Why the business case for doing nothing is dead — and how to right-size the investment before an incident writes your budget.
By Manny Farr, Chief Financial Officer, Gadget Access & CiBRAI
The old boardroom question was: "Can we afford cybersecurity this year?" The financially responsible question is now: "What level of disruption, loss and loss of trust can we afford — and what is the least-cost sequence of actions that keeps those consequences within tolerance?"
Drawing on a 45-year career across accounting, investment banking and operating businesses, Manny Farr sets out why deferring cyber uplift is simply self-insuring a loss that has never been priced — and how a CFO should size, sequence and evidence the investment instead.
Enter your work email and we'll send the full paper — 13 pages of evidence-based, plain-English financial reasoning on cyber uplift — straight to your inbox.
We'll email you the download link and occasional CiBRAI insights. No spam, unsubscribe any time. See our Privacy Policy.
Manny Farr is Chief Financial Officer of Gadget Access and CiBRAI. Across a 45-year career spanning accounting, investment banking, financial management and Finance Director roles with SMEs in Australia and overseas, he has helped businesses make difficult capital decisions. He was most recently CEO of a Sydney-based plastics manufacturing organisation. At Gadget Access and CiBRAI, he oversees financial planning, governance, capital discipline and commercial strategy.
Manny's focus is practical: cybersecurity investment should protect continuity, strengthen insurability, support credible growth and produce evidence that stands up when the business is under pressure.
The paper provides general business commentary. It is not legal, accounting, insurance or financial-product advice. Figures are drawn from published ASD, OAIC, IBM and public company sources, current to 28 August 2026; full source notes and qualifications are included in the paper.