2.2.3. Strategic Planning: Business Cases, Budgets, and Resourcing
💡 First Principle: Security spending only survives competing budget priorities when it is justified the same way every other business investment is — by the value it protects or creates, not by the fear it invokes.
A security leader who asks for budget by describing a frightening threat will lose that argument to a product leader who can show a revenue number, every time, because the finance function is built to compare investments in comparable terms. A business case reframes a control investment the same way: what loss does this prevent, how likely is that loss without the control, and what does the control cost relative to that expected loss — the same cost-benefit logic used for any other capital request.
Return on Security Investment (ROSI) calculations attempt to formalize this: (expected loss reduced by the control) minus (cost of the control), expressed as a return. These calculations are necessarily imprecise — loss estimates for security events carry real uncertainty — but the discipline of producing one, and defending its assumptions, is what earns a security proposal a seat at the same table as other capital requests, rather than being treated as a cost center to be minimized.
⚠️ Exam Trap: A larger security budget is often assumed to directly produce better security. Without a business case tied to actual risk reduction, additional budget just as often funds tools that don't address the organization's real risk profile — sometimes called "shelfware." The correct answer ties budget adequacy to whether spending maps to a documented gap, not to the raw size of the number.
Reflection Question: Your security budget has doubled over three years, but the risk register shows the same top five risks unaddressed the whole time. What does this suggest about how that budget has been allocated?