Strategic Approaches to Security Budgeting: Essential Tips for Companies
Companies must reevaluate security budgeting frameworks to align with customer-centric metrics
Commentary
For over a decade, financial leaders have treated customer success as a strategic function rather than a dedicated department. Metrics such as net revenue retention, customer lifetime value, and trust capital economics have become standard in boardroom discussions. Fred Reichheld’s 1996 research at Bain demonstrated that B2B organizations with below-average net revenue retention face significant challenges, a reality universally acknowledged by executives. However, security practices have not adopted similar economic principles.
Security Budgeting Frameworks
Security budgets are traditionally calculated as a percentage of IT expenditures, which are themselves tied to operational efficiency targets. These efficiency goals are then linked to quarterly profit margins, leaving security funding detached from direct customer value creation. Investment justifications often focus on risk language that prioritizes organizational protection over broader economic impacts.
Measuring Breach Costs
Breach costs are typically measured through forensic expenses, notification requirements, regulatory penalties, and legal liabilities, with minimal consideration for cascading effects on customer relationships. The relational approach adopted by sales, marketing, and product teams over the past two decades demonstrates the value of customer-centric metrics. Security, however, continues to emphasize incident detection rates and incident response cost savings.
Case Studies of Cascading Impacts
A relational framework would instead assess the impact of security incidents across the entire customer relationship network. When a software provider experiences a data breach, the immediate financial burden falls on the vendor, while customers face long-term consequences such as eroded trust, extended sales cycles, and customer attrition that may not manifest for months.
CDK Global Incident
The CDK Global incident in June 2024 illustrates this dynamic. The SaaS company, which manages back-office systems for approximately 15,000 North American auto dealerships, suffered a ransomware attack that disrupted operations for nearly three weeks. Anderson Economic Group estimated that franchised dealers incurred $1.02 billion in direct losses, including 56,200 missed new vehicle sales. Dealerships reliant on digital systems operated manually during the outage, with costs entirely externalized from CDK’s financial statements.
Change Healthcare Attack
The Change Healthcare attack in February 2024, which forced UnitedHealth to report cyberattack-related impacts of $1.90 to $2.05 per share in 2024 adjusted earnings. The company also allocated over $9 billion in advance funding to sustain healthcare providers. Pharmacies struggled with prescription processing, and medical practices faced weeks without claims revenue. An April 2024 AMA survey revealed that 80% of physician practices experienced revenue losses from unpaid claims.
Critical Infrastructure Incidents
The economic harm was distributed across the healthcare ecosystem, highlighting the interconnected nature of modern infrastructure. Critical infrastructure incidents amplify these effects. The 2021 Colonial Pipeline ransomware attack cost the company $4.4 million in ransom, but the broader impact included fuel shortages and regional economic disruptions along the Eastern Seaboard. The 2021 Texas grid failure, attributed to extreme weather, resulted in $80 to $130 billion in damages despite an ERCOT operating budget under $300 million.
Customer Relationship Graph
These examples underscore how security incidents create cascading financial consequences that extend beyond the directly affected organization. Economists would classify these outcomes as negative externalities, but for CIOs, the critical perspective is customer economics. The customer’s experience directly influences revenue, and the customer’s customer’s experience impacts the former’s revenue, creating a two-step relationship.
Security Measurement Frameworks
The customer relationship graph functions as a critical asset, with security incidents posing a direct threat to its value. Current security measurement frameworks fail to account for this interconnected risk. CISA’s Systemically Important Entities designation implicitly acknowledges these externalities without explicitly using the term. IBM’s annual Cost of a Data Breach report focuses solely on direct organizational costs, neglecting the broader economic ripple effects.
New Metrics for Security Risk
The cyber insurance industry faces challenges in modeling correlated losses due to the lack of comprehensive frameworks for assessing ecosystem-wide impacts. A practical approach requires three key metrics: probability of disruption, mean time to recovery, and value at risk per unit time across the customer relationship graph, including downstream stakeholders. The third metric is particularly complex, as it demands an understanding of both customer and customer-of-customer economic dynamics.
Conclusion
Customer success teams track net revenue retention, finance departments analyze revenue concentration, but security teams often lack these insights. CIOs do not need to produce exact figures immediately but should begin integrating relationship-based risk assessments alongside traditional incident cost measurements. Forensic expenses, notification costs, fines, and downtime remain critical metrics for CISOs, but they must be supplemented with analyses of potential value at risk across the relationship graph.
This approach applies equally to organizations of all sizes, as demonstrated by a 1,200-employee SaaS company with two major enterprise clients, which faces higher relationship graph exposure than a 50,000-employee firm with a diversified customer base. At the next board meeting, security discussions should shift from “cost of a breach to us” to “value at risk across the relationship graph.” The former addresses an abstract question, while the latter aligns with the business’s operational reality.
Relationships have become the primary asset, and trust serves as the mechanism for long-term value creation. Customer outcomes must replace traditional security metrics as the primary performance indicator. The challenge for CIOs and CISOs is to define the initial measurement framework for their organization. What does the first iteration of this metric look like, and who within the team currently owns this responsibility? The transition requires cross-functional collaboration and a fundamental reevaluation of how security risk is quantified and communicated.
