Ask a leadership team what they spend on security and someone can find the number. Ask what threats that spend is pointed at and the room goes quiet. That silence is the most expensive thing in the budget.

The autopilot problem

Security budgets in mid-sized companies are mostly archaeology. Each line item is a decision someone made years ago, for a threat that was in the news at the time, renewed annually because renewal is the path of least resistance. Nobody re-asks the threat question, because no one owns re-asking it.

The result is a budget shaped like the past. Overspend where risk is low, because the tool is familiar and the invoice is expected. Blind spots where risk is high, because the threat arrived after the budget did. The company is defended. Just not this company, this year.

What the tabletop record shows

The pattern is not theoretical. Across 150+ executive tabletop exercises I have facilitated, 87% of organizations had not tested backup recovery in the previous six months, 93% could not confirm who had authority to take production systems offline during an incident, and 91% had no one in the room who could cite their cyber insurance notification timeline. These are not expensive gaps to close. They are unowned gaps. Meanwhile the same organizations were current on every renewal.

The threat-to-spend conversation

The fix is one structured conversation a year, run before renewal season. List the top five threats to this business ranked by likely cost, not by headline. Map every material line of security spend to the threat it addresses. Then look at the two lists side by side.

Three things fall out immediately. Spend mapped to no current threat, which is your recovery budget. Threats mapped to no spend, which is your exposure. And controls that exist on paper but have never been rehearsed, which are your comfortable illusions. The 72-hour question settles the last category fast. If the incident started Friday night, who does what by Monday morning, and when did we last practice it?

Treat it as capital allocation, not technology

This is a CFO conversation as much as a CISO conversation. Security spend is capital allocated against loss scenarios, and it deserves the same discipline as any other allocation. When leadership teams run it that way, the budget usually does not grow. It moves. That is the point. The goal is not to spend more on security. It is to point what you already spend at what actually matters.

If you want the version with a score, a gap analysis, and named owners, that is what a threat readiness review produces. If you run it yourself, run it before the next renewal, not after the next incident.