
May 8, 2026 · 3 min read · Dustin Holden
Cybersecurity Is a CFO Problem Now
When most CFOs hear "cybersecurity," they mentally file it under IT. It's a technical problem, owned by technical people, with a budget line the CFO approves and otherwise leaves alone. That instinct is increasingly dangerous, because the attacks that actually drain money from companies are rarely sophisticated technical breaches. They're finance process failures dressed up as security incidents, and they land squarely in the CFO's domain.
The attacks that actually take your money are finance attacks
Forget the Hollywood image of hackers breaching firewalls. The most common and most costly attacks on mid-market companies exploit people and processes, not technology. Business email compromise is the canonical example: an attacker impersonates an executive or a vendor and convinces someone in finance to change payment details or wire money to a fraudulent account. No firewall is breached. The attack succeeds because a finance process let a payment instruction be changed on the strength of an email.
These attacks work because they target exactly the things finance controls: payments, vendor master data, wire authorizations, payroll changes. The defense isn't better firewalls—it's better finance controls. Which means the CFO isn't a bystander to this risk; the CFO owns the processes the attackers are exploiting.
The controls that actually stop the common attacks
The good news is that the controls that defeat these attacks are unglamorous finance discipline, not exotic technology.
Verify payment changes out of band. The single most effective control: any change to vendor banking details or any unusual payment request gets verified through a separate channel—a phone call to a known number, not a reply to the email that requested it. The attack depends on the request and the verification flowing through the same compromised channel. Break that and most business email compromise fails.
Enforce separation of duties on payments. The person who can change vendor details shouldn't be the only person who can release a payment to them. The person who initiates a wire shouldn't be the only one who approves it. Attackers exploit single points of control; segregation removes them.
Be suspicious of urgency. These attacks almost always manufacture time pressure—the executive who needs the wire sent now, before a deadline, while traveling and unreachable. Urgency is the tool that bypasses normal controls, so a culture where urgency triggers more verification rather than less is itself a defense.
None of this requires a security team. It requires finance processes designed with the assumption that someone will try to manipulate them.
Where finance and IT genuinely overlap
This doesn't mean the CFO replaces IT on cybersecurity—it means recognizing the overlap and owning the finance side of it. IT owns the technical defenses, the access controls, the systems. Finance owns the process controls around money movement and the financial consequences of a breach. The two have to work together, and the CFO is often the executive who can force that collaboration because the CFO sees both the risk exposure and the financial stakes.
The CFO also owns the financial dimension of cyber risk that IT can't: the insurance, the quantification of exposure, the business continuity implications, the regulatory and disclosure consequences if customer or financial data is compromised. These are finance decisions that require understanding the technical risk, which is exactly why the CFO can't treat cyber as someone else's problem.
The disclosure and accountability shift
There's also a governance dimension the CFO can't delegate. Cyber incidents increasingly carry disclosure obligations, and boards increasingly hold the C-suite—not just IT—accountable for cyber preparedness. When an incident happens, "that was IT's department" is not a defense that protects the CFO or satisfies a board. The expectation now is that the CFO understands the company's material cyber exposure well enough to oversee it as the financial risk it is.
The practical starting point
You don't need to become a security expert. You need to do two things. First, audit your own house: are the payment, vendor-change, and wire controls above actually in place and enforced, or are they policies people work around when someone's in a hurry? That audit alone closes the door on the most common attacks. Second, build a real working relationship with whoever owns IT security, so the technical and process defenses are coordinated rather than siloed.
Cybersecurity stopped being purely a technical problem the moment the most effective attacks started targeting finance processes. The attackers already understand that finance is the target. The CFOs who understand it too are the ones whose companies don't end up wiring money to a stranger.
Tools that can help
Tech for CFO apps that put the ideas in this article to work on your own numbers.