How CFOs Can Bridge the Integration Gap Between Cybersecurity and Enterprise Risk Management
APQC research shows that despite high awareness of cyber risk, most enterprises still keep it outside enterprise risk management (ERM), leading to insufficient risk visibility and slow decision-making. Based on data from 5,000 organizations globally, this article points out that only 41% have achieved meaningful integration, and 23% apply unified risk management to suppliers. CFOs can use four levers—governance embedding, financial articulation, process integration, and ecosystem extension—to make cyber risk an enterprise-wide responsibility and enhance organizational resilience.

This article is a guest post by Kelley Pruetz, APQC's lead research principal, and contributor Kristen Senz. The views expressed are solely those of the authors.
Preventing data breaches requires far more than a strong cybersecurity defense. Yet in many organizations, cyber risk remains outside of enterprise risk management (ERM), which limits visibility into emerging risks and slows decision-making to reduce risk exposure before events occur.
Despite cyber risk being widely recognized as a multidimensional threat with serious financial implications, this disconnect persists. Based on data from 5,000 global enterprises, new research from the American Productivity & Quality Center (APQC) shows that only 41% of organizations have achieved any meaningful integration between cybersecurity and ERM. Only 23% apply a unified risk management framework to suppliers and partners, despite the growing role of third parties in major breaches. Few organizations consistently articulate cyber risk reduction in financial terms to support enterprise-level decisions. The data is clear: awareness is high, but coordination is low.
Organizations that connect cybersecurity with ERM gain a more comprehensive view of risk, enabling earlier detection, more coordinated responses, and faster recovery. Integration transforms cyber risk management from a defensive function into a shared enterprise responsibility, anchored in governance, embedded in business processes, and reinforced through executive-level collaboration.
The challenge for financial leaders
Financial leaders play a central role in how enterprise risk management actually operates. ERM is designed to provide organizations with a common language for weighing risks, allocating resources, and making trade-offs under uncertainty. When cyber risk remains outside this framework, the finance function loses visibility into risk exposure, and coordination suffers.
Stronger cyber-ERM integration is associated with coordinated governance, shared metrics, and embedding cyber risk into business processes and decision-making practices. Financial leaders, by virtue of their existing roles in governance, measurement, and enterprise decision-making, are uniquely positioned to influence these conditions.
Here are four practical levers financial leaders can use to foster a more unified approach to risk management:
1. Bring cyber risk into enterprise-level conversations
One of the most effective ways financial leaders can promote better integration is through governance. In many organizations, cybersecurity is still deliberated in separate forums, disconnected from the ERM structures that shape enterprise priorities. Organizations with higher integration are more likely to review cyber risk through standing ERM governance, including risk committees and board-level reporting. This visibility is critical. Issues that consistently appear in enterprise forums gain attention, resources, and follow-up.
Financial leaders are often at the center of these governance structures. By ensuring cyber risk is discussed alongside financial, operational, and strategic risks, they normalize it as an enterprise issue rather than a technology update.
2. Insist on financial expression that supports leadership decisions
Another key lever is how cyber risk is measured and communicated. Few organizations consistently articulate cyber risk reduction in financial terms, even though cyber incidents are widely recognized to have financial consequences. Without this translation, cybersecurity investments often compete at a disadvantage against other priorities.
Financial leaders are uniquely positioned to change this dynamic. By asking how specific controls reduce risk exposure, limit downtime, or protect revenue, you can help translate cyber risk into the ERM context. Precision is not the goal. Even directional estimates help leaders compare options and align investments with risk appetite.
3. Connect cyber risk to business processes
Organizations with stronger cyber-ERM integration embed controls and monitoring directly into business processes, with security teams working with end-to-end process owners on critical handoffs. This more decentralized approach reflects where cyber risk most often emerges: not within individual systems, but in the seams where data flows and access increases, across teams and third parties.
Financial leaders can solidify this integration through ERM by reinforcing process ownership. Many high-risk processes in an organization cut across finance, procurement, and shared services. By pushing risk discussions into these workflows, CFOs help ensure cyber risk exposure is addressed where decisions are made and work is executed. ERM becomes less of a static risk register and more of a daily risk management practice.
4. Extend ERM thinking to the broader ecosystem
Financial leaders can also help broaden the scope of ERM by driving more consistent oversight of high-impact suppliers and partners. This does not mean treating all vendors the same, but rather applying ERM principles—clear accountability, shared standards, and continuous monitoring—to areas with the greatest risk exposure.
When third-party risk is managed through ERM rather than one-off assessments, organizations gain earlier visibility into emerging issues and have more levers for action. Ecosystem-level integration enhances resilience without adding bureaucratic burden.
Resilience by design
An organization's ability to withstand cyber incidents is shaped long before any system alert is triggered. Preparedness depends on risks being visible early, understood in context, and governed in ways that support coordinated enterprise action. When cybersecurity operates in isolation, these conditions are harder to achieve.
As cyber risk is more fully integrated into ERM, preparedness improves. Governance practices surface issues earlier. Process-level integration clarifies accountability. Shared metrics help leaders assess trade-offs more meaningfully. ERM provides the structure that connects these elements without replacing the technical rigor needed to manage cyber risk on a day-to-day basis.
For financial leaders, the role is not to direct cybersecurity efforts, but to ensure technical insights flow into enterprise decision-making. By strengthening integration through governance, measurement, and cross-functional collaboration, CFOs and their teams can enhance the organization's confidence in anticipating, responding to, and recovering from disruptions.