How to Justify Security Spending When Nothing’s Gone Wrong

TL;DR: Justifying security spending is hard because the payoff is an absence of events, which looks like luck. The strongest case isn’t a threat briefing. It’s the fact that your insurer and your customers already require these controls, and your policy only pays if you can prove they were running. Use your renewal questionnaire as the roadmap.

Justifying security spending gets hard at exactly the moment things are going well. Systems are stable. Nobody’s been breached. And you’re in a budget meeting asking for money to prevent something that, as far as anyone in the room can tell, wasn’t going to happen anyway.

Every other request has a visible outcome attached. A new platform speeds up billing. A hire adds capacity. Security offers resilience, faster recovery, and reduced exposure, which are real things that photograph badly in a spreadsheet.

So it gets deferred. Not rejected, usually. Just moved to next quarter, behind the things that produce something you can point at.

The City of Hamilton, Ontario deferred one. In the fall of 2022, staff knew their cyber insurance policy required multi-factor authentication. They started a pilot the next year, in a handful of departments. In early 2024 they were preparing to finish the rollout. On February 25, ransomware hit first.

Why is security spending so hard to justify?

Because the return is an absence of events, and absence looks like luck. Every other investment produces something visible. Security produces a quiet week, which looks exactly like a quiet week you’d have had anyway. That’s the real problem, and better slides don’t solve it.

It gets worse the longer your record stays clean. Three quiet years feel like proof the spending is unnecessary, when they’re just as likely proof it’s working. Nobody can tell from the inside which one they’re in.

Arguing harder doesn’t fix that. Finding the parts of the case that aren’t invisible does, and there are more of them than most people bring to the meeting.

“Nothing happened” is a result, not an accident

There’s real evidence that controls change outcomes, and it comes from the people who pay when things go wrong. Coalition’s 2026 Cyber Claims Report found that a record 86% of businesses hit with ransomware in 2025 refused to pay, which the insurer attributes to organizations having workable backups and incident response plans in place. In the same data, 64% of closed claims were resolved with no out-of-pocket loss for the policyholder.

Read that as a business case, not a security statistic. The companies walking away from seven-figure ransom demands aren’t lucky. They’re the ones who paid for backup and recovery they’d actually tested before they needed it. That spending turned a catastrophe into an expensive week, which is a story leadership can follow because there’s a decision in it.

Your cyber policy is a conditional promise

Most owners think of cyber insurance as risk transfer. Buy the policy, move the exposure off the balance sheet, get on with the business. That’s not what the document says. A cyber policy is a conditional promise, and the conditions are the exact controls you keep postponing.

Hamilton found out in July 2025. The attack took down most municipal services for weeks. The city refused to pay the ransom and spent roughly $18.3 million rebuilding. When it filed a claim of about $5 million, the insurer paid none of it, citing the policy’s position that no coverage applied where missing MFA was a root cause. An independent review found the denial consistent with the policy.

The city’s own IT leadership argued the breach would have happened even with MFA fully deployed. It didn’t matter. The condition wasn’t met.

That’s the argument that moves budget, and it has nothing to do with hackers. The risk you thought you’d transferred is still on your side of the table, and it stays there until the controls you attested to are real and provable. A policy in a drawer isn’t protection. It’s a receipt for a promise with conditions attached.

What do insurers require in 2026?

Multi-factor authentication across email, remote access, and admin accounts, endpoint detection and response on every device and server, backups that are isolated and restore-tested, a written incident response plan, and documented security awareness training. What’s changed is that carriers want evidence now, not a checked box.

Underwriting has stopped being a form and become an audit. Applications that once ran two dozen yes-or-no questions now ask for coverage reports, configuration exports, and the date of your last restore test. Several carriers scan your environment externally before they quote.

That shift is inconvenient and it’s also the best budget tool you’ve been handed in years. Your renewal questionnaire is a security roadmap written by someone with no stake in your internal politics, aimed at your business, with a deadline attached. It costs nothing and it’s already in your inbox.

There’s precedent behind the strictness. In a 2022 Illinois federal case, Travelers moved to rescind a cyber policy after finding a customer had attested to MFA that wasn’t deployed, and the policy was declared void from its start date. Intent wasn’t the issue. Accuracy was.

How do you build the business case?

Lead with requirements that already exist, then attach numbers to the gaps. Four arguments do most of the work, and none depend on predicting an attack:

  1. The insurance condition. Name each control the policy requires, and mark which ones you can prove today. Every unmarked line is uninsured exposure.
  2. The customer requirement. Security questionnaires from clients are now routine in professional services, manufacturing, and anything touching regulated data. Losing a contract is a number people understand.
  3. The recovery number. How long to restore operations after ransomware, based on your last real test? If you’ve never tested, that’s your first ask, and it’s cheap.
  4. The priced option. Every gap gets a fix, a cost, and the risk that remains afterward. Leadership can decide between options. They can’t decide about worry.

Frame it as reducing uninsured exposure rather than preventing attacks. One is a finance conversation. The other is a weather forecast.

What to do before your next renewal

Start 60 to 90 days out and treat it as a gap analysis, not paperwork. Walk each control the carrier asks about, confirm whether you can produce evidence, and fix or formally document what’s missing before you submit. An outside reviewer helps here, which is ordinary cybersecurity consulting work.

Look hard for drift. Controls decay quietly: an MFA exception granted for one executive and never revoked, an EDR agent that fell off a server during a rebuild, a backup nobody has restore-tested in eighteen months. Each was true when you answered the question last year.

Then build an evidence pack and keep it current. MFA coverage reports, endpoint deployment reports, dated restore test results, your incident response plan, and training records. That’s standard work in a managed IT services engagement, and it makes next year’s budget conversation take ten minutes instead of an hour.

The takeaway

You’ll rarely win a security budget by describing what might happen. You’ll win it by showing what’s already required, what you can’t prove today, and what each gap costs if a claim gets tested.

Hamilton wasn’t careless. They knew the requirement, started the work, and ran out of time because nothing had happened yet. That’s the ordinary version of this failure, and the one worth avoiding.

If you’d like help mapping your controls against what your carrier and customers are asking for, set up a short call.

Frequently Asked Questions

How do you justify cybersecurity spending to leadership?

Anchor it in requirements that already exist rather than threats that might. List the controls your policy and customer contracts require, show which you can prove today, and price the gaps. That turns open-ended worry into a decision with options.

Can a cyber insurance claim be denied for missing security controls?

Yes. Policies tie coverage to the controls you attested to on the application, and carriers verify them after an incident. The City of Hamilton’s roughly $5 million claim was denied because multi-factor authentication had not been fully deployed when ransomware struck.

What security controls does cyber insurance require?

Commonly MFA on email, remote access, and admin accounts, endpoint detection and response across all devices, isolated and tested backups, a documented incident response plan, and security awareness training. Carriers increasingly want evidence each was running, not just a yes.

What if we’ve never had a security incident?

That’s a reason to check whether your controls work, not evidence that spending is unnecessary. A clean record and an undetected gap look identical from the inside. Your insurance questionnaire and a restore test will both tell you which you have.

How far ahead should we prepare for a cyber insurance renewal?

Roughly 60 to 90 days for a clean renewal. If you need to deploy new controls first, give yourself four to six months, since identity, endpoint, and backup projects rarely finish on schedule.

Find Out What You Can Actually Prove

Most businesses find the gap between the controls they think they have and the ones they can document at the worst possible time. Z-JAK helps Louisville businesses close it before a questionnaire or a claim puts it to the test. Start a conversation and we’ll walk through where you stand.