Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2026 GBAF Publications Ltd - All Rights Reserved. | Sitemap | Tags | Developed By eCorpIT

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Business > DOES YOUR CFO SPEAK THE LANGUAGE OF CYBER RISK?
    Business

    DOES YOUR CFO SPEAK THE LANGUAGE OF CYBER RISK?

    Published by Gbaf News

    Posted on February 21, 2018

    9 min read

    Last updated: January 21, 2026

    This image illustrates the impact of automation in financial services for creating a comprehensive 360-degree view of customer interactions, crucial for enhancing service delivery and operational efficiency.
    Automation in financial services enabling a 360-degree view for customer engagement - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    David Higgins, Director of Customer Development EMEA, CyberArk

    In the traditional realms of cybersecurity, ‘security’ and ‘risk’ are always the predominant topics of conversation. But for FDs and CFOs it’s even more reductive than that – everything boils down to one factor: risk. It’s their job to be aware of the financial repercussions of every single risk an organisation takes and their approach to cybersecurity is no different. They want models which specifically demonstrate their exposure to risk in cyberspace, both from internal and external threats.

    Ignorance isn’t bliss

    We constantly hear that cybersecurity should be a boardroom topic – and in most cases it is. But it’s largely a futile exercise at the moment. CISOs go into the last five minutes of a board meeting to outline their most recent cybersecurity initiatives, but no-one listens. Why? Because the board doesn’t speak the same technical language. CFOs need things explained in a way which easily translates into their risk modelling frameworks.

    This leaves us at a bit of an impasse. Cybersecurity teams, constantly focused on defending their organisation in cyberspace, become isolated from the wider organisation and the implications their initiatives may have on their colleagues, particularly from a financial perspective. They also become detached from the activity of accounts with privileged access – such as CFOs – and miss potential indicators of a security vulnerability, an impending data breach or an inside threat, such as a disgruntled employee.

    Likewise, without adequate explanation as to why certain security protocols are in place, the finance function can become quickly become frustrated at measures which appear to hinder their job function and choose to ignore them, potentially exposing them even further to the risk of a catastrophic data breach.

    Creating a dialogue

    Organisations should therefore seek to create a reciprocal dialogue between these core business units, so they understand the implication of security policies on critical business accounts and transactions, and vice versa. This comes from encouraging cybersecurity teams to avoid technical jargon and speak to the finance function in a language they understand, so their messages resonate more clearly. CFOs and FDs in particular have the best view of the entire threat landscape of their organisation, so must train their security leadership team to converse with them in the way they want to provide effective defence against cyber threats. Doing so will help both business units identify and nullify potential threats to the business – both internal and external – early, helping ringfence security at the heart of the enterprise and prevent a costly cyber attack.

    Taking a security-first approach to the enterprise

    But that’s not enough. It’s also about educating your workforce to about the implications of a constantly-changing digital environment. Almost every company out there has heard the ubiquitous calls for a ‘change of attitude’ to cybersecurity by now, but how can their employees put this new attitude into action without practical guidance?

    Aside from cybersecurity awareness training, which should be a requirement for every employee within the organisation, finance teams must firstly be trained to report potential vulnerabilities and attacks as soon as possible, and secondly consider the implications of their actions from a cybersecurity perspective; at every turn they should think how their actions may increase the business’ exposure to attack. This may require involving the CISO in strategy or business development meetings for example, as well as board meetings, so they are aware of recent initiatives and can express their security concerns from a business viewpoint.

    Establishing exposure to risk

    Up to now the process of allocating budget to cybersecurity has not been an exact science, and this has created confusion regarding ownership of the function within business. Many businesses operate without measuring their exposure to risk – meaning they don’t know how much it would cost them if a successful cyber attack took place. Given how critical it now is to the financial viability of a business, CFOs and FDs should take the lead and demand a demonstrable measure of their organisation’s risk exposure in cyberspace. Not only will this help them secure insurance policies which leave them fully covered in the event of an attack, but it will also to allow them to align the correct amount of budget to cybersecurity spend.

    Cybersecurity can no longer be considered as simply a technological risk – it is now a business-critical risk. According to IBM’s latest cost of data breach study, the average cost of a data breach globally is $3.62 million – and the size of these breaches is increasing.[1] A reactive approach simply isn’t sufficient to prevent costly and irrevocable damage to an organisation, and it’s widely accepted that the senior finance team should take a leading role in helping their organisation implement a robust, pragmatic, and proactive strategy to deal with cyber threats.

    This process will only work if the two critical business functions work together to create a reciprocal dialogue which is understood by both parties, formulate easily navigated frameworks, and educate the entire organisation to the scale of its threat landscape. While no protection against cyber attacks is foolproof – they are becoming more sophisticated every day – these steps are critical to effectively mitigate risk and defend against cyber threats. After all, as Ginni Romety, the CEO of IBM, said: “Cyber crime is the greatest threat to every company in the world”. So it’s worth listening.

    David Higgins, Director of Customer Development EMEA, CyberArk

    In the traditional realms of cybersecurity, ‘security’ and ‘risk’ are always the predominant topics of conversation. But for FDs and CFOs it’s even more reductive than that – everything boils down to one factor: risk. It’s their job to be aware of the financial repercussions of every single risk an organisation takes and their approach to cybersecurity is no different. They want models which specifically demonstrate their exposure to risk in cyberspace, both from internal and external threats.

    Ignorance isn’t bliss

    We constantly hear that cybersecurity should be a boardroom topic – and in most cases it is. But it’s largely a futile exercise at the moment. CISOs go into the last five minutes of a board meeting to outline their most recent cybersecurity initiatives, but no-one listens. Why? Because the board doesn’t speak the same technical language. CFOs need things explained in a way which easily translates into their risk modelling frameworks.

    This leaves us at a bit of an impasse. Cybersecurity teams, constantly focused on defending their organisation in cyberspace, become isolated from the wider organisation and the implications their initiatives may have on their colleagues, particularly from a financial perspective. They also become detached from the activity of accounts with privileged access – such as CFOs – and miss potential indicators of a security vulnerability, an impending data breach or an inside threat, such as a disgruntled employee.

    Likewise, without adequate explanation as to why certain security protocols are in place, the finance function can become quickly become frustrated at measures which appear to hinder their job function and choose to ignore them, potentially exposing them even further to the risk of a catastrophic data breach.

    Creating a dialogue

    Organisations should therefore seek to create a reciprocal dialogue between these core business units, so they understand the implication of security policies on critical business accounts and transactions, and vice versa. This comes from encouraging cybersecurity teams to avoid technical jargon and speak to the finance function in a language they understand, so their messages resonate more clearly. CFOs and FDs in particular have the best view of the entire threat landscape of their organisation, so must train their security leadership team to converse with them in the way they want to provide effective defence against cyber threats. Doing so will help both business units identify and nullify potential threats to the business – both internal and external – early, helping ringfence security at the heart of the enterprise and prevent a costly cyber attack.

    Taking a security-first approach to the enterprise

    But that’s not enough. It’s also about educating your workforce to about the implications of a constantly-changing digital environment. Almost every company out there has heard the ubiquitous calls for a ‘change of attitude’ to cybersecurity by now, but how can their employees put this new attitude into action without practical guidance?

    Aside from cybersecurity awareness training, which should be a requirement for every employee within the organisation, finance teams must firstly be trained to report potential vulnerabilities and attacks as soon as possible, and secondly consider the implications of their actions from a cybersecurity perspective; at every turn they should think how their actions may increase the business’ exposure to attack. This may require involving the CISO in strategy or business development meetings for example, as well as board meetings, so they are aware of recent initiatives and can express their security concerns from a business viewpoint.

    Establishing exposure to risk

    Up to now the process of allocating budget to cybersecurity has not been an exact science, and this has created confusion regarding ownership of the function within business. Many businesses operate without measuring their exposure to risk – meaning they don’t know how much it would cost them if a successful cyber attack took place. Given how critical it now is to the financial viability of a business, CFOs and FDs should take the lead and demand a demonstrable measure of their organisation’s risk exposure in cyberspace. Not only will this help them secure insurance policies which leave them fully covered in the event of an attack, but it will also to allow them to align the correct amount of budget to cybersecurity spend.

    Cybersecurity can no longer be considered as simply a technological risk – it is now a business-critical risk. According to IBM’s latest cost of data breach study, the average cost of a data breach globally is $3.62 million – and the size of these breaches is increasing.[1] A reactive approach simply isn’t sufficient to prevent costly and irrevocable damage to an organisation, and it’s widely accepted that the senior finance team should take a leading role in helping their organisation implement a robust, pragmatic, and proactive strategy to deal with cyber threats.

    This process will only work if the two critical business functions work together to create a reciprocal dialogue which is understood by both parties, formulate easily navigated frameworks, and educate the entire organisation to the scale of its threat landscape. While no protection against cyber attacks is foolproof – they are becoming more sophisticated every day – these steps are critical to effectively mitigate risk and defend against cyber threats. After all, as Ginni Romety, the CEO of IBM, said: “Cyber crime is the greatest threat to every company in the world”. So it’s worth listening.

    More from Business

    Explore more articles in the Business category

    Image for Empire Lending helps SMEs secure capital faster, without bank delays
    Empire Lending helps SMEs secure capital faster, without bank delays
    Image for Why Leen Kawas is Prioritizing Strategic Leadership at Propel Bio Partners
    Why Leen Kawas is Prioritizing Strategic Leadership at Propel Bio Partners
    Image for How Commercial Lending Software Platforms Are Structured and Utilized
    How Commercial Lending Software Platforms Are Structured and Utilized
    Image for Oil Traders vs. Tech Startups: Surprising Lessons from Two High-Stakes Worlds | Said Addi
    Oil Traders vs. Tech Startups: Surprising Lessons from Two High-Stakes Worlds | Said Addi
    Image for Why More Mortgage Brokers Are Choosing to Join a Network
    Why More Mortgage Brokers Are Choosing to Join a Network
    Image for From Recession Survivor to Industry Pioneer: Ed Lewis's Data Revolution
    From Recession Survivor to Industry Pioneer: Ed Lewis's Data Revolution
    Image for From Optometry to Soul Vision: The Doctor Helping Entrepreneurs Lead With Purpose
    From Optometry to Soul Vision: The Doctor Helping Entrepreneurs Lead With Purpose
    Image for Global Rankings Revealed: Top PMO Certifications Worldwide
    Global Rankings Revealed: Top PMO Certifications Worldwide
    Image for World Premiere of Midnight in the War Room to be Hosted at Black Hat Vegas
    World Premiere of Midnight in the War Room to be Hosted at Black Hat Vegas
    Image for Role of Personal Accident Cover in 2-Wheeler Insurance for Owners and Riders
    Role of Personal Accident Cover in 2-Wheeler Insurance for Owners and Riders
    Image for The Young Rich Lister Who Also Teaches: How Aaron Sansoni Built a Brand Around Execution
    The Young Rich Lister Who Also Teaches: How Aaron Sansoni Built a Brand Around Execution
    Image for Q3 2025 Priority Leadership: Tom Priore and Tim O'Leary Balance Near-Term Challenges with Long-Term Strategic Wins
    Q3 2025 Priority Leadership: Tom Priore and Tim O'Leary Balance Near-Term Challenges with Long-Term Strategic Wins
    View All Business Posts
    Previous Business PostUK FINANCIAL SERVICES LAGGING BEHIND GLOBAL RIVALS IN DIGITAL
    Next Business PostIMPROVING WORKPLACE PENSION COMMUNICATION CAN PREVENT AUTO ENROLMENT  DROP OUTS SAYS PUNTER SOUTHALL ASPIRE