Why Security Teams Keep Losing Budget Fights
Security teams spend their days behind screens full of scanner alerts, CVEs, CVSS scores, critical 10s. When they need budget, they take that same vocabulary into the executive suite. Executives nod, then say no. The reason: boards run on debt and risk by design. Net 90s, net 120s, three-year outstanding invoices are just business. Security coming in with “we have risk” lands the same way. The executives already knew that. They take risks every day. That’s the job.
Risk Means Something Different to Every Stakeholder
Walt Powell, field CISO at CDW, said this at a late-night Milwaukee session: risks are what you stand to lose if things go bad. Boards deal with compliance risk, operational risk, legal risk, and supply chain risk simultaneously. These overlap but are not identical. Only 1 to 2% of board members know what a CVE is. Their job is managing investor ROI. When security uses risk without specifying which kind, every person in the room hears a different thing.
Reputational Risk Is Not the Argument You Think It Is
CrowdStrike crashed global transportation, stranded millions, and was up 16% on the year as of McDaniel’s talk. The average company takes 50 days to recover stock price after a major incident. SolarWinds, Uber, and CircleCI all still exist, still profitable. Going to a board with reputational risk as your budget argument fails when the counterexamples are in yesterday’s stock price. The one caveat: some industries (Kaspersky, for example) face structural reputational damage. For most enterprises, the argument doesn’t hold.
Technical Debt Was Always a Metaphor
Ward Cunningham coined “technical debt” around 2002 for a financial services audience who literally understood credit. He needed to explain why shipping unfinished code would cost more to clean up than it saved in time. Perfect analogy in that room. Then it spread without the context. McDaniel asked four people at a conference dinner what technical debt meant and got four different answers. The GSA definition came from a blog post. Every time security teams say “we have technical debt,” leadership hears a phrase, not a measurement.
The Balanced Scorecard for Cyber Resilience: Promise and Limits
The Balanced Scorecard for Cyber Resilience, built on Kaplan and Norton’s 1993 framework and only recently applied to security, reduces board reporting to three things: a stoplight indicator, the biggest risk window, and an action plan with a completion percentage. Healthy boards, per HBR research, ask four questions: what is our security risk, what are we doing, can we recover, and can we still deliver. But the scorecard cannot be copied between companies, which maddens board members juggling multiple organizations.
Translating Vulnerabilities Into Business Language
The pitch that works: “We’re vulnerable to something that will cost us a million dollars a day when it hits. Give me $25,000 and I can fix it in a month.” That framing gives executives a story they can carry into the boardroom. The Uber breach started with $20 of dark web credentials, MFA flooding, and PowerShell scripts packed with plaintext passwords for everything. That story lands harder than a CVSS 10. Stop screaming about debt and risk. Translate the exposure into money lost, then show what fixing it costs.
Q&A
How do you put a dollar value on a security risk? Use incident stories from similar organizations and work with your CFO on what idle developers or a downed production system actually costs your company per hour. ▶ Watch (40:24)
If you know your per-minute downtime cost, how do you connect it to a specific security risk? Walk through a scenario like Uber’s credential-stuffed PowerShell scripts, showing the chain from vulnerability to outage, then price the fix against the daily loss figure. ▶ Watch (42:15)
Notable Quotes
risks are what you’re set to lose if things go bad that’s what a risk is now Dwayne McDaniel · ▶ Watch (6:44)
reputational risk is a myth we told ourselves and we got to get it out of our heads Dwayne McDaniel · ▶ Watch (11:22)
that’s what I’m saying go talk to your CFO and like hey if this thing went away Dwayne McDaniel · ▶ Watch (41:43)
Key Takeaways
- Boards already accept debt and risk as normal; framing a CVE as “risk” won’t move budget.
- Translate vulnerabilities into dollars lost per day, then show the cost of fixing it.
- Build relationships outside your department before a crisis forces the conversation in their language.
About the Speaker(s)
Dwayne McDaniel has been a Developer Advocate since 2016 and active in tech communities since 2005. He has given talks at over a hundred events worldwide, including institutions like MIT.