Funding Cyber Readiness As An Operating Capability
David Etue is Chief Executive Officer of Cyberbit and a Senior Fellow at the National Security Institute’s Cyber and Technology Center.
gettyBoards, the C-suite and the cybersecurity team all want to know the answer to the same question: Are we ready to deal with a cybersecurity incident?
Despite that collective security desire, budgeting processes have not matured to ensure the desired outcomes. Organizations are making significant investments in SIEM, XDR, EDR, identity and cloud security platforms (to name a few), as well as in developing human capital on the cybersecurity team.
However, those investments deliver their promised value only when people can use them under the conditions that matter: with incomplete information, competing alerts, time pressure and cross-functional decisions.
However, based on the conversations I’ve had with security leaders as the CEO of a cyber readiness platform, many organizations struggle to drive this critical aspect of their cybersecurity program.
The investment to ensure the human operating layer is capable in proportion to the tools it is expected to run is too often labeled as “training.” Technical excellence matters, but it is the cost of admission. Training is an imprecise term, and one only tangentially related to the readiness goal.
When budgets get tough, training’s fuzziness becomes problematic. Training, especially under the umbrella of learning and development, can be delayed or cut without changing a business process, decommissioning technology, migrating systems or reducing personnel. It is treated as a bonus investment rather than a capability the organization has committed to maintaining.
From what I’ve seen, when a reduction in force or broader cost action arrives, it is among the first things to go. Those decisions directly impact readiness.
Boards do not generally care whether the cybersecurity team is trained or resilient. They want to know whether it is ready. When human capability is aligned to the security operating model and measurable readiness outcomes, the investment gains broader support and stability.
An analyst can complete a course, earn a certification and understand a technology in isolation, yet the organization can still fail when an incident requires team collaboration.
Readiness is demonstrated when the team can use its actual tools, telemetry, playbooks and escalation paths to detect, investigate, contain and recover from an attack. Readiness is a team outcome under realistic conditions.
Organizations routinely approve substantial investments in security technology, but those tools do not create outcomes alone. Their value is realized when analysts and incident responders can recognize meaningful signals, make sound decisions and coordinate action under pressure.
Security leaders should fund the people operating these platforms in proportion to the technology investment they must turn into outcomes. That is the logic a CFO understands and values.
Don’t mistake this as an argument against technical training. Technical skills, including foundational skills, technical currency and role-specific knowledge, are table stakes. In competitive talent markets, providing upskilling opens additional hiring paths and allows you to hire for culture and potential versus a defined skill set.
But course completion, attendance and certifications show participation, not whether the organization can manage a ransomware event, credential compromise, cloud intrusion or other incidents when speed, judgment and coordination matter.
Security leaders should not ask to fund “training.” That language sounds optional in many corporate cultures. Instead, frame the investment around outcomes:
• Reduce operational risk by testing response capability before an attacker does.
• Validate current technology investments.
• Identify people, process and technology gaps before an incident exposes them.
• Improve time to triage, investigation, escalation, containment and recovery.
• Strengthen coordination between security operations and incident response teams.
• Reduce costly mistakes during a breach.
These outcomes turn readiness investments from a discretionary purchase into a governed operating commitment that is visible in the security program, annual operating plan and leadership scorecard.
Now your human capital investment is reporting on an established operational control, its performance, its gaps and the investment required to sustain it.
Few organizations have a defined “cybersecurity readiness” budget today.
Because of this, I’ve seen many projects where readiness funding often appears late in the buying cycle. It is sourced from leftover budget or split inconsistently among HR, L&D and the security operations center. A request for training competes with other workforce-development priorities. A request to validate the organization’s ability to protect critical services belongs in the risk-management and resilience conversation.
That distinction determines where the budget belongs. Ideally, readiness should be owned by the CISO given their accountability for preventing, managing and recovering from operational disruption.
However, that mission can still be achieved with budget in other areas with the right organizational alignment.
An outcome focus is critical; however, compliance is often overlooked in its value in readiness funding, even if it does not create the business case. Many compliance regimes require incident response plan testing and responder preparation. NIST similarly treats incident response exercises and tests as mechanisms for evaluating program performance and preparing staff and involved third parties for future response activities.
• Move readiness into the security operating budget. Own the line item in the CISO, SOC, incident response or enterprise resilience function rather than HR or L&D. Tie it to priority threats, critical services and the platforms the team operates every day.
• Fund the human operating layer in proportion to the tool stack. Size the readiness investment against the SIEM, XDR, EDR, identity and cloud security spend it converts into outcomes and present it as operational risk reduction and validation of technology already purchased. That is the case a CFO recognizes.
• Govern readiness on measured outcomes. Replace attendance and certification metrics with response speed, investigation and escalation quality, playbook execution and cross-functional coordination. Set an annual live-fire exercise cadence, critical-scenario coverage and accountable remediation deadlines, then report progress through the security program, annual operating plan and leadership scorecard.
That is the bridge from compliance to readiness: Responders need repeated practice using the alerts, telemetry, workflows and escalation paths that will shape a real incident.
Compliance may be the guardrail, but readiness is the outcome. The program validates that existing security investments will function as intended when people are under pressure.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


