91% of large organizations have already adjusted their cybersecurity strategy due to geopolitical volatility. If your board hasn’t, you’re not just behind — you’re about to walk into a budget meeting with the wrong conversation.
Every year, the same theater plays out in boardrooms across America.
The CISO walks in with a number. The CFO pushes back. The CISO had already padded the ask knowing the CFO would push back. The CFO knew it was padded and cut it anyway. Nobody actually knows if the final number reflects the real risk. Everyone goes home and calls it a budget process.
Padding isn’t a strategy. It’s a signal that nobody in the room trusts the number — including the person who made it up.
With Iran, Russia, and China all actively targeting US and allied organizations simultaneously this month, there’s a legitimate reason to reopen the conversation mid-cycle. Geopolitical escalation is a real budget trigger — if you know how to frame it.
Here’s how to have that conversation using the same framework we use to teach professional negotiators. The 8 Moves of Negotiation™ don’t just apply to vendor contracts and M&A. They apply to any high-stakes ask — including the one you’re about to make to your board.
MOVE 1: KNOW YOURSELF
Do You Actually Feel Comfortable Asking for Money?
Before you build a single slide, answer this honestly: are you the type who walks into a room and confidently names a number — or do you pre-negotiate against yourself before anyone else even speaks?
Research from Carnegie Mellon and the Harvard Program on Negotiation found that 46% of the variance in negotiation outcomes comes from consistent individual differences — your patterns, tendencies, and defaults. Not your tactics. Nearly half the result is determined before you say a word.
Knowing which one you are changes everything about how you prepare.
THE SELF-AWARE MOVE:
Take the NegotiatorIQ style assessment before you walk in. Know your strengths, your blind spots, and your pressure tendencies. The most dangerous negotiator is the one who doesn’t know what they do under stress — especially when the CFO pushes back. negotiatoriq.com
MOVE 2: RUN THE NUMBERS
The Comps Exist. Use Them.
The single most powerful thing you can do in a budget negotiation is anchor your ask to external benchmarks. Not internal precedent. Not last year’s number plus 10%. Market data.
Here’s what the data actually says:
8–12% of IT budget is the enterprise cybersecurity benchmark. High-threat industries (financial, healthcare) target 10–15%. Gartner / Elisity 2026 Planning Guide
0.69% of revenue is what companies currently spend on cybersecurity — up from 0.48% in 2022 as boards treat it as core infrastructure. IANS Research / Artico Search 2025 Benchmark Report
$5.08M average cost of a single ransomware incident in 2025. Compare that to the cost of prevention. IBM Cost of a Data Breach Report 2025
91% of large organizations have already adjusted their cybersecurity strategy due to geopolitical volatility. World Economic Forum Global Cybersecurity Outlook 2026
This is your ZOPA — your Zone of Possible Agreement. If your organization is spending below the 8% IT benchmark, that gap is not a negotiating position. It’s a documented exposure.
Frame it that way.
MOVE 3: SET YOUR STRATEGY
Stop Asking for a Number. Present Three Options.
The padding game exists because both sides are negotiating over a single number with no shared understanding of what that number buys. The CFO has no context. The CISO has no leverage. Everyone is guessing.
The fix is presenting three options. Instead of asking for one number and waiting to get cut, you present three packages with explicit trade-offs. Now the conversation shifts from “how much” to “which level of protection.”
That’s a fundamentally different negotiation.
OPTION A- Full Defense Posture
• Investment: [X% of IT budget / $X annual]
OPTION B- Managed Risk Posture
• Investment: [X% of IT budget / $X annual]
OPTION C- Last Year’s Budget — With This Year’s Threat Environment
• Investment: [current annual spend]
MOVE 4: CONTROL THE OPENING
Set the Anchor Before the CFO Does
Whoever sets the first number controls the range. Most CISOs wait to be asked. That’s the wrong move.
Open with the benchmark. “Organizations in our industry are allocating 10–12% of IT budget to security. We’re currently at 6.5%. Here’s what that gap costs us in real exposure.” You’ve just set the ceiling. Every number that follows is measured against it.
MOVE 5: CONTROL THE CLOCK
Geopolitical Escalation Is a Legitimate Mid-Cycle Trigger
Budget cycles exist for process, not for reality. Iran, Russia, and China are all actively operating against US and allied organizations right now — simultaneously. That’s not a routine quarterly update. That’s a material change in threat environment.
You have standing to reopen the conversation. Use it. Frame the ask as a response to a changed environment, not as a request for more resources. Those are very different things to a CFO.
Given the current geopolitical environment, I’d like to present an updated risk posture review before your April board meeting. That’s not a budget ask. That’s risk governance.
MOVE 6: SIGNAL WITH PRECISION
Speak CFO, Not CISO
There’s a well-documented principle in behavioral economics called loss aversion — people feel the pain of a loss roughly twice as strongly as the pleasure of an equivalent gain. In budget negotiations, most CISOs lead with what they want to gain. The CFO hears cost.
Flip it. Lead with what the organization stands to lose. The risk. The exposure. The dollar figure sitting unprotected right now. That’s the language that activates a CFO’s decision-making — not threat briefings, not tool counts.
Every word you use should translate technical risk into financial consequence.
Don’t say: “We need to improve our threat detection capability.”
Say: “A single ransomware incident costs $5.08 million on average. Our current detection gap means we’d likely find out 21 days after initial compromise. Here’s what that 21-day window costs us.”
Don’t say: “Nation-state actors are increasingly sophisticated.”
Say: “91% of large organizations have already updated their cyber strategy due to geopolitical escalation. We haven’t. Here’s what that gap looks like on our risk register.”
Numbers. Losses. Consequences. That’s the language that moves a CFO.
MOVE 7: REDIRECT & COUNTER
When They Push Back — And They Will
Every budget ask gets pushback. How you handle it determines whether you leave with a decision or a deferral. Here are the three pushbacks you’ll get and how to counter each one.
PUSHBACK: “We can’t afford this right now.”
COUNTER: “Let me show you what we can’t afford not to do. Option C reflects where we are today. The accepted exposure at that level is [dollar amount] — based on IBM’s 2025 breach cost benchmarks for our industry. I want to make sure the board is making a conscious decision about that number, not an accidental one.”
PUSHBACK: “We already have cybersecurity tools in place.”
COUNTER: “We do. What we don’t have is coverage for [specific gap]. That’s the gap that cost [comparable company] $X in [recent incident]. And it’s worth noting — our current cyber liability policy may require us to address this gap to maintain coverage. I’m not asking for more tools. I’m asking for coverage on a known, documented exposure that our insurer is already watching.”
PUSHBACK: “Let’s revisit this in the next budget cycle.”
COUNTER: “The threat environment changed materially this month. I want to make sure we’re not making a timing decision that turns into a risk decision. Can we agree on a 30-day review instead of waiting for the annual cycle? I can have updated numbers to you within two weeks.”
Redirect every pushback to the consequence of inaction. Not the cost of action.
One More Thing: Internal Negotiations Are Different
Negotiating inside your own organization is not the same as negotiating with a vendor or a counterpart across a table. Everyone in the room — CISO, CFO, CEO, board — theoretically has the same objective: protect the company and reduce risk. The problem is their priorities aren’t always aligned. The CFO needs to hit quarterly numbers. The CEO is managing fifteen other priorities. The board is thinking about liability.
Rapport isn’t a soft skill in this context. It’s a strategic asset. The CISO who has built a real relationship with the CFO before the budget meeting gets a fundamentally different conversation than the one who shows up with a slide deck once a year.
UNDERUSED ALLY: INTERNAL AUDIT
Internal audit can be one of the most effective allies in a cyber budget negotiation. They speak the CFO’s language fluently, they understand risk quantification, and the CFO has a higher baseline of trust with IA than with the CISO. If internal audit has flagged cyber gaps in a recent review, that finding carries weight in a budget conversation that a CISO’s own ask often doesn’t. Use it.
The Bottom Line
The padding game is broken because it’s built on mistrust and guesswork. The CFO doesn’t know what the number buys. The CISO doesn’t know what will survive the cut. Everyone leaves the room with a number nobody believes in.
Present three options. Anchor to market benchmarks. Lead with loss, not cost. Counter every pushback with consequences, not ask sizes. Build the internal relationships before you need them. And get a signed decision — not a polite maybe.
The board meeting is coming. The threat environment just changed. You have both the timing and the data to have a different kind of conversation this quarter.
Use them.
Tools Referenced in This Article
→ Cyber Oversight Card — 48 board-level governance topics at stasiak.com
→ NegotiatorIQ Assessment — Discover your negotiation style before your next high-stakes ask at negotiatoriq.com

