The Threat You Are Already Inside

The Breach Is Not an IT Incident. It Is a Balance Sheet Event the CFO Cannot Yet See.

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
May 2026 · 6 min read
Cover image for Part 4 of The Threat You Are Already Inside series by Garzon Cyber Solutions, showing the title The Breach Is Not an IT Incident with key CFO cybersecurity statistics on breach costs, risk quantification, and insurance denial rates

The Threat You Are Already Inside: Part 4 of 5

IBM’s 2025 Cost of a Data Breach report puts the global average breach cost at £3.9 million per incident. In the United States, that figure reaches £8.2 million, up from £7.5 million the year before. These are not IT costs. They are financial events that flow through every line item the CFO is responsible for: legal costs, insurance costs, regulatory penalties, operational downtime, reputational write-downs, and customer attrition.

Yet in most organisations, the CFO receives cybersecurity information the same way the board does: filtered, quarterly, framed in technical language, and disconnected from the financial architecture they manage. The CISO reports to the CTO. The CTO reports to the board. The CFO sees a risk register entry labelled “cyber” and a budget line labelled “security tools.” What they do not see is the actual financial exposure sitting underneath those labels.

That disconnect is no longer a governance inconvenience. Under NIS2, DORA, and the SEC’s cybersecurity disclosure rules, it is a regulatory liability.

Cybersecurity is now a financial reporting obligation.

In December 2023, the SEC’s cybersecurity disclosure rules took effect. In the first twelve months, 55 cybersecurity incidents were reported on Form 8-K filings. Only 14% of those filings confirmed the incident was material, according to analysis by Greenberg Traurig and NYU. The remaining 86% were filed as a precaution because the reporting organisation could not determine materiality with confidence.

That uncertainty is the CFO’s problem. Materiality is a financial concept. Determining whether a cybersecurity incident meets the threshold for disclosure requires the same judgment that the CFO applies to every other material event: revenue impact, litigation exposure, operational disruption, and shareholder consequences. If the finance function cannot assess cybersecurity events through that lens, the organisation is either over-reporting (creating market anxiety) or under-reporting (creating enforcement risk).

The SEC made this explicit in 2024 when it brought enforcement actions against four companies for misleading cybersecurity disclosures. In the same year, it penalised RR Donnelley for inadequate internal accounting controls over its IT systems, classifying its technology infrastructure as a financial asset subject to the same governance standards as any other balance sheet item.

In Europe, NIS2 introduces penalties of up to €10 million or 2% of an essential entity’s global annual turnover per infringement. DORA imposes a 1% penalty on average daily worldwide turnover for ICT providers. Both frameworks include personal liability provisions for management bodies under Article 20 of NIS2. The CFO who treats these as somebody else’s problem is personally exposed to consequences they may not have priced in.

Most organisations cannot quantify their own exposure.

The FAIR Institute’s 2025 research found that only 31% of organisations primarily use a quantitative, financially expressed approach to measuring cyber risk. The rest rely on qualitative heat maps, colour-coded risk matrices, and ordinal scoring systems that tell the CFO nothing actionable about financial exposure.

This matters because the CFO’s entire function operates in financial terms. Every other category of enterprise risk, credit risk, market risk, operational risk, and liquidity risk, is measured, modelled, and reported in pounds, euros, or dollars. Cybersecurity remains the one domain where the risk register says “high” instead of “£4.2 million.”

Among organisations that have adopted quantitative risk models, the results are measurable. The FAIR Institute reports that 90% of adopters see improved security posture and clearer decision-making. 30% of Fortune 100 companies now use the FAIR model. The cyber risk quantification market itself is projected to grow from £3 billion in 2025 to £17.6 billion by 2034, according to Market.us. The direction is clear. The pace of adoption is the concern.

PwC’s 2025 Global Digital Trust Insights survey found that only 2% of organisations have implemented firm-wide cyber resilience measures. 77% expect their cybersecurity budget to increase next year. The spending is rising. The ability to connect that spending to measurable financial outcomes is not.

Infographic summarising eight key statistics from Part 4 of The Threat You Are Already Inside series by Garzon Cyber Solutions: breach costs, risk quantification gap, cyber insurance denial rates, downtime costs, and NIS2 regulatory penalties
The CFO’s cybersecurity blind spot, in eight numbers. Sources: IBM 2025, FAIR Institute 2025, Coalition 2024, N-able/ITIC 2024.

Cyber insurance is not the safety net the CFO assumes it is.

The global cyber insurance market is projected to reach £178 billion by 2034, up from £21 billion today. Premiums are forecast to rise 15 to 20% over the next twelve months, according to Woodruff Sawyer’s 2025 market outlook. For the CFO, these are significant line items. They should also be concerning ones.

Over 40% of businesses that file a cyber insurance claim receive no payout. Coalition’s 2024 claims data found that 82% of denied claims involved organisations without multi-factor authentication in place. The denial is not arbitrary. Insurers are tightening underwriting requirements, and the gap between what the CFO believes is covered and what the policy actually pays out is widening.

The implication is straightforward. The CFO cannot treat cyber insurance as a substitute for security investment. The premium buys conditional coverage. The conditions are technical. If the organisation’s security posture does not meet the insurer’s baseline requirements, the policy is a cost without a corresponding benefit.

US cyber insurance direct written premiums reached £7.3 billion in 2024, a 7% decrease from 2023, according to the NAIC. That decline reflects insurers becoming more selective, not less concerned. The market is repricing risk. The CFO needs to understand what that repricing means for their organisation’s specific coverage position.

The cost of downtime is measurable, material, and largely unmodelled.

N-able and ITIC’s 2024 research found that 90% of mid to large enterprises report single-hour downtime costs exceeding £240,000. 40% report costs exceeding £800,000 per hour. The average ransomware attack now results in 23 to 24 days of operational disruption, according to IBM’s 2024 data.

Run those numbers through a simple financial model. An organisation experiencing £400,000 per hour in downtime costs, hit by a ransomware event that caused 10 days of partial disruption, is facing a direct operational impact measured in the tens of millions before legal, regulatory, and reputational costs are factored in.

Academic research published in Finance Research Letters in 2024 found that publicly traded firms experience an average abnormal stock return of -1.3 % following a disclosed breach. Healthcare firms averaged a negative 5.21%. The study found that negative cumulative abnormal returns persisted for up to 250 trading days after disclosure. That is not a temporary event. It is a sustained destruction of shareholder value that the CFO will be asked to explain.

TrustCloud’s 2025 analysis estimates that 60% of the financial impact from breaches goes unreported to shareholders. The CFO is responsible for accurate financial reporting. If the full impact of a cyber event is not captured in the financial statements, the disclosure risk compounds the operational one.

What needs to change

The CFO’s relationship with cybersecurity needs to move from budget approver to risk owner. Three specific shifts make this operational.

First, adopt quantitative cyber risk measurement. The FAIR model, or an equivalent framework that expresses cyber exposure in financial terms, is one that the CFO already works with. Stop accepting “high, medium, low” as a risk assessment for a category that can generate eight-figure losses. The 31% of organisations already doing this have better security outcomes and clearer capital allocation decisions.

Second, audit the cyber insurance position. Not the premium amount, but the actual coverage. What are the exclusion clauses? What security controls does the policy require? What is the gap between the insured amount and the realistic cost of a major incident? If the answer to any of these questions is “I do not know,” the policy is not providing the protection it appears to on the balance sheet.

Third, build cyber exposure into financial reporting and planning. The SEC’s disclosure rules, NIS2’s penalty framework, and DORA’s operational resilience requirements all assume that the organisation can assess the financial materiality of a cybersecurity event in real time. If the finance function lacks the data, the models, or the relationship with the security function to make that assessment, the organisation is exposed to both the incident itself and the regulatory consequences of failing to report it accurately.

Cybersecurity Ventures projects global cybercrime costs at £7.3 trillion in 2024, rising to £11 trillion by 2028. The CFO does not need to understand the technical mechanics of a ransomware attack. They need to understand what it costs when one lands, what the insurance actually covers, what the regulatory penalties look like, and whether the organisation can demonstrate that it took reasonable steps to prevent it.

The breach is not an IT incident. It is a balance sheet event. The CFO who cannot see it coming is the one who will be asked to explain it afterwards.

This is Part 4 of “The Threat You Are Already Inside,” a five-part series examining how cybersecurity risk intersects with every level of the organisation. Part 5 examines what the frontline workforce needs to understand about their role in organisational security posture.

Garzon Cyber Solutions provides cybersecurity advisory services, compliance architecture, and specialist recruitment for organisations building integrated security capabilities.

Where does this sit on your own risk register?

A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.

Start the Conversation →
#CyberSecurity#ThreatIntelligence#Leadership#Governance#RiskManagement#GarzonCyberSolutions