There is a question every security leader gets asked, usually in a quarterly review, that most of them cannot answer well: is the money we are spending on security worth it?
Watch how people handle it. The auditor answers by pointing at the control. Yes, the firewall is present. Yes, the MFA is enforced. Yes, the training is completed. That answers a different question. It answers "is the control in place," not "is the control worth paying for." Those are not the same question, and conflating them is why so much security budget survives review on faith.
Most security leadership today stops at the compliance report, the gap list, the checkbox roadmap. The board nods, the funds flow, and nobody ever hears the number that actually matters: the dollars at risk. That is audit-as-a-service wearing a CISO title.
A real vCISO operates a P&L
A real vCISO treats security like a business unit with a P&L. On one side you put the cost of the function: controls, tools, headcount. On the other side you put expected loss avoided. Both sides are quantified, not hand-waved. The question that drives every decision becomes: are we spending defensibly?
This is where FAIR comes in, and it is worth being precise about what it is. FAIR, the Factor Analysis of Information Risk, is not another compliance framework. It is a way of expressing risk in the same unit of measure a CFO already thinks in. It models threat event frequency, loss magnitude, and the uncertainty around both, then runs Monte Carlo simulation to turn "we might get hacked someday" into a dollar figure with a distribution. Now you have something a board can actually hold, compare, and challenge. Compliance frameworks tell you what to check. FAIR tells you what to decide. If you want the mechanics, our deep-dive on FAIR Monte Carlo simulation walks through it, and why you need FAIR or equivalent models covers the case for it.
What this flips in practice
I have seen what this flips. In a recent engagement with a mid-market healthcare organization, the starting picture was not subtle. The client was carrying an estimated $24.7 million in annualized cyber loss exposure, roughly twelve times its stated $1 million risk tolerance. The dominant drivers were PHI data breaches and ransomware. That is the kind of gap that usually gets described with words like "material" and then ignored because nobody can price it. We put a price on it.
Then we went to work on the control side. About $1.9 million of targeted, re-scoped controls cut that exposure to $11.3 million. The math is worth sitting with. That is $13.4 million in annualized risk avoidance against a $1.9 million investment. A 611 percent return with payback somewhere around two months.
That is a P&L, not a compliance report. The board did not fund out of fear. They funded because the economics were undeniable, and funding something because you can prove it is worth it is a very different conversation from funding something because everyone is scared not to.
The point is not to stop buying controls
The point of all this is not that controls are overdone and we should stop buying them. The point is that security has a value argument to make, in the language the people who hold the money actually speak, and the leaders who cannot make it are running audit-as-a-service with a fancier title.
If you are carrying a security budget, you should be able to defend it the same way you would defend any other line item. If you cannot, that is not a fear problem. That is a P&L problem.
New to this? Our guide on quantifying cyber risk with the FAIR model is a good place to start, and if you want the concrete process for building a defensible budget, the 30-day security road-mapping sprint shows how to do it in a month. For the broader argument about why security shows value by making spend defensible, see that follow-up.
Make security a documented line item
See how defensible your security budget really is
A real vCISO shows you expected loss in dollars, not a control checklist. The first analytical pass is step one of proving the spend.
Talk to a vCISO →The leaders who can show a board a number have stopped begging and started operating. That's the whole difference.