skip to content

The CFO reads two quiet years as over-investment and wants your second analyst cut - what do you argue?

level: principalimportance: nice to knowfreq 30%

answer

  1. concede the count, change the subject
  2. capability, not fear
  3. never claim breaches prevented
  4. options with honest costs, not a plea
  5. a provider buys hours, not ownership

basics

~20 s

Argue about capability, not fear. Say what the second person actually delivers in hours and cases, present the options with their honest costs, and let the budget holder choose knowingly. Never claim a number of breaches prevented you cannot evidence.

solid answer

~50 s

I accept the frame rather than fight it: the CFO is right that two quiet years are not proof of value, and a security lead who answers with fear loses the room. So I argue capability. I show what the second person produced - cases detected and contained with their timelines, the hours of the day actually covered, alerts worked, techniques we executed and caught - and then present options rather than a plea: keep two people, drop to one and lose named coverage, or move first-line triage to a provider. For each I state honestly what it buys and what it costs, including that a provider buys hours but not ownership - they raise, we still decide and act on our own estate. I never claim a count of breaches prevented. Then I ask for the decision to be recorded with a review date.

go deeper

for a junior

Know that a quiet period is not self-evidently proof that security spending worked, and that the case for it is made from what the team observed and did rather than from what might have happened.

for a middle

Be ready to supply the underlying evidence - case timelines, alerts worked, hours actually covered, techniques executed and detected - in a form somebody can put in front of a budget holder.

for a senior

Show that you can hold this conversation without fear-based arguments or invented prevented-breach numbers, and that you know what an outsourced triage arrangement genuinely buys and what stays yours.

for a principal

Own the trade. Bring options with honest costs, let the budget holder decide knowingly, get the accepted coverage recorded with a review date, and instrument the coming year so the next renewal reviews a record instead of arguing about a zero.

## Why the CFO's position is reasonable In a mid-size company with two security people, an annual renewal and no breach in its history, the CFO is applying an ordinary test: what did this money buy? The answer 'nothing happened' is genuinely weak evidence, and a security lead who treats the question as ignorance rather than as a fair challenge will lose. The productive move is to concede the point about the incident count and change what the argument is about. ## Fear is not an argument, and neither is an invented number Two failure modes lose the room immediately. The first is **fear**: industry breach statistics, a competitor's incident, a generic average cost of a breach. These are claims about other organisations, and a numerate CFO discounts them correctly - your base rate is not theirs, and the figure was not derived from your estate. The second, and worse, is **inventing a prevented-breach count**. You cannot count events that did not occur. Asserting a number you cannot derive puts your credibility in play for a figure that will be challenged in the next meeting, and once it collapses, the defensible evidence you presented alongside it collapses with it. ## Argue capability, with evidence that actually exists What you can put on the table, all observable: - **Cases detected and contained**, with the time from first record to containment, and what impact was avoided in each specific case. Two well-documented near-misses beat any industry statistic. - **Coverage in hours**. With two people there is a staffed window; name it. If an alert arrives outside it, say what actually happens and how long it waits. - **Worked volume** - alerts triaged, including the ones correctly closed as benign, which demonstrate the pipeline was live rather than dormant. - **Executed techniques and the stage each reached** - the only positive evidence generated by the defence itself rather than by an adversary's mistake. - **How findings arrived** - detected internally versus reported to you by a supplier or a customer. If any arrived from outside, that gap is your strongest concrete ask. ## Present options, not a plea The budget decision belongs to the budget holder. Your job is to make it an informed one, which means offering the alternatives with their honest costs rather than defending the status quo: 1. **Sustain two people.** What it buys: the current staffed window, in-house context on the estate, response executed by people who know it. What it costs: the salary, and no overnight coverage regardless. 2. **Drop to one.** What it buys: the saving. What it costs: single points of failure on leave and illness, a queue that grows, and the loss of whichever activity the second person was doing that nobody else does - usually detection improvement and the exercises, which are exactly the evidence this meeting needed. 3. **Move first-line triage to a provider.** What it buys: hours of coverage that a two-person team cannot staff, at a cost usually below a second salary. What it costs: a provider triages alerts against your estate without your context, and cannot own containment decisions on it - escalation and response authority stay in-house, so you still need an owner, and you have added a supplier to manage and measure. It is a coverage purchase, not a responsibility transfer. Mixing options is often the honest answer: a provider for out-of-hours raising plus one in-house owner is a real configuration, and saying so demonstrates that you are optimising the company's spend rather than protecting headcount. ## Frame the spend correctly Security capability is bought against a low-probability, high-consequence event, which is why activity-based justification fails. The comparison a CFO can act on is: what does the company lose in a bad week, who would run that week, and how many hours of that week would pass unobserved under each option. That reframes the question from 'what did we get for the money' to 'what capacity are we choosing to hold', which is a decision an executive is used to making. End by asking for the decision to be recorded with the coverage it accepts and a date to revisit it, so the same conversation next year starts from what was agreed rather than from scratch. ## Then instrument the year you just argued about badly The reason the meeting was hard is that the evidence was assembled afterwards. Fix it forward: record every case's detection-to-containment timeline as it happens, keep a running list of techniques executed and the stage reached, track the staffed-hours gap, and note every finding that arrived from outside. Next renewal is then a review of a record rather than an argument about a zero.

  • The CFO offers to keep the role if you can show what it prevented. Can you?
    Not directly, and I say so. Prevented events leave no record to count. What I can show is what was caught and contained with timelines, what was deliberately tested and detected, and which hours stop being covered if the role goes. I offer that trade explicitly rather than accepting a test that no security programme anywhere can pass.
  • Does moving triage to a provider close the coverage gap?
    It buys hours, not ownership. A provider raises and enriches alerts, but they do not know your estate's context and cannot make containment decisions on it, so escalation and response authority stay in-house and someone must still own them. You also acquire a supplier to measure. It is a real option and often the right one, but it changes the shape of the team rather than removing the need for it.
  • What do you concede in this meeting?
    That the incident count is genuinely weak evidence of value, that some of the current effort may be better spent than it currently is, and that the decision is the CFO's to make. Conceding those buys the credibility to be believed on the parts I will not concede: no prevented-breach number, and a clear statement of the hours that go dark under each option.

saying these in an interview costs you the question

  • Answers with industry breach statistics and fear
  • Claims a specific number of breaches prevented
  • Treats the budget decision as the security team's to make
  • Offers only the status quo with no alternatives
  • Says an outsourced provider transfers the responsibility
  • Argues from headcount rather than from coverage and cases

context