{"id":26332,"date":"2026-03-03T14:02:15","date_gmt":"2026-03-03T14:02:15","guid":{"rendered":"https:\/\/microvibenews.com\/?p=26332"},"modified":"2026-03-03T14:02:15","modified_gmt":"2026-03-03T14:02:15","slug":"why-investing-in-cybersecurity-just-became-a-must-have-for-cfos","status":"publish","type":"post","link":"https:\/\/microvibenews.com\/?p=26332","title":{"rendered":"Why investing in cybersecurity just became a &#8216;must-have&#8217; for CFOs"},"content":{"rendered":"<p><\/p>\n<p>Good morning. As the U.S.\u2013Iran conflict continues, banks and corporations face heightened risk of Iranian or proxy cyberattacks\u2014not only on their systems but also on the vendors and service providers that support finance operations.<\/p>\n<div>\n<p>For CFOs, this is no longer a back-office IT issue; it\u2019s a balance sheet, liquidity, and disclosure risk.<\/p>\n<p>\u201cWe\u2019re in the midst of annual planning cycles and insurance renewals, which makes this the critical window for CFOs to reassess vendor cyber resilience and coverage adequacy,\u201d Joy Mbanugo, CFO of CXApp Inc., a workplace experience and employee engagement platform, told me. \u201cInvesting in cybersecurity is no longer a nice-to-have; it\u2019s a must-have, right alongside AI investment, given the geopolitical landscape we\u2019re operating in today.\u201d<\/p>\n<p>CXApp is treating vendor cyber risk as a material enterprise risk, integrating resilience assessments into its framework, updating incident playbooks, and aligning insurance coverage with vendor exposure, according to Mbanugo. \u201cIt\u2019s essential to safeguard sensitive data and maintain stakeholder trust, which means moving from reactive incident response to proactive risk quantification with the same rigor we apply to any material balance sheet risk,\u201d she said.<\/p>\n<p>But the issue extends well beyond any single geopolitical flashpoint. J. Michael Daniel, president and CEO of the Cyber Threat Alliance, told me that CFOs should maintain continual diligence in cybersecurity regardless of the moment. Daniel joined CTA in 2017, after serving as the White House\u2019s cybersecurity coordinator. Before that, he spent 17 years across administrations in senior roles at the Office of Management and Budget.<\/p>\n<p>\u201cThe threat landscape continues to evolve,\u201d he said. Financial institutions, because they are where the money is, \u201care always going to be in the crosshairs,\u201d he said. <\/p>\n<p>That persistent risk, he argued, demands clearer communication at the top. Daniel drew a comparison between how a CFO communicates with the board and how cybersecurity leaders should.<\/p>\n<p>The board is not interested in every detail of \u201chow did we calculate the depreciation on the four assets in Indiana?\u201d he said.<\/p>\n<p>Instead, they want the broad picture: \u201cHas the CFO done a good job at managing financial risk? And can the CFO explain, in plain English, how they are managing that financial risk for the company?\u201d<\/p>\n<p>The same should be true from a security perspective, Daniel said. Chief security officers, CISOs, and CIOs should clearly explain what they\u2019re doing, where they\u2019re investing, how they\u2019re transferring risk through cyber insurance, and which risks they\u2019ve chosen to accept\u2014and whether that approach is evolving as threats change.<\/p>\n<p>Still, even the best board-level strategy won\u2019t prevent every incident. Large-scale attacks are a concern, but so are employee-targeted phishing and other social engineering attacks, which often serve as the entry point.<\/p>\n<p>\u201cThe truth is the things that we cybersecurity professionals typically tell you to do is not rocket science,\u201d he said. \u201cIt\u2019s kind of like what your grandmother told you: If it\u2019s too good to be true, it probably is,\u201d he said.<\/p>\n<p>Adversaries play on emotions and create urgency, Daniel said. If a message feels rushed, double-check it.<\/p>\n<p>Part of CTA\u2019s recommendations is a campaign called \u201cTake Nine.\u201d The idea is simple: take nine seconds before you respond, Daniel said.<\/p>\n<p>Then verify the request through another channel\u2014if it came by email, text or call; if by text, send an email. That pause and cross-check is one of the best ways to reduce the risk that a social engineering attempt succeeds, he said.<\/p>\n<p>In this environment, it seems the CFOs who fare best will be the ones who treat cybersecurity as a core risk discipline, and not a technical footnote.<\/p>\n<p><strong>Sheryl<\/strong>\u00a0<strong>Estrada<\/strong><br \/>sheryl.estrada@fortune.com<\/p>\n<h3>Leaderboard<\/h3>\n<p><b>Kenneth (Ken) Sharp <\/b><span style=\"font-weight:400\">was appointed SVP and CFO of <\/span><span style=\"font-weight:400\">L3Harris Technologies<\/span><span style=\"font-weight:400\"> (NYSE: LHX), a defense contractor, effective March 16. Sharp, 55, brings more than 30 years of financial leadership in defense and technology. He succeeds Ken Bedingfield, who will focus on leading the Missile Solutions segment as its president. Sharp joins L3Harris from Peraton Inc., where he served as EVP and CFO. Before that, Sharp was CFO of DXC Technology, and CFO of Northrop Grumman\u2019s Defense Systems business.<\/span><b><br \/><\/b><b><br \/><\/b><b>Brad Hill<\/b><span style=\"font-weight:400\"> was appointed CFO and EVP of transformation at <\/span><span style=\"font-weight:400\">Red Lobster<\/span><span style=\"font-weight:400\">, the seafood restaurant brand. Hill will lead Red Lobster&#8217;s finance organization, along with leading the company&#8217;s strategic real estate efforts. He previously held multiple executive roles at P.F. Chang&#8217;s. Hill succeeds Bob Baker, who has departed the company.\u00a0<\/span><\/p>\n<h3>Big Deal<\/h3>\n<p><span style=\"font-weight:400\">E*TRADE from Morgan Stanley clients were net buyers in five of 11 sectors in February, with a good portion of the buying occurring in areas of the market that sold off amid AI disruption concerns, according to the firm.<\/span><\/p>\n<p><span style=\"font-weight:400\">The sectors with the most net buying were financials (+6.33%), communication services (+2.39%), and tech (+2.03%).<\/span><\/p>\n<p><span style=\"font-weight:400\">\u201cThe financial sector was the S&amp;P 500\u2019s weakest performer last month, with brokerage and insurance stocks among the groups experiencing AI-related sell-offs, at least briefly,\u201d Chris Larkin, managing director of trading and investing, said in a statement. \u201cClients also appeared to be buying the dip in some of the tech leaders that suffered similar setbacks.\u201d<\/span><\/p>\n<p><span style=\"font-weight:400\">Meanwhile, the sectors with the highest net selling were consumer staples (-8.01%), energy (-7.63%), and utilities (-3.96%)\u2014\u201ca possible case of selling into strength, as all of them were among the month\u2019s strongest performers,\u201d he said.<\/span><\/p>\n<figure class=\"wp-caption alignnone\" id=\"attachment_4430647\" aria-describedby=\"caption-attachment-4430647\">\n<div class=\"block w-full\"><img data-cy=\"article-image\" alt=\"\" loading=\"lazy\" width=\"1024\" height=\"536\" decoding=\"async\" data-nimg=\"1\" class=\"transition-opacity duration-300 size-full wp-image-4430647 not-prose w-full\" style=\"color:transparent;background-size:cover;background-position:50% 50%;background-repeat:no-repeat;background-image:url(&quot;data:image\/svg+xml;charset=utf-8,%3Csvg xmlns='http:\/\/www.w3.org\/2000\/svg' viewBox='0 0 1024 536'%3E%3Cfilter id='b' color-interpolation-filters='sRGB'%3E%3CfeGaussianBlur stdDeviation='20'\/%3E%3CfeColorMatrix values='1 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 100 -1' result='s'\/%3E%3CfeFlood x='0' y='0' width='100%25' height='100%25'\/%3E%3CfeComposite operator='out' in='s'\/%3E%3CfeComposite in2='SourceGraphic'\/%3E%3CfeGaussianBlur stdDeviation='20'\/%3E%3C\/filter%3E%3Cimage width='100%25' height='100%25' x='0' y='0' preserveAspectRatio='none' style='filter: url(%23b);' href='data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR4nGNgYAAAAAMAASsJTYQAAAAASUVORK5CYII='\/%3E%3C\/svg%3E&quot;)\" sizes=\"(max-width: 320px) 50vw, (max-width: 768px) 85vw, (max-width: 1024px) 50vw, (max-width: 1200px) 40vw, 33vw\" srcset=\"https:\/\/fortune.com\/img-assets\/wp-content\/uploads\/2026\/03\/February.png?format=webp&amp;w=128&amp;q=100 128w, https:\/\/fortune.com\/img-assets\/wp-content\/uploads\/2026\/03\/February.png?format=webp&amp;w=256&amp;q=100 256w, https:\/\/fortune.com\/img-assets\/wp-content\/uploads\/2026\/03\/February.png?format=webp&amp;w=320&amp;q=100 320w, https:\/\/fortune.com\/img-assets\/wp-content\/uploads\/2026\/03\/February.png?format=webp&amp;w=384&amp;q=100 384w, https:\/\/fortune.com\/img-assets\/wp-content\/uploads\/2026\/03\/February.png?format=webp&amp;w=480&amp;q=100 480w, https:\/\/fortune.com\/img-assets\/wp-content\/uploads\/2026\/03\/February.png?format=webp&amp;w=576&amp;q=100 576w, https:\/\/fortune.com\/img-assets\/wp-content\/uploads\/2026\/03\/February.png?format=webp&amp;w=768&amp;q=100 768w, https:\/\/fortune.com\/img-assets\/wp-content\/uploads\/2026\/03\/February.png?format=webp&amp;w=1024&amp;q=100 1024w, https:\/\/fortune.com\/img-assets\/wp-content\/uploads\/2026\/03\/February.png?format=webp&amp;w=1280&amp;q=100 1280w, https:\/\/fortune.com\/img-assets\/wp-content\/uploads\/2026\/03\/February.png?format=webp&amp;w=1440&amp;q=100 1440w\" src=\"https:\/\/fortune.com\/img-assets\/wp-content\/uploads\/2026\/03\/February.png?format=webp&amp;w=1440&amp;q=100\"\/><\/div><figcaption id=\"caption-attachment-4430647\" class=\"wp-caption-text\">Courtesy of E*TRADE<\/figcaption><\/figure>\n<h3>Going deeper<\/h3>\n<p>\u201cReporting Cybersecurity Risk to the Board of Directors\u201d is a white paper by ISACA, a global professional association focused on IT governance, risk, security, audit, and privacy. The paper covers key topics such as cyber risk as strategic risk, oversight programs, legal and regulatory concerns, the role of threat intelligence, and reporting and education for boards.<\/p>\n<h3>Overheard<\/h3>\n<p><strong>&#8220;Executives now face synthetic threats from two directions: their likenesses cloned to authorize fraudulent transfers or inflict reputational harm, and AI-generated voices impersonating government officials, board members, and business partners used to manipulate them.&#8221;<\/strong><\/p>\n<p>\u2014James Richardson, a senior managing director at the global law firm Dentons, writes in a <em>Fortune<\/em> opinion piece titled, &#8220;Boards aren\u2019t ready for the AI age: What happens when your CEO gets deepfaked?&#8221;<\/p>\n<\/div>\n<p>#investing #cybersecurity #musthave #CFOs<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Good morning. As the U.S.\u2013Iran&hellip; <\/p>\n","protected":false},"author":1,"featured_media":26333,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[2],"tags":[529,526,528,527,530,532,531,533],"_links":{"self":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/26332"}],"collection":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=26332"}],"version-history":[{"count":0,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/26332\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/media\/26333"}],"wp:attachment":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=26332"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=26332"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=26332"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}