Certified Information Security Manager (CISM)Information Security GovernanceMedium

A CISO is presenting the annual information security strategy to the board of directors. During the presentation, a board member questions the return on investment (ROI) of a significant security budget increase, stating that security is perceived as a cost center. Which of the following is the MOST effective way for the CISO to address this concern and demonstrate business value?

  1. AHighlight the potential financial penalties and reputational damage from a major data breach.
  2. BPresent a detailed list of all security incidents prevented and vulnerabilities patched in the past year.
  3. CBenchmark the organization's security spending against industry averages for similar companies.
  4. DQuantify security's contribution to enabling new business opportunities and reducing business risk.
Show answer & explanation

Correct answer: D. Quantify security's contribution to enabling new business opportunities and reducing business risk.

To counter the perception of security as a cost center, the CISO must articulate its value in business terms. Quantifying security's role in enabling new revenue streams (e.g., secure cloud adoption, compliant market entry) and reducing quantifiable business risks (e.g., avoiding fines, protecting intellectual property) directly demonstrates its strategic business value and ROI.

Why the other options are wrong

  • A. Highlighting negative consequences emphasizes fear, uncertainty, and doubt (FUD), which may not be as effective as demonstrating positive business value and ROI.
  • B. While important, demonstrating incidents prevented focuses on cost avoidance rather than proactive business enablement or ROI.
  • C. Benchmarking provides context but doesn't inherently demonstrate the organization's specific ROI or business value.

Communicating Security Business Value

Articulating the benefits of information security initiatives in terms that resonate with business leadership, focusing on how security enables business objectives, reduces risk, and contributes to strategic goals and financial performance.

  • Translates technical security to business language.
  • Focuses on enablement, not just prevention.
  • Quantifies impact on revenue, risk, and reputation.

Memory trick: Show them the money, not just the locks.

More Information Security Governance questions