Sep 17 2026
Security

How Banks Should Prioritize Cybersecurity Spending

Security teams that are trying to communicate budget needs in nontechnical terms must learn how to quantify cyber risks.

Financial organizations know that when it comes to cybersecurity, there’s always room for improvement. But friction may arise when it comes to justifying cybersecurity budgets to boards and executives in nontechnical terms

A closer look at CDW’s latest Cybersecurity Research Report reveals that, for the finance sector, improving data resilience, threat defense and response/continuous threat exposure management, and improving network resilience have been the top three focus areas for organizations’ cyber resilience efforts over the past 12 months. 

Yet only 23% of financial IT decision-makers are measuring value on cybersecurity investments through clearer communication of cyber risk in business terms. 

Click the banner below to find out how financial institutions can quantify their cyber risk.

 

It’s time for financial institutions to shift how they think about and measure cyber risk altogether. Instead of treating cybersecurity as a cost center, they should see it as a competitive advantage. By quantifying cyber risk in terms of financial exposure, security teams not only justify their spending to their leaders but also make the case that cybersecurity is a business-critical endeavor that helps organizations meet their most important goals. 

Quantify Cyber Risk in Financial Terms 

“While traditional, qualitative assessments (like red/yellow/green heat maps or ordinal ‘5-severity’ grids) are useful for hygiene and compliance, they don’t tell you which investments will reduce risk the most — or at what cost. You can’t reliably choose between fixing ‘one severe’ vs. ‘six moderates’ when every box is a color, not a forecast,” write CDW Lead Field CISO Walt Powell and CDW Editorial Lead Max Reczek in a blog about risk quantification

Financial organizations that express cyber risk in dollars and probabilities can prioritize work, justify budgets and show measurable progress. Rather than a risk heat map with labels such as high/medium/low, Powell and Reczek shared this risk quantification example: “Ransomware on finance systems is expected to cost us $2.1M per year; expanding MFA and hardening backups would reduce that by about $1.6M for $250K in spend.” 

So, instead of focusing on an item that’s the loudest or reddest, security teams can mitigate the risk that would result in the most loss, such as closing an identity gap instead of fixing midlevel endpoint findings. As Powell and Reczek note, “Trade-offs become mindful, not accidental.” 

READ MORE: Are banking incident response plans ready for a new era of cyber threats?

Cyber budgets then become framed as ROI in risk terms. “A $250K control that cuts expected loss by $1.5M/year is a different conversation than ‘we need another tool.’ Show the reduction, the sensitivity range and how it drops you below appetite,” Powell and Reczek write. 

Cyber insurance also becomes more of a lever in this model, with coverage and retention considered with existing controls for “the most cost-effective residual risk,” they add. 

For financial institutions, the stakes are especially high. A breach that exposes customer data triggers regulatory penalties, erodes public trust and can cost millions in remediation. Effective cybersecurity prioritization is as much a communication challenge as a technical one. Cybersecurity is a value-protecting function that keeps a business operational, not a line-item burden.

PixeloneStocker/Getty Images
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.