Security Strategy, Plan, Budget

Companies have to rethink how they budget security  

Scissors cutting a $100 bill in half

COMMENTARY: Just about every chief financial officer (CFO) for at least a decade has considered customer success a discipline, not a department.

Net revenue retention (NRR), lifetime value, and the compound economics of trust capital are settled territory. Fred Reichheld made the math undeniable at Bain in 1996: A B2B company with NRR below benchmark faces some trouble, and everyone in the boardroom knows why.

The issue at hand: Security has not absorbed any of this.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

Look at how we budget. Security gets sized as a percentage of IT spend. IT spend gets sized against operational efficiency. Operational efficiency gets sized against quarterly margin. By the time the discussion reaches security, the budget has been anchored three steps away from anything resembling customer value. We then justify investment with risk language that treats the firm as the only entity that matters.

A breach gets sized against direct cost to the company: Forensics. Notification. Regulatory fines. Legal exposure. Maybe a stock price wobble. None of those numbers measure what actually breaks when an incident propagates through a customer relationship graph.

Sales, marketing, and product made the relational turn over the last two decades because the math worked better. Security still measures incidents detected and dollars saved on incident response.

What does the relational turn look like? It means measuring incident impact across the customer's relationship graph, not just inside the firm's perimeter. When a software company has an incident that exposes its customer's data, the breached company pays for forensics and notification. The customer pays in lost trust, deal cycle elongation, and churn that will not show up for two or three quarters. None of those second- and third-order costs hit the breached company's P&L directly. They show up later, in NRR compression and in the slow erosion of trust.

The CDK Global incident in June 2024 offers a clean illustration. SaaS provider CDK runs the back office software of roughly 15,000 car dealerships across North America. A ransomware attack took its systems offline for nearly three weeks. Anderson Economic Group estimated direct losses to franchised auto dealers at $1.02 billion over the outage window, including roughly 56,200 lost new vehicle sales. Dealerships ran on paper. None of those costs hit CDK's P&L. They propagated through the relationship graph from CDK to dealerships to car buyers. CDK was the leverage point that touched all of them at once.

The same pattern shows up at larger scale. The Change Healthcare attack in February 2024 led UnitedHealth to disclose roughly $1.90 to $2.05 per share in cyberattack impacts on full-year 2024 adjusted earnings, plus over $9 billion in advance funding to keep providers solvent.

Pharmacies could not process prescriptions, and medical practices went weeks without claims revenue. An April 2024 AMA survey found 80% of physician practices lost revenue from unpaid claims. The harm was distributed across the healthcare delivery system.

Critical infrastructure represents the same logic run to its limit. Colonial Pipeline paid roughly $4.4 million in ransom in 2021; the Eastern Seaboard paid in fuel shortages and regional economic friction. The Texas grid failure cost between $80 and $130 billion in damage, against an ERCOT operating budget under $300 million. It’s the same propagation. What changes at the limit: the customer's customer is the public, and the harm does not come back as a transaction the breached firm can see. The wrong-denominator problem gets worse the further the graph extends.

An economist would call this a negative externality. The framing that matters for CIOs is not the policy framing. It’s the customer economics framing. The customer's outcome is our revenue. Our customer's customer's outcome is our customer's revenue, and that’s our revenue at one degree of separation. The relationship graph becomes the asset. Security incidents damage the asset. We do not currently measure security in those terms.

It's a real measurement gap. CISA's Systemically Important Entities designation represents an implicit externality argument without using the word. IBM's annual Cost of a Data Breach report measures direct cost to the firm and stops there. The cyber insurance market struggles with correlated losses partly because nobody can model what happens when an incident propagates through interconnected ecosystems.

A working framework starts with three numbers: Probability-of-disruption. Mean-time-to-recover. Value at risk per-unit-time across the customer relationship graph, including downstream nodes. The third is the hard one because it requires knowing the customer's economics, and at least the shape of the customer's customer's economics. Customer success knows NRR. Finance knows revenue concentration. Security typically has neither view. This represents the gap the framework would force the firm to close.

CIO’s don’t need to produce the number immediately. They need to start asking the question, additively, alongside the incident-cost measurement already in place. Forensics, notification, fines, and downtime are still real numbers a CISO owns; the relationship-graph denominator sits next to them, not instead.

The logic does not weaken at smaller scale. A 1,200-person SaaS company with two large enterprise customers has more concentrated relationship-graph exposure than a 50,000-person firm with a long tail. At the next board meeting, frame security in terms of customer impact across the relationship graph. When sitting with the CFO every quarter, swap the slide that totals "cost of a breach to us" for one that estimates "value at risk across the relationship graph." The first answers a question no one in the business really asks. The second answers the question the business already lives by.

Relationships are the asset. Trust has become the compound mechanism. Customer outcomes are the metric. The disciplines that made the relational turn outperformed the ones that did not.

The open question for CIOs and CISOs: What does the first version of that number look like in our environment, and who on our team owns it today?

Alan LeFort, chief executive officer, StrongestLayer

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds