What are the main cybersecurity challenges for the CISO? What are the priorities and how can the CISO deal with them? Cybersecurity expert Rob Musquetier compiled his top 3 biggest priorities for the CISO and provides practical tips on how CISOs can address them. In this third part, we explain the third-biggest challenge for the CISO: the CISO's limited budget and mandate.
CISO budget and mandate are limited
The average CISO's to-do list is longer than that of our prime minister! While this is a problem in itself, it's exacerbated by a limited mandate. The CISO must first convince management, a director, or a CEO of the necessity of cybersecurity investments before having sufficient budget to invest in new measures. As a result, implementing measures almost always takes longer than desired or even justifiable given the risk of cyberattacks and organizational vulnerabilities. An additional disadvantage for the CISO is that decision-makers often have a strong affinity for their industry but less so for security risks and cybersecurity measures, making budgeting decisions difficult.
What can a CISO do to increase their budget and mandate?
Decision-makers are often deterred by the high costs of cybersecurity. However, the CISO must invest to cope with daily evolving cyber threats and the increasing number of cyberattacks. Furthermore, organizations can no longer insure themselves against damages caused by cyberattacks if they lack appropriate technical and organizational measures. But how can the CISO increase the cybersecurity budget and mandate?
- Approach cybersecurity budget requests as a business case. Start by analyzing the risk appetite: how significant are the security risks and how much risk is management willing to take? Illustrate the likelihood of cyberattacks using examples from similar organizations and recent (industry) research findings;
- Explain to management/stakeholders that the term ‘appropriate technical and organizational measures’ is specifically intended to emphasize that context determines whether measures are appropriate or not. For example, in high-risk data processing, privacy risks are significant, and thus the demands on the level of cybersecurity are high. Furthermore, the context is also shaped by evolving threats, so a CISO must continuously invest to maintain cybersecurity.
- It is the CISO's responsibility to ensure that the organization is prepared for and resilient against cyberattacks. If the CISO's budget and mandate are insufficient to properly perform the role, it is advisable to first discuss this with the Privacy Officers and/or Data Protection Officer, and then collectively with the executive board or directors responsible. Make it clear that a limited budget and mandate lead to a greater risk of security incidents.
- Relate the importance of cybersecurity directly to the interests of and security risks for the target group. Outline the damage that customers, patients, and clients can experience using case studies from your industry. For example, the understanding and perception of the privacy and security risk of 'identity fraud involving a vulnerable client' is often much greater than the risk of a fine from the Dutch Data Protection Authority (even though these fines can be enormous).
- The budget for increasing cyber resilience is actually aimed at protecting business continuity. Increasing cyber resilience, in particular, is a shared responsibility and a top priority. As a CISO, emphasize shared interests, goals, and responsibilities. This way, you, as a CISO, can transform the perception of an expense into an opportunity and an obligation to strengthen and protect the organization's cyber resilience.
Research results for a business case are easy to find; the number of cyberattacks in the Netherlands rose by 53% in the first quarter of this year. The top 3 most affected sectors in Q1 2025 Cyberattacks Rise by 53% in the Netherlands in Q1 2025 | BeveiligingsWereld according to research by Beveiligingswereld::
- healthcare with an average of 3,164 attacks per week;
- consultancy with an average of 1,382 attacks per week;
- retail/wholesale with an average of 1,179 attacks per week.
What else should a CISO invest in?
With a smart budget request, the likelihood of being granted (most of) the desired budget has significantly increased. However, sufficient budget is not the only success factor for good cyber resilience. Engaging stakeholders is equally important. It's advisable to meet at least monthly with the Privacy Officer, Security Officer or (C)ISO, Quality Manager, Complaints Officer, and the Purchasing Manager or Financial Administration. It's useful to discuss issues such as risks, incidents, data breaches, and complaints together to immediately devise a joint solution. After all, an issue only arises when there is a deviation, often involving five aspects to varying degrees: security, privacy, quality, legality, and compliance. The solution lies in jointly analyzing and addressing the issue, which usually leads to actions and process adjustments. By directly involving all necessary parties in brainstorming potential solutions, you, as a CISO, significantly accelerate the resolution of issues!
How does the CISO secure more budget and mandate?
In summary, the CISO secures more budget and mandate by treating budget requests as business cases that include:
- An outline of realistic privacy and security risks, including likelihood and impact, and an indication of potential damage;
- A focus on the importance of cybersecurity and cyber resilience for business continuity;
- Considering stakeholders' specific interests;
- Emphasis on shared goals and shared responsibility.
Invest in engaged stakeholders, central consultation, and collaborative issue resolution.
Also read the other two parts on the Top 3 CISO Challenges in Cybersecurity:
Part 1: Cybercrime and Ransomware: A Rapidly Growing Problem
Part 2: The Impressive Quality of Phishing Emails










.jpg)
.webp)