a financial risk discipline budget smarter, negotiate insurance better, reduce exposure, avoid surprises, and protect the organization's credibility.

Can a cyber insurance claim be denied even if you have a policy in place?

Carriers are enforcing technical requirements with zero flexibility. If you miss one control, the claim is at risk. For example, if your application states that you have multi-factor authentication (MFA) on every application, and they find an application that isn't using MFA, your claim could be denied — even if that lack of MFA on that one application isn't the cause of the breach.

What are the real financial costs of a cyber incident beyond the initial technical response?

A compromised email account isn't an IT problem. It's a fraud risk. A wire-transfer risk. A tenant-trust risk. A regulatory risk. Every one of those has a dollar figure attached. These include emergency IT response, legal review, insurance documentation, forensic investigation, tenant communication, and system restoration — and they land squarely on the CFO's desk.

Written by: — President / CEO, IBSRE

Mike Mullin is the President & CEO of Integrated Business Systems (IBS) and ProtectMyIT, where he leads a mission to help small and mid-sized businesses in Northern New Jersey and the greater New York City area stay protected from IT disruptions, downtime, and cyber threats. With more than three decades of experience in technology and business operations - including roles at Yardi Systems, First Advantage/SafeRent, and GEAC Computers - Mike brings a well-rounded, practical perspective to IT strategy and risk management. As a trusted partner to SMB finance leaders and business owners, he focuses on translating complex technology challenges into real-world solutions that safeguard both operations and financial health.