Skip to content

Cyber risk has a price. Many CFOs haven’t been shown the invoice.

cyber-security

A CFO assigns a price to every material risk the business faces. Currency exposure is hedged, debtors are aged, and credit risk is provisioned. Cyber risk, however, is an exception—not because it is less significant, but because it has traditionally been presented to the board as a color-coded slide rather than a numerical value. This approach is no longer viable, as everyone else in the discussion now has a number, and they will use it against you: the attacker, the regulator, and even your own insurer.

Here is the ledger that a CFO should be looking at:

The average cost of a data breach in South Africa was R44.1 million in 2025, a decrease from R53.1 million the previous year. In the financial services sector, this figure is notably higher, with the financial sector incurring the highest breach cost at R70.2 million. It is important to note that this is not merely an IT-related expense. The costs encompass incident response, forensics, downtime, breach notification, legal review, and recovery, all of which are processed through financial channels rather than the IT department. The most prevalent methods of breach remain the most cost-effective for attackers: compromised credentials and phishing each accounted for 13% of cases.

The compliance number under the Protection of Personal Information Act (POPIA) is significant. The Information Regulator is authorized to impose an administrative fine of up to R10 million, or a prison sentence of up to 10 years, or both. This is not merely theoretical. The first fine, amounting to R5 million against the Department of Justice, was not due to a sophisticated data breach. It resulted from a failure to maintain security safeguards, specifically an expired antivirus and intrusion-detection license that would have detected unauthorized access. Essentially, it was a failure to maintain visibility. Importantly, for any Chief Financial Officer considering whether to take immediate action or delay, it should be noted that remedial measures taken post-incident do not mitigate the fine imposed by the regulator. Compliance cannot be retroactively purchased following a breach. One must either demonstrate reasonable precautions beforehand or face the consequences.

Cyber insurance is no longer a simple annual formality. Insurers now mandate specific security controls as prerequisites for coverage and conduct comprehensive assessments of your security posture prior to issuing a policy. Additionally, an increasing number of insurers offer premium discounts based on continuous telemetry monitoring of your environment. The trend is evident: lack of evidence regarding your security posture may result in higher premiums, reduced coverage, or disputed claims at critical times. Demonstrable monitoring is becoming essential for securing a renewable policy, distinguishing it from an uninsurable risk.

In evaluating the financial implications, consider the following figures: an exposure of R44.1 million, a regulatory ceiling of R10 million, and an insurance premium that adjusts according to your documented risk posture. These should be weighed against the cost of maintaining continuous visibility. XContent RED offers HAX services across client environments at a rate of R1.5 million per enterprise tier annually. This service provides the precise evidence required by the aforementioned metrics: ongoing monitoring of external exposure, detection of credentials on the dark web, and the speed at which critical issues are addressed. This cost is negligible compared to a potential R44.1 million incident and serves as documentation to demonstrate compliance to regulators and risk posture to underwriters.

All other risks on your balance sheet are quantified, provisioned, and assigned ownership. Cybersecurity risks can be managed similarly. CFOs who assess these risks prior to an incident are those who remain operational, insured, and compliant in the aftermath. Conversely, those who fail to do so may find themselves explaining to the board why the unquantified risk was the one that materialized.

In today’s complex business environment, cyber risk demands the same rigorous financial scrutiny as any other material risk on the balance sheet. CFOs must move beyond abstract presentations and embrace quantifiable metrics to safeguard their organizations. By investing proactively in continuous visibility and compliance measures, businesses not only reduce the likelihood and impact of breaches but also strengthen their position with regulators and insurers. The cost of inaction far outweighs the investment in robust cyber risk management. It is imperative that CFOs lead the charge in integrating cyber risk into financial planning, ensuring their organizations remain resilient, insured, and compliant. Take decisive action now—quantify your cyber risk, implement continuous monitoring, and demonstrate your commitment to protecting your enterprise’s financial health before the next incident occurs.

This article is written by our trusted Distribution Partner – Simoné Deyzel of XContent RED · A business unit of XContent (Pty) Ltd .  If it has prompted you to rethink your cyber risk, keep the conversation going – reach out to XContent at [email protected]