How do you convince a business to invest in security when it competes with other priorities?
This is the core of a senior security role, and the answer must not be "because it is important".
- Speak in risk, not in threats. Risk is likelihood times impact, expressed in business terms: "a ransomware event would halt order processing for an estimated five days, which is roughly X in lost revenue plus recovery cost". That is a number a finance director can weigh.
- Use evidence they cannot dismiss. Penetration test findings, a phishing simulation click rate, an audit finding, or a peer organisation's public breach. Abstract threats are easy to defer; a report showing your own domain admin was compromised in a test is not.
- Offer options with costs, not a single demand. A tiered proposal lets them choose the level of risk to accept, which is genuinely their decision to make.
- Tie it to something they already want — a customer contract requiring ISO 27001, a regulatory deadline, or cyber insurance conditions. Security funded as a business enabler moves faster than security funded as insurance.
Note: Being able to say you accepted a decision not to fund something, documented the risk acceptance, and moved on shows maturity. Security people who treat every rejection as a battle lose influence.





