Guides·28 August 2026

The CFO's Guide to Cyber Risk, Financial Resilience and Recovery

How finance leaders should quantify cyber exposure, test what insurance really transfers, and judge whether recovery investment is proportionate to the loss it prevents.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
6 min read
Share
The CFO's Guide to Cyber Risk, Financial Resilience and Recovery
Guides

Why it matters

What this means for organisations holding critical data

How finance leaders should quantify cyber exposure, test what insurance really transfers, and judge whether recovery investment is proportionate to the loss it prevents.

Who this guide is for

This guide is written for chief financial officers, finance directors and audit committee members who are asked to fund cyber security without a reliable way to price the risk it removes.

What finance is actually responsible for

  • Quantifying exposure: business interruption, recovery cost, regulatory cost and claim outcomes.
  • Deciding how much risk is transferred through insurance and how much is retained.
  • Protecting liquidity through a period when invoicing, payroll and collections may be degraded.
  • Ensuring financial controls survive an incident, including payment authorisation and supplier verification.
  • Reporting cyber risk truthfully in the annual report and to lenders and insurers.

The decisions you own, and what you can delegate

  • Own the loss model, the insurance structure, the retained risk and the capital allocation.
  • Own the working-capital plan for an outage of several weeks.
  • Delegate control selection and architecture to the CIO, CISO and IT leadership.
  • Delegate technical testing, but require the recovery times used in your model to be evidenced.

How to size the exposure

Most cyber business cases fail because they price the control rather than the loss. Build the loss first.

  1. Identify the revenue-bearing processes and the daily contribution each one carries.
  2. Take the recovery time the business would actually achieve, not the target in the policy document.
  3. Add the recovery cost: incident response, legal, forensics, overtime, temporary manual process, customer credits.
  4. Add the regulatory and contractual cost, including notification, remediation and service credits.
  5. Subtract only what the insurance policy will genuinely pay, after the waiting period and sub-limits.

The residual figure is the number that justifies, or fails to justify, spend. Investment is proportionate when it materially shortens recovery time for the processes that carry the largest daily loss.

Cyber insurance, read properly

  • The waiting period often removes the first day or two of business interruption cover entirely.
  • Cover for systems the insured does not own, including cloud providers, is frequently sub-limited.
  • Warranties about backups, multi-factor authentication and patching can affect a claim if they are not met.
  • Ransom payment cover is narrowing, and sanctions rules may prohibit payment regardless of cover.
  • Insurers increasingly price physical isolation and tested offline recovery favourably. Ask your broker directly.

The questions to ask

  1. What is our modelled loss per day for each critical process, and who agreed it?
  2. What recovery time can we evidence, as distinct from the one we have planned for?
  3. What exactly would our policy pay in the scenario we are most worried about?
  4. Can we run payroll and pay critical suppliers if our finance systems are unavailable for two weeks?
  5. Which financial controls depend on systems an attacker would hold?

The evidence to expect

  • A dated restore test with measured durations for the finance stack.
  • A written business interruption model agreed between finance and IT.
  • A policy review noting waiting periods, sub-limits and warranties.
  • A manual payment and verification process that does not depend on email.
  • A supplier concentration list with financial exposure attached.

What happens when preventative controls fail

Prevention buys time. It does not remove the need to answer a simple question: if an attacker holds your identity platform and your management console tonight, what still works tomorrow morning? Most organisations discover that their backup catalogue, their recovery credentials and their runbooks all depend on the systems that have just been taken. That is the dependency worth removing first.

No control removes the possibility of a serious incident. The realistic goal is a smaller blast radius, a recovery path that does not depend on the compromised estate, and evidence that both were tested.

Deciding what you actually need

Finance should judge this as risk reduction per pound, not as engineering. The relevant question is which option shortens recovery for the processes carrying the highest daily loss. Firevault is the company. It provides three distinct things, and the honest answer is often that you need one of them rather than all of them.

  • Offline Secure Storage® holds a defined set of critical records and clean recovery data physically disconnected from the live estate. It is a protected set, not a replacement for your backup infrastructure.
  • Control Modules are a suite of nine purpose-built tools and techniques that give you physical control over the paths into and across your estate. Introduce only the modules that map to the risk you are treating.
  • Control Blueprints are proven combinations of those modules assembled for a named outcome, such as containing a live breach or governing third-party access.

If your existing controls already deliver a tested recovery path that survives the compromise of your identity and management planes, and you can evidence it, you may not need any of this. Test that assumption before you buy anything. If you are unsure which of the three applies, the Firevault Concierge walks through the question set without a sales conversation.

The Control Blueprints most relevant to this role

These are the patterns most often justified on financial grounds. Control by Firevault is a set of nine Control Modules, grouped into the FIRE layer (Firebreak, Isolate, Relay, Execute) and the VAULT layer (Validate, Archive, Unlink, Lock, Transfer). Seven Control Blueprints combine those modules for a specific outcome. You do not need all nine modules, and most organisations start with one blueprint.

The full set is on the Control overview and the Control Blueprints index.

Where to go next

For the governance view, read cyber security for boards. For the recovery mechanics behind your assumptions, read the IT director guide to ransomware recovery. Our note on cyber insurance and physical controls covers the underwriting conversation.

Sources and further reading

About this guide

Author Mark Fermor, Firevault. Reviewed by Firevault advisory board. Last reviewed 28 August 2026.

This guide draws on primary regulatory and technical sources together with Firevault's own field work on physical isolation and offline recovery. It is guidance, not legal advice. Where a legal or regulatory duty is in question, take advice on your own circumstances.

Other guides in this series are listed on the role guide hub.

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

HardwareYour copy sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
RecoveryA known-clean copy to rebuild from, on your timetable
LocationHeld in a secure Firevault Bunker
Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up