712-50 Question 95
Single answerFunding Request Justification and ROI PromotionA newly appointed CISO is requesting board approval for a $2.5 million security modernization program that includes privileged access management, phishing-resistant MFA, and third-party risk monitoring. The CFO has rejected prior security requests because they were framed primarily around compliance and fear of breach headlines. This year, the board has asked for a business-based justification that can compete with other capital requests. Which approach would provide the strongest justification for funding approval and best promote ROI?
- A
Present the proposal primarily as a compliance requirement, emphasizing that regulators expect stronger controls and that noncompliance could result in fines
- B
Build a business case using quantified loss exposure reduction, implementation and operating costs, measurable operational benefits, and a prioritized roadmap tied to the organization's strategic objectives
- C
Focus on the technical superiority of the selected tools, including detection rates, architectural advantages, and vendor market share
- D
Request the full budget immediately and explain that security investments are difficult to measure financially, so leadership should fund the program based on industry trends alone
Show answer and explanation
Correct answer: B
Explanation
For CCISO-level leadership, funding requests should be justified in business language, not primarily technical or compliance language. The strongest approach is to present a defensible business case that includes: baseline risk exposure, target-state risk reduction, implementation and ongoing costs, operational efficiencies, and alignment with enterprise strategy. This mirrors widely accepted governance and risk management practices found in sources such as NIST SP 800-30 for risk assessment concepts, NIST CSF for aligning cybersecurity outcomes to business objectives, and FAIR-style quantitative risk analysis approaches for estimating probable loss exposure. While exact ROI in cybersecurity can be imperfect, executives still expect disciplined financial reasoning, including cost avoidance, reduced incident frequency or magnitude, improved resilience, and measurable control outcomes. A phased roadmap with metrics strengthens credibility because it shows how benefits will be tracked after approval.
- A. Incorrect.
This is weaker than the best answer because compliance-only justification rarely competes well against other strategic investments. While regulatory obligations can support urgency, executives and boards typically want a broader business case showing financial impact, risk reduction, and alignment to enterprise objectives. A common misconception is that compliance by itself is sufficient to justify major security spending; in practice, it often results in a minimum-baseline discussion rather than a value-based investment decision.
- B. Correct.
This is correct because it frames the request in terms executives use to allocate capital: expected reduction in loss exposure, total cost of ownership, measurable business and operational benefits, and clear linkage to strategic goals. For example, the CISO can estimate reduced probability and impact of credential compromise, lower fraud or incident response costs, improved audit efficiency, and reduced third-party disruption risk. A phased roadmap also improves credibility by showing governance, achievable milestones, and the ability to track realized value over time.
- C. Incorrect.
This is not the strongest justification for board-level funding. Technical strengths matter during solution evaluation, but they do not by themselves demonstrate enterprise value or return on investment. Boards and CFOs generally prioritize financial outcomes, risk treatment, and strategic impact over product feature comparisons. Someone might choose this option because they equate better technology with better business decisions, but capital approval requires translation into business terms.
- D. Incorrect.
This is incorrect because it ignores the board's explicit request for a business-based justification. Although some security benefits are difficult to measure precisely, that does not eliminate the need for disciplined financial framing. Mature security leaders use reasonable assumptions, scenario analysis, and risk-based estimates to support investment decisions. Relying on trends alone is unlikely to survive scrutiny from finance or the board.