CFO Perspective · Australia · August 2026

The CFO Says Yes to Cybersecurity

Why the business case for doing nothing is dead — and how to right-size the investment before an incident writes your budget.

By Manny Farr, Chief Financial Officer, Gadget Access & CiBRAI

"The cost of doing nothing is not zero. It is an unfunded liability whose amount, timing and creditor are unknown." Manny Farr — CFO, Gadget Access & CiBRAI
A$4.22m Average cost of an Australian data breach IBM 2026 sample
84,700+ Cybercrime reports to the ASD in 2024–25 — about one every six minutes ASD 2024–25
A$56,600 Average self-reported loss per report for a small business (A$97,200 medium, A$202,700 large) ASD 2024–25
1,205 Notifiable data breaches in 2025 — the highest annual total since the scheme began OAIC 2025
Finance discipline applied to cyber risk

The question has changed

The old boardroom question was: "Can we afford cybersecurity this year?" The financially responsible question is now: "What level of disruption, loss and loss of trust can we afford — and what is the least-cost sequence of actions that keeps those consequences within tolerance?"

Drawing on a 45-year career across accounting, investment banking and operating businesses, Manny Farr sets out why deferring cyber uplift is simply self-insuring a loss that has never been priced — and how a CFO should size, sequence and evidence the investment instead.

Inside the paper
  • The numbers CFOs must not confuse — reading ASD, IBM and OAIC figures as different lenses, not one forecast.
  • The breach P&L — why the visible invoice is the smallest part of the balance-sheet impact.
  • Four Australian balance-sheet lessons — Medibank (A$160.8m), Optus (A$140m), Service NSW (A$25–35m), Noosa Council (A$1.7m).
  • Insurance is a backstop, not a business model — what a policy can and cannot do.
  • The CFO's right-sizing model — five steps from "what must keep trading" to reusable evidence.
  • Eight questions every CFO and owner should ask — in plain business language.
Cover of The CFO Says Yes to Cybersecurity by Manny Farr
Get the CFO Perspective

Read it before your next budget conversation.

Enter your work email and we'll send the full paper — 13 pages of evidence-based, plain-English financial reasoning on cyber uplift — straight to your inbox.

We'll email you the download link and occasional CiBRAI insights. No spam, unsubscribe any time. See our Privacy Policy.

No sales follow-up unless you ask Link delivered by email Unsubscribe any time

About Manny Farr

Manny Farr is Chief Financial Officer of Gadget Access and CiBRAI. Across a 45-year career spanning accounting, investment banking, financial management and Finance Director roles with SMEs in Australia and overseas, he has helped businesses make difficult capital decisions. He was most recently CEO of a Sydney-based plastics manufacturing organisation. At Gadget Access and CiBRAI, he oversees financial planning, governance, capital discipline and commercial strategy.

Manny's focus is practical: cybersecurity investment should protect continuity, strengthen insurability, support credible growth and produce evidence that stands up when the business is under pressure.

Manny's CFO view

"CFOs are trained to say no to spending without a return. That discipline is healthy. But 'not now' has stopped being a prudent answer to cyber risk. The right answer is yes — at the right size, in the right order, with evidence."

The paper provides general business commentary. It is not legal, accounting, insurance or financial-product advice. Figures are drawn from published ASD, OAIC, IBM and public company sources, current to 28 August 2026; full source notes and qualifications are included in the paper.