Security Budget in Tiers
Security Budget in Tiers
The pattern that the Enterprise Information Security Reddit Practitioner Research 2026-08-03 corpus converges on as the way security program budgets actually survive a CFO conversation: present the ask in three tiers with a marginal-value answer at every boundary, and track revenue security cleared as the single durable justification line.
The reframe that unlocks the CFO conversation
The r/AskNetsec top comment — u/Street-Mycologist670 — reframing the CFO's "if we cut this in half, what breaks?":
"Your CFO didn't ask you a counterfactual question. 'If we cut this in half, what breaks' is a marginal value question and it is answerable. You lost that room because you reached for a risk argument when he asked an operations one. […] Build the ask in tiers. Tier 1 is what keeps you legal and contractually compliant, tier 2 is what keeps the lights on, tier 3 is what reduces exposure faster than it accumulates. […] Track revenue that security cleared — deals where a security review, questionnaire, or certification was on the critical path. In my experience this is the single line that has moved budgets, more than any exposure chart."
The three tiers
| Tier | What it funds | What breaks if cut |
|---|---|---|
| 1. Legal / contractual | Regulatory obligations (SOX, HIPAA, GDPR, PCI-DSS, NIS2), contractual security requirements (Compliance Cascade), cyber-insurance policy conditions | Legal exposure, contract breach, loss of insurability |
| 2. Keep-the-lights-on | Baseline controls (asset inventory, patching, IAM, EDR, logging, MFA, backup/recovery, incident response retainer) | Any incident becomes a crisis; no evidence for auditors; recovery time balloons |
| 3. Reduces exposure faster than it accumulates | Above-baseline programs (threat intel, purple team, red team, security-champions, deception, application-security engineering, AI-security governance) | Exposure grows; the org drifts into a shape that makes tier-1 or tier-2 harder over time |
Each tier answers "what breaks if we cut this?" with a concrete, non-hyperbolic answer. That is what wins the room.
The corroborating panel view — revenue is the argument that lands
From the CISO Series AMA (↑219), asked what quantitative argument works:
"Honestly? Revenue. […] 'We need this investment to prevent this threat or avoid this outcome, but it will also allow us to sell into this market, or pursue these customers that either can't do business with us or left us because we couldn't provide the necessary assurances.'" — u/AuditBoard_Rich
Second lever — CFO personal accountability:
"Know what CFOs hate more than spending money? Signing off on risk personally. Your conversation will quickly change from the cut-in-half question on cost to cut-in-half on time to deliver." — u/TickleMyBurger
Third — the compliance frame that also works:
"Compliance started hitting our industry really hard and increasing our security made it possible for us to bid and hold high dollar contracts we couldn't before." — u/Ok-Hunt3000 [↑26]
Metrics that survive scrutiny (the corpus's list)
- CISA-KEV-scoped exposure on internet-facing assets — not CVSS-weighted; CISA-KEV is what matters
- Blast radius from one compromised standard endpoint — quantifiable, testable
- Recurrence rate by finding class — measures whether the program actually closes findings vs. papers over them
- Coverage honesty — "we're 94% patched on the 60% we know about" is a more truthful metric than 94% patched
- Purple-team detection deltas — real detection improvement per program change
Metrics that die in the room
- MTTR — auditors like it; CFOs don't buy it
- Raw vuln counts — reads as inflation to a CFO
- Phishing click rate alone — reads as vanity; a program's response-rate to the click is what matters
Instrumenting the revenue-cleared line
The single most important operational addition to a security program per this corpus: wire deal reviews into the security team's dashboard, tagged with:
- Deal amount
- Whether a security review, questionnaire, or certification was on the critical path
- Whether the deal would have been won without the program's evidence
- Which specific control(s) evidenced
This produces a revenue-cleared-per-quarter number that is the durable budget-defense line. It's not a metric the security team owns alone — it requires the sales team to log the security-gate crossings. That instrumentation itself is a program deliverable.
The one contrarian view worth engaging
"Maybe the CFO is right. Cyber insurance and losses will be less than your security spend. In which case you should cut things in the program." — CISO Series AMA panel
The tiered-ask + revenue-cleared frame is what makes that a testable claim rather than an argument. Tier-1 spend is legally non-optional. Tier-2 spend has a defined "the lights go out at this level" threshold. Tier-3 spend is where the "cyber insurance would cost less" test can actually be made — honestly. If a specific tier-3 investment costs more than the insurance-priced expected loss, the CISO should be the one making that trade, not the CFO discovering it.
Cross-links
- Security Obligation Propagates Via Revenue and Contract — the synthesis this concept is the CFO-facing operationalization of.
- Compliance Cascade — the mechanism generating tier-1 obligations.
- Security Questionnaire Fatigue — the operational cost of the revenue-cleared line before this pattern is in place.
- Audit Evidence Bar — the auditor-facing corollary of the tiered ask (evidence-per-tier).
Follow-ups
- Watch for a Fortune 500 CISO to publish a revenue-cleared dashboard. This is a differentiating artifact.
- Watch for cyber-insurance underwriters to publish premium reductions priced on the tier-1-clear evidence the concept produces.
- Watch for a CFO-side artifact (finance-team-facing) that endorses the three-tier ask — would harden the pattern from CISO-community lore to a jointly-defended budget shape.