What CFOs Wish CISOs Knew
Hillstrong Group Security ·

Roger Hill
How to Defend OT Security Budgets in a Recession (Without Sounding Like an Alarmist)
Let’s get one thing straight — nobody in the boardroom is moved by a list of unpatched CVEs anymore.
Not in this economy.
In the last 90 days alone, I’ve seen three global manufacturers slash their cybersecurity budgets mid-year. Two of them had “industry-leading” OT security programs. All three had CISOs who failed to tie security investment to business outcomes. Not threats. Not vulnerabilities. Not frameworks. Outcomes.
And here’s the part no one wants to say out loud: It’s not the CFO’s fault.
The Disconnect We Don’t Talk About
Most OT cybersecurity leaders still think the key to board-level alignment is “learning to speak finance.”
But knowing how to say “return on investment” doesn’t mean you know how to earn it.
The real challenge is this: We’re trying to justify business resilience with technical language. We show the firewall rules, the segmentation maps, the NIST scores — and we hope that translates to reduced risk.
It doesn’t.
The CFO isn’t trying to decode your acronyms. They’re trying to understand what happens if this program gets cut. And if your answer is “we’ll be more vulnerable,” you’ve already lost the room.
Stop Talking About Risk in Theory
I once watched a CISO get grilled by a CFO who asked one question: “What’s the cost curve of a cyber incident across day 1, day 3, and day 10?”
There was silence.
Not because the CISO wasn’t prepared — but because his entire narrative was built around what might happen, not what will happen if a specific OT-dependent service fails.
This is where we need to pivot. Start talking about:
- The lost production hours per system.
- The per-hour financial impact of downtime for each facility tier.
- The number of days before a product batch becomes non-compliant due to interrupted data integrity.
You want to keep your OT cyber program funded in a recession? Stop leading with risk scores. Start leading with business exposure over time.
The Story the Board Actually Needs
Here’s a better way to frame the conversation.
Instead of: “We need to improve segmentation in our OT networks.”
Try: “There are four production sites generating 60% of quarterly revenue that currently lack isolation between control and enterprise layers. If ransomware hits corporate IT, those sites lose visibility and control within 20 minutes. That’s $8M in production risk per hour.”
That’s not scare tactics. That’s business truth.
And if you don’t tell that story, someone else will fill the gap — probably with an oversimplified narrative that gets your program deprioritized.
The Recession Budget Reality
You don’t need to win the whole budget cycle. You just need to defend the programs that protect uptime, quality, and safety in ways the CFO can model.
One executive I worked with didn’t pitch cyber funding at all. He pitched “Uptime Risk Reduction Initiatives” — and included OT segmentation, identity failovers, and site-specific response training as line items. The result? Funding approved. No debate.
That’s not spin. That’s translation.
Final Thought
CISOs who survive this economic cycle will be the ones who stop arguing for security and start advocating for operational continuity.
You don’t need a new vocabulary. You need a new angle — one that starts with, “Here’s what’s at risk if this system goes down,” and ends with, “Here’s what that means for revenue, safety, and brand trust.”
If you’re still walking into the boardroom with technical diagrams and a list of alerts, you’re not defending your program. You’re defending plumbing.
And nobody funds plumbing in a recession.
Follow Hillstrong on LinkedIn: