How to Present Security Findings to a CFO or Board

TU0LZJQA1-U0B3VV05084-10fa14008046-512
Diana Wright Publication date: 2 September, 2026
Education

A security assessment lands on a CFO’s desk with 47 findings, a spider graph, and a recommendation to remediate per best practice. The CFO asks one question: what does this cost me if I ignore it? If you are the advisor in the room and cannot answer with a number, the meeting produces a polite nod and no budget, and the findings join last year’s findings in a drawer. Plenty has been written on why boards need business framing; this article is about the mechanics of producing the number, because that is the part nobody shows.

The method below is a translation procedure a vCISO or MSP security lead can run per client in an afternoon: posture score to top risks, top risks to financial exposure ranges, ranges to a costed ask. It borrows its structure from formal risk quantification and simplifies it honestly for the scale of a 60-person client rather than a Fortune 500 board pack, because that is the room where most of these conversations actually happen.

Start With the Security Posture Score

The translation starts from the outputs a decent assessment already produces: a posture score and a risk register. The posture score is your opening exhibit, since executives read a 5.2 out of 10 instantly, especially next to a trend line and a peer comparison. What the score cannot do is justify spending, because no CFO writes a check to move an abstract index. The score frames the conversation; the register funds it.

From the register, take the top three risks and no more. Three is the number that keeps every subsequent step honest: each risk is about to get frequency and impact estimates that need defending, and the discipline of quantifying three risks well beats a spreadsheet of 30 guesses. The rest of the register stays in the appendix, where it reassures the reader that rigor exists without asking them to price it.

How to Turn Security Risks Into Financial Ranges

The quantification model worth borrowing from is Factor Analysis of Information Risk (FAIR), the open standard for expressing risk in financial terms: risk is loss event frequency multiplied by loss magnitude, with every input expressed as a range rather than a point estimate. Full FAIR practice involves calibrated estimation and Monte Carlo simulation, which is more machinery than an SMB conversation needs. The FAIR-shaped shortcut that survives contact with a CFO keeps the structure and drops the simulation: estimate how often the loss event plausibly happens, estimate what it plausibly costs when it does, multiply the ends of the ranges, and present the spread with its confidence stated.

The impact inputs are where most translation attempts lose credibility, because they reach for the famous number: the $4.88 million global average breach cost from IBM’s 2024 report. That figure describes large-enterprise incidents, and a CFO at a 60-person company recognizes immediately that it does not describe their world, at which point the whole model loses the room. SMB-calibrated sources exist and are more persuasive precisely because they are smaller. Insurance claims data from small and medium-sized enterprises (SMEs) shows what incidents actually cost mid-market companies, with over 10,000 SME cyber claims in the underlying dataset, and survey data puts the mean SME incident cost at $369,000 with medians far lower. That tells you the honest shape of the distribution: most incidents cost five figures, a meaningful tail costs six or seven. Ranges built from claims data at the client’s own scale read as homework. The enterprise average reads as a sales tactic.

For frequency, anchor on the base rate before adjusting for the client: Hiscox’s 2025 readiness survey found 59% of SMEs experienced a cyberattack in the prior twelve months, and a third of those attacked faced regulatory consequences on top of the direct costs. Then move the estimate for this client’s specific posture: untested backups move a ransomware estimate up, enforced multifactor authentication (MFA) moves an account-takeover estimate down. The adjustment is judgment, which is fine, because the judgment is now visible and arguable instead of hidden inside an adjective like “high risk.”

A Cyber Risk Quantification Example for a Small Business

Here is the method run end to end for an illustrative client: a 60-person professional services firm with roughly $9 million in revenue and a posture score of 5.2. Its register’s top three risks are ransomware with untested backups, business email compromise with partial MFA coverage, and an unvetted file-sharing vendor holding client data. The numbers are constructed for the example, with each input’s source type labeled, because the point is the arithmetic a reader can rerun with their own client’s inputs.

StepRisk 1: ransomwareRisk 2: email compromiseRisk 3: vendor exposure
Annual likelihood (estimated from base rates + this client’s controls)5% to 10%10% to 20%3% to 8%
Impact if it happens (claims-data scale + client’s downtime cost)$90K to $320K$25K to $110K$40K to $180K
Annualized exposure (likelihood × impact)$4.5K to $32K$2.5K to $22K$1.2K to $14K

The downtime arithmetic inside the impact column is worth showing to the client, because it is where the range stops being abstract. This firm bills roughly $35,000 per working day, so the difference between a two-day disruption with tested backups and a 10-day disruption without them is itself a six-figure spread, before recovery costs and notification obligations are counted. Summed across the three risks, the client’s modeled exposure runs roughly $8,000 to $68,000 per year at moderate confidence.

The ask then prices against the exposure it removes. If a $2,400 per month engagement covering tested backup verification, full MFA rollout, and a vendor assessment program credibly moves each likelihood toward the bottom of its range, the modeled exposure drops by more than half. The CFO is now looking at a decision shaped like every other decision they make: $28,800 a year against a modeled reduction of tens of thousands in expected loss, plus the tail scenarios that do not fit in an expected-value model. It is the tail that usually closes the conversation, because the top of the ransomware impact range is a number the firm would feel.

Presented this way, the conversation also survives the follow-up questions, because every input has a stated source: a base rate, a claims-data range, or a labeled judgment call the CFO is welcome to move. If they think the likelihood estimate is too high, the model reruns in the meeting with their number, and the ask usually survives the adjustment. A model the client can argue with is a model the client ends up owning, and owning the model also means owning its limits, which is the part to get ahead of.

How to Handle the False-Precision Objection

Quantification has serious critics, and the strongest version of their argument should live inside your presentation rather than ambushing it. Peer-reviewed work has called cyber risk management “an illusion of a risk-based approach”, numeric on the surface and judgment-driven underneath, and practitioners inside the quantification field warn that presenting a figure like $3.47 million implies false precision that undermines credibility, recommending ranges at stated confidence instead. The defenders of quantification, notably Douglas Hubbard’s calibration school, land in the same place from the other direction: their case is that ranges and explicit probabilities outperform the high-medium-low heat maps they replace, which they argue can perform no better than chance.

So concede the critique openly. The ranges are estimates, the tails are wider than any model shows, and the arithmetic is a structured way of making judgment visible rather than a measurement of the future. Then make the counterpoint that closes the loop: the alternative to an imperfect range is an unpriced fear, and unpriced fears lose budget conversations to line items that arrive priced. This framing also matches how your clients already think about the spend, since 40% of managed security customers measure ROI as reduced incidents, and almost none of them believe their budget has slack, with only 7% of SMBs calling their security budget sufficient. A costed ask with a visible model is built for exactly that room.

How to Make Executive Risk Reporting Repeatable

Run once, this method wins a budget conversation. Run quarterly, it changes the relationship, because the next QBR opens with the same model updated: posture score moved from 5.2 to 6.4, modeled exposure down from last quarter, here is the delta the spend bought, and here is the next priced decision. The format for structuring the executive report around that update already exists; the quantification method is what fills it with numbers a CFO trusts.

The practical constraint is effort. Hand-built, the model above costs an afternoon per client per quarter, which is manageable at five clients and impossible at 40. This is where the method either gets systematized or gets abandoned, and it is the argument for platforms that maintain the posture score, the risk register, and executive-ready risk reporting as living artifacts of delivery rather than quarterly reconstruction projects. Cynomi’s platform pairs those with a business impact analysis capability that turns posture data into the budget conversation this method builds by hand, which is the same translation running continuously instead of the night before the QBR. One partner put the outcome plainly: executives look at the output and say they understand where security lies in their company and why it deserves the discussion.

Take one client, three risks, and an afternoon, and run the method before the next renewal conversation. The first time a CFO responds to a finding by asking which option you would fund, you will know the translation landed. And when the afternoon per client stops scaling, that is the complexity Cynomi carries for you, so you can lead the conversation and take the credit.