The CFO Standard
When cyber risk becomes a CFO problem
Cyber security for CFOs: are you asking the right questions?
The remit of the CFO has expanded considerably in recent years, from steward of the numbers to strategic adviser and, increasingly, a central figure in cyber and technology governance. As a result, cyber security for CFOs is becoming an increasingly important area of oversight, particularly as boards expect greater visibility over technology risk, investment and organisational resilience.
It is a significant vote of confidence, with the Gartner Board of Directors Survey finding boards trust CFOs to lead through volatile market conditions more than any other CEO direct report. The downside is that many CFOs have found themselves occupying accountability gaps, becoming legally or strategically answerable for functions they were never trained to lead.
A Gartner Leadership Survey found that CFOs now report ownership or co-ownership of enterprise priorities extending well beyond finance – from data and analytics to enterprise risk, AI, cyber security and ESG. As CFOs assume oversight of these areas, questions arise as to whether they truly grasp the accountability and level of risk they have been expected to carry.
Cyber is of particular concern because, as recent cases have shown, even a failure to implement effective cyber security controls can result in multi-million-dollar penalties. The story gets worse for actual cyber incidents, with costs for some organisations running into the hundreds of millions and even billions of dollars.
For Australian organisations, data breaches can lead to financial loss, disrupted operations and reputational damage. Cyber risk may also extend through the supply chain, making it important to understand where critical suppliers hold data or support essential services.
CFOs who have been entrusted with cyber oversight and reporting, effectively discharging their responsibilities in this area would require a very clear appreciation of:
- What they know
- What they don’t know
- What they don’t yet realise they don’t know.
When cyber security blind spots sneak up on you
75% of CFOs planned to increase technology budgets in 2026, with almost half expecting increases of 10% or more. The rationale provided was that technology had become central to digital transformation, operational resilience and AI adoption.
However, investment is only part of the equation. CFOs also need to understand whether resources are being directed towards the areas that matter most, and if cyber capabilities are keeping pace with the organisation’s risk profile.
The consequences of getting this wrong are not theoretical. Recent enforcement action by the Australian Securities and Investments Commission (ASIC) saw a financial services firm ordered to pay a $2.5 million penalty due to a range of cyber security failures.
Some of these failures included where the company did not:
- Allocate the necessary financial resources to have suitably qualified and experienced people available, or implement adequate technological resources to manage cyber security
- Implement adequate cyber security measures
- Have qualified IT personnel monitoring threat alerts to identify and respond to cyber attacks
- Provide mandatory cyber security awareness training to staff
- Have an appropriate cyber incident response plan that was tested at least annually.
This is why it’s critical for CFOs to know where the organisation is well protected, where there are weaknesses, and how those gaps are being managed.
Unfortunately, this is often easier said than done as cyber risk has become a highly specialised field. Without a technical background, it can be difficult to get a genuine gauge on the risk level or know if reports being provided are completely accurate. A simple "Are we good?" may attract a confident "yes" from an IT Manager, though even IT personnel are rarely cyber security experts and may not be aware that vulnerabilities or capability gaps exist.
How CFOs can take control of cyber risk
Cyber risk is evolving rapidly, particularly as artificial intelligence increases both the scale and sophistication of potential attacks. Keeping up with that change is becoming more difficult for organisations of all sizes in all sectors.
The good news is that a CFO does not need to become a cyber security expert. Their role in cyber oversight is to ask informed questions, understand the organisation’s exposure and ensure the right people have the resources to manage it. Accountability is not responsibility, and that responsibility can be delegated to a person or team with the requisite experience such as a Chief Information Security Officer (CISO).
Where a full time CISO is not commercially viable, CFOs may prefer to engage a virtual CISO to:
Evaluate the organisation’s risk profile
Understand its risk appetite
Assess the level of alignment
Plot out the gaps
Develop a plan to plug those gaps
Oversee implementation

SUBSCRIBE TO THE CFO STANDARD
Subscribe now to read the latest insights as soon as they’re released.
The cost of getting cyber security wrong
Once done, a virtual CISO would then return once a year to assess any new gaps that have emerged and recommend how to close them.
This helps ensure the difference between internal capability and evolving external risks stays minimal to reduce the potential for an attack.
If budget for a CISO – in-house or virtual – is a concern, keep in mind the expense your organisation may be liable for if it (a) fails to implement appropriate security controls or (b) is hacked. The budget to remediate would quickly become available at that point, yet the cost would likely be exponentially more. This way, you spend a little now to save a lot later…and avoid the added risk of reputational loss.
It is a no-lose game for CFOs charged with cyber to invest properly in prevention. Because as we’ve seen, if the hackers don’t get you, the regulators might.
This checklist is based on guidance from the Australian Cyber Security Centre, together with ASIC's cyber resilience guidance for boards and senior management.
HAVE A QUESTION?
Get in touch
Strengthen your cyber security approach
Speak with our cyber security team to understand your current risk exposure, identify capability gaps and determine the right level of support for your organisation.
Strengthen your cyber security approach
Speak with our cyber security team to understand your current risk exposure, identify capability gaps and determine the right level of support for your organisation.
Ideas and insights