The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Cyber Security Business
Cyber Security Business artwork

Cybersecurity Budgets

Cyber Security Business · 2023-11-01 · 19 min

0:00--:--

Key moments - from our scoring

Substance score

55 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality9 / 20
Guest Caliber13 / 20
Specificity & Evidence12 / 20
Conversational Craft10 / 20

Chuck Thomas shares practical budget planning strategies from his five years managing security operations at Blue Cross Blue Shield Rhode Island. Rather than focusing on dollar amounts alone, he advocates quantifying employee time as a cost metric and using data-driven justification to secure approvals - a discipline that's helped him consistently get budget approval from his CISO and business leadership. His key insight: successful budget requests require simplifying threats and technology for non-technical stakeholders, avoiding the perception of "toys for IT to play with," and presenting realistic asks upfront rather than incremental requests. Thomas discusses how he transitioned vulnerability management from a manual, labor-intensive process to an automated one, improving results by 95% while justifying the technology investment through time and KPI metrics. He also touches on emerging budget pressures - including API vulnerability expansion and the future impact of AI and ChatGPT on security staffing - while emphasizing that budgets at regulated companies like healthcare aren't necessarily immune to pressure to do more with less. His closing advice centers on metrics: compliance benchmarks, time-to-value calculations, tool downtime analysis, and regulatory alignment (HIPAA, GDPR) as the storytelling backbone of any budget pitch.

Key takeaways

  • →Use time-tracking and employee cost metrics as financial justification for technology investments, not just dollar amounts, to demonstrate real ROI when asking for budget increases.
  • →Automate labor-intensive security processes only after proving with metrics that manual approaches are failing - Thomas improved vulnerability management results by 95% post-automation.
  • →Frame budget requests in business language for non-technical stakeholders: explain threat severity, avoid IT jargon, and always show realistic, complete asks rather than incremental requests.
  • →Monitor and quantify security tool downtime as a cost metric; presenting downtime data can justify tool replacements and earn budget approval for infrastructure improvements.
  • →Build flexibility into annual budgets by establishing a mid-year funding request process tied to emerging gaps, allowing you to secure additional funds if justified with proper business case documentation.

In this episode

  1. 1Chuck's Background and Role at Blue Cross
  2. 2Budget Planning Process and CISO Input
  3. 3Justification Through Metrics and KPIs
  4. 4Vulnerability Management Automation Success
  5. 5API Security and Emerging Threats
  6. 6Security Budgets in Economic Downturns
  7. 7AI and ChatGPT Impact on Security Teams
  8. 8Key Advice: Metrics-Driven Budget Justification

Mentioned

K logixBlue Cross Blue Shield of Rhode IslandKevin PoucheChuck ThomasMicrosoftChatGPTHIPAAGDPR

Guests

Chuck Thomas

Topics in this episode

API securityHIPAA complianceGDPR complianceVulnerability Management AutomationSecurity Tool Downtime MetricsKPI and KRI MeasurementChatGPT and AI in SecurityBudget JustificationInformation Security OperationsEmployee Time Cost Analysis

Questions this episode answers

How should you justify a new cybersecurity technology investment to leadership?

Present data-driven metrics showing how current manual processes are failing (time spent, poor results, compliance gaps), then demonstrate the cost-benefit of automation by quantifying employee time savings and improved KPIs. Simplify the threat explanation in business terms and show realistic, complete asks upfront rather than incremental requests.

What happens if you don't spend your entire annual security budget?

Unspent budget is clawed back unless you have a valid plan to reallocate it to another security initiative. At Blue Cross, leadership recovers unused funds, though they'll approve reallocation if you present a good business case.

Can you request additional security budget mid-year if a gap emerges?

Yes, Blue Cross Blue Shield allows mid-year funding requests if you present your case to senior business leadership (not just IT) with proper justification - explaining the gap in layman's terms and demonstrating real value and ROI.

How do healthcare security budgets compare to other industries during economic downturns?

Healthcare security budgets face similar pressure to do more with less, but regulated industries like healthcare have additional compliance requirements (HIPAA, GDPR) that provide some justification for maintaining or growing security spending.

How might AI and ChatGPT change cybersecurity budgets in the next five years?

Chuck expects AI to augment both people and technology, making security teams more nimble and efficient; security staff will do more with less because AI co-pilots will automate research and problem-solving, though new job categories may emerge as a result.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

The episode offers some practical advice on budget justification and the value of metrics, but much of the content is generic best-practice guidance (e.g., 'bring metrics to justify spending,' 'simplify for lay audiences') that security leaders have likely encountered before. The vulnerability management automation example provides concrete detail, but the episode lacks novel frameworks or counterintuitive insights that would substantially change how an operator approaches budgeting.

metrics, metrics, metrics, and have good data, and the data should be able to tell the story
if there's another area where we've tried our approach with the people-powered approach and we're just not seeing the results, that's when we'll kind of branch out and look for a different way of doing things

Originality

9 / 20

The thinking is sound but conventional: use metrics to justify spend, frame technology as a business problem not an IT toy, prioritize automation over headcount, and pivot mid-year if new threats emerge. These are well-trodden paths in security budgeting. The AI speculation at the end ('co-pilot' augmentation) is topical but speculative rather than grounded in original analysis or contrarian insight.

you really have to be realistic with what you're asking for. Don't ask for something small because you're not going to have probably a second opportunity to get more money
it needs to be some kind of real value proposition for what you're kind of buying

Guest Caliber

13 / 20

Chuck is a credible practitioner - an Information Security Operations Manager at a large regulated healthcare organization with five years tenure - who has actually managed budget cycles and tool implementations. However, he is not a C-level executive or strategist; his perspective is middle-management operational, and he operates within an organization with apparently generous budget flexibility (rare at most firms), limiting the universality of his insights.

I'm the security operations manager for Blue Cross Blue Shield Rhode Island. In a nutshell, what that essentially means is I manage almost all of our security tools
I'm about to enter my fifth year in the role, and I am proud to talk about, as I said, some of the movement I made in terms of our security posture

Specificity & Evidence

12 / 20

The episode includes one strong specific example (vulnerability management automation improving results by 95%) and mentions API security as a current initiative. However, most claims lack named products, concrete metrics, timelines, or budget figures. The discussion of HIPAA, GDPR, and tool downtime is vague. No actual budget numbers, savings data, or comparative analysis across organizations is provided.

when I first got the role, one of the programs we had to manage was our vulnerability management program...Once we got some automation into the pipeline, it was a one-time cost. we dramatically improved the state of that program by over 95%
this year, the theme has been to kind of build that same kind of program that we have for vulnerability management, but now taking that to the APIs

Conversational Craft

10 / 20

Kevin's questions are competent and logical (process, prioritization, economy impacts, ROI justification) but rarely push back or probe deeper. When Chuck makes claims - e.g., 'my company always funds good ideas' or speculative AI predictions - the host accepts them without follow-up skepticism. There is no challenging of potential bias, request for comparative data, or exploration of failure cases or constraints that might limit the applicability of Chuck's model.

Okay. Are there... Other specific areas, you know, there's no need to mention any products that you are allocating more budget for
Huh. Interesting. So, Chuck, what about the converse of that?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

budget17security16money13process12metrics11chuck9less9technology8blue7tools7terms7program7economy7results7data7automation6

Episode notes

We sat down with Chuck Thomas, Information Security Operations Manager at Blue Cross Blue Shield of Rhode Island, to discuss budget planning - how to approach it, how to do more with less, how to present and justify it to executives, and what to look out for - including regulations, AI and ChatGPT.

Full transcript

19 min

Transcribed and scored by The B2B Podcast Index.

Welcome to Cybersecurity Business. I'm your host, Kevin Pouche, COO of K logix. In our podcast, we interview CISOs and other security leaders to hear their advice on the business of information security. This podcast gives our listeners actionable takeaways to help them increase the effectiveness of their security programs.

Today, we're joined by Chuck Thomas, Information Security Operations Manager at Blue Cross Blue Shield of Rhode Island, where he's now been for over five years. Chuck has many years of experience managing different cybersecurity programs, and he's here to talk about budgets and budget planning, which is a pretty relevant topic considering most organizations tend to wrap their budgets up by the end of October. So, Chuck, welcome to the podcast. Well, thank you for having me, Kevin.

So to kick it off, Chuck, give everybody some background on your role at Blue Cross, how you got to the position as Information Security Ops Manager, the type of role that you report up to, and just give the audience an understanding of who Chuck is and how he got here. Sure. So I'm the security operations manager for Blue Cross Blue Shield Rhode Island. In a nutshell, what that essentially means is I manage almost all of our security tools.

I set the posture for how those programs that are associated by the tools are going to run. And how I got here is my journey actually started mostly on the risk side. And what happened was at the time I was reporting to our CISO and our CISO got promoted and there's some opportunities that came up. And when this opportunity kind of presented itself, I jumped at it.

And here we are. I'm about to enter my fifth year in the role, and I am proud to talk about, as I said, some of the movement I made in terms of our security posture. Okay. Well, let's get specific to that then.

How does your current organizations decide their program's budget for the current year? What's the process like? Yeah, so our CISO mostly controls the process. However, all of his leaders kind of come together and we all kind of give input on things that we want to kind of work on during the course of the following year, right?

So, you know, let's say one of his initiatives was to do something more with our endpoints, right? And as far as segmentation, I would definitely go into that meeting and kind of give him some ideas and pitches for things that I would like to do with my tools to kind of help. you know achieve his vision so ultimately as I said the CISO has the ultimate ultimate say but the rest of us all have input in the process okay so in terms of your input in the process how much does it change from year to year so for example do you tend to go through the same process for your organization from year to year or does that drastically change It's typically this.

I mean, for me so far, it's typically been, you know, generally the same process. Obviously, the threats and things that we're trying to protect may change from year to year, and that might definitely change the outlook of where I need funding to kind of close certain gaps. But as far as the process goes, the process is pretty consistent. And the one thing I like to say about Blue Cross is, you know, whenever I've had a good argument for.

doing something i've never been told no um as long as i bring all my metrics and you know a valid rationalization for why i need to do something blue cross will have enabled me to make it happen so okay so what will happen in terms of so for justification you'll bring metrics charts things like that to the table to your cso correct Okay. And typically you'll present a case and at least up until now, you tend to get what you want. That is absolutely correct. Okay.

Do you prioritize people over technology? Is there one that you tend to prioritize? And then how about sort of the state of the economy over the past couple of years? Have you been asked to do more with less?

Absolutely. So, you know, one of the things that I want to say our budget's been pretty much the same and has actually gone up a little bit. However, to your point, we are definitely asked to do much more but less all the time. So it definitely feels like our budget's going down, even though dollar amounts are still the same.

But the way I kind of see it is you can't always just look at the dollar amounts. You've got to look at employee time as well, which I also always view as another, you know. employee time is money right so if employees are spending more time that to me means more money right so typically if i'm in place or spending excessive amount of time we're not getting the results that we need i can kind of you know again present that in such a way to my leadership and say hey you know this is our metrics right now this is how we're doing um and this is how much time and energy it's taking us to get there.

And then basically what I can do is I'll map that against different approaches, right? I think the best example I'm going to give you about what we did here, when I first got the role, one of the programs we had to manage was our vulnerability management program. And that was a very, very laborious manual process. I knew coming into the job that, you know, If I continued on with the team that I had, I simply was not going to be successful.

So I argued for some automation, and I demonstrated that, hey, with the team of people that we have, the people -centric process, this is the results we're getting, and the results were just not good or not where I want them to be, right? Once we got some automation into the pipeline, it was a one -time cost. we dramatically improved the state of that program by over 95%. You know, when you look at where we were just two years ago to where we are now, it's night and day results just with some of the automation that we were kind of able to put in.

And again, I was able to rationalize that, which again, just some time value metrics as well as other KPIs about how terrible we were doing in that space until we made these necessary investments. Okay. Are there... Other specific areas, you know, there's no need to mention any products that you are allocating more budget for.

And if that's not something you're at liberty to say, maybe you can talk about the industry in general. So I would say, again, we're talking about emerging trends and threats and things, right? So the big thing for us this year has been kind of expanding our vulnerability management program and our footprint to kind of look at more than just endpoints. So we actually have expanded into more of that API space, right?

So this year, the theme has been to kind of build that same kind of program that we have for vulnerability management, but now taking that to the APIs and making sure that we're not necessarily exposing more than we then we should, right? So we're definitely actively looking at that currently. Okay. Now, you had mentioned a few minutes ago that even in a down economy, you still are seeing additional budget being allocated.

Based on what you know, either about your own organization or other organizations, is security being affected less than other departments? In a down economy in terms of budgets being slashed? Is it the same? I would say that probably every security department has the same pressures that we are.

Obviously, if you work in a regulated industry such as the one that I'm in, healthcare, you are definitely always, you know, again, when you think about HIPAA, right, it's a million feet wide but only two feet deep, right, which gives auditors and other compliance analysts a lot of levity in terms of like, hey, you should be looking at this, you should be looking at that. The reality is security teams are, you know, a certain size and they're only so many hours in a day. Right.

So, again, so. you know while my budget hasn't gone down we are definitely definitely asked to do more so one of the things that i've had to do is just got really really creative with my solutions right um so whenever i'm out there looking for a way to kind of do something i'm always looking for automation right because i can't necessarily grow my head count but i can definitely see if i can make my processes a little bit smarter and a little more effective to kind of close gaps that a human being necessarily isn't going to be able to achieve So by automation, would that involve investing in new technology?

Absolutely. Absolutely. Yes. So like on a percentage basis, how much is spent on continuing to operationalize what you currently have versus investing in new technology like automation?

So it's going to depend on what area I'm kind of looking at. You know, if there's a program that is working fine with the way it is, I probably wouldn't change the way I'm doing things in that space. But however, if there's another area where we've tried our approach with the people -powered approach and we're just not seeing the results, that's when we'll kind of branch out and look for a different way of doing things. And we'll definitely reach out to vendors and others in the space.

We'll talk to our peers, really, and get ideas on ways to kind of... to fix it um and that oftentimes takes us down a journey where you know then we make a decision right do we get this new product or we stick with the way it is right and then you got to do some more quantification about all right the asset i'm trying to protect is this much uh the new technology is going to cost this much is it something that's worth it are we good with what we have right so there is definitely a good bit of analysis that goes into the into that decision about which do we make the investment or do we stay with what we got And I and speaking of that, you know, I hear a lot of people talk about justification in terms of when it does come to a new spend.

Well, geez, I've given you X, Y and Z over the past few years. What what in the world are you doing with that? You're coming to me with more and more and more. Are you proactively doing that justification?

And basically showing out that you've maximized what you can divest, what you can consolidate, and only new spend can solve this issue. You are absolutely right, right? I think a lot of times when IT teams go to leadership to ask for money, obviously from an IT point of view, we know the technology and we understand the threat. But the typical lay person that you're kind of talking to may not necessarily have any idea how big the threat is or why it is.

So I think it's really important when you talk about technology with lay people to really simplify and really explain why that particular threat means something to my organization so they understand it. And then when you're asking for money, you really have to be realistic with what you're asking for. Don't ask for something small because you're not going to have... probably a second opportunity to get more money.

You're going to ask for something realistic kind of upfront, right? So, you know, you get the spend that you need to kind of achieve, get the desired result. And ultimately, you know, as I said, you need to, you just don't want to make it seem like it's another toy for IT to play with, right? There needs to be some kind of real value proposition for what you're kind of buying.

And as I said, when I've done that, I've always been typically effective in getting what I've needed to get. And is that, do you need to have that justification and that Final budget number in by October. Is that the season? So that's one way to do it.

The other way to do it is, let's say, hypothetically, you know, you get your budget, but then you go down the year and you realize, hey, you know, there's this gap that we have. Right. So at my company, we do have a process where we can definitely go ask for more money. You know, it's you know, you got to make your case in front of senior leadership in front of the business, not even IT at this point.

Right. And again, that goes back to, again, explaining in layman's terms what exactly you're trying to do so that people feel good about giving the money. And, you know, again, I think the big thing is. Most business people don't want to make it seem like, you know, they don't want just to give another toy to IT so they can play with.

It needs to be some kind of real return on investment. That's interesting. So your budget isn't necessarily set in stone for the year. If there is a need midway through the year and you have the proper justification, there could be discretionary funding that gets allocated to you.

Absolutely. And it happens all the time. Huh. Interesting.

So, Chuck, what about the converse of that? Let's say you did an amazing job doing more with less, as you said earlier, less people, less investment in technology, and you actually don't use up all the budget allocated to you. Will you lose that budget for the following year? Yes, unless you can kind of allocate to something else.

Yes, they will take that money away. You're not just going to be able to keep that extra balance in Europe. account for lack of better words right uh that money will be clawed back if you're not going to use it and quite frankly at the end of the day if you didn't need the money it's probably the right thing to do to give it back to the business but again if they gave you the money um and you have a it's already there you happen not to use it all if you have a good reason for where you want to kind of take that money again i've never experienced any pushback with that whatsoever of course as you said you know we're in a down economy right now so there is definitely pressure to kind of again demonstrate value with your tools and what you have right but at the same time there is something to be said about you know obviously you don't want to be holding you know hundreds of thousands of dollars that could be going somewhere else if you don't have a real anything to use it for, right?

So I would say, again, if you have a good plan with that money, no one's going to give you any grief. But however, at the same time, recognizing down economy, if I had that much leftover, I would probably tend to give some of that back, right? You know, given the state of things. Yeah, I mean, it's the right thing to do, right?

It's the right thing to do. You've been there for five years and you're clearly in it for the long game. So I think that makes sense. How about the rise of artificial intelligence, and chat GPT.

Does that affect budgets? Will it affect budgets? Not yet. However, I do think our industry is in for a, I would think within five years, you're going to see some major changes, right?

I think with the rise of AI and chat GPT and all this other stuff, I think you're going to see a move to security departments potentially getting nimbler, just because now you have this. i mean i'm gonna borrow a term for microsoft right you have a co -pilot kind of sitting next to you that can kind of help you all the hard stuff i believe is going to become a lot simpler with chat gpt kind of sitting right there next to you um if you have a question again the ability to ask that question in natural language and get a real answer back without spending hours and hours googling and researching it boy that's a game changer so i absolutely believe you're going to see some huge changes on industry within five years so does that so it sounds like what you mentioned could potentially be an augmentation of both people and technology absolutely 100 yep which is exciting and scary at the same time right absolutely but we've had these moments before and you know things have always kind of worked out and i kind of always believe that you know with ai you know it's like the jobs of the future that haven't been invented yet right i think there's gonna be new use cases that come out of the ai revolution that create new jobs that people haven't even thought about yet and that's what the economy of the future is going to be, right?

It's definitely going to be an economy of people kind of working side by side with machines and machines being able to do more and be able to mimic kind of like the person, right? So yeah, so we go back to doing more or less. Yeah, with AI, security teams are definitely going to be doing more or less, but the good news is you'll be able to be successful doing more or less because again, the AI will be able to kind of supplement any gaps that you may have and give you the answers you need in a quick, timely manner.

All right. Well, we have time for one more question. And so the question I'd love to close with is any sort of advice that you can think of for other security leaders when it comes to budget or budget planning, especially people that, you know, Chuck, haven't been doing this for 5, 10, 15 years like you have, like they're going into the year, maybe their budget's not set. right anything that comes to mind that you really want them to know absolutely get a good handle on your metrics and really have some good metrics right i kind of feel like when you have data um data should be able to tell the story of why where you are and where you want to get to and you know how and how to get there right um i find good metrics like trying to savings right again when i had my old program and like but i thought probably amazing before how brutal that process was the way we used to do it how many hours of consuming just quite frankly just the terrible results we're getting right um so have that data kind of showing hey um you know this is what i can get to if i do this right have some good measurements on your kpis and your kris right show some metrics about how compliant you are with the current regulations right um i'm sure you know as a healthcare company we have to be compliant with hipaa But somehow the companies have to be compliant with things like GDPR as well, right?

Like the European regulations, which is a whole other set of complications, right? So definitely show how compliant you are with our regulations. Show the value of, you know, time to value. Like, again, this is how much this is what we're doing right now with this spend.

If we did it this way, we can get this. kind of outcome, right? And then other things as well, like the security tools. I know the one thing that we're very cognizant and sensitive to is downtime with security tools, right?

Certainly don't want to minimize downtime, right? So if you have a ton of downtime, bring that to the table and say, hey, some of our old tools are causing this type of downtime. If we went to this, we would have much better results with our systems being up and our business users being happy. So again, metrics, metrics, metrics, and have good data, and the data should be able to tell the story.

And the data doesn't lie. So data doesn't lie. Well said. Well, Chuck, thank you so much.

We've about hit our time limit. So we really want to thank you for coming on. It was fun. How'd I do?

You did great. And listen, we're at a time where. You know, budget planning, I think, is important. People are finishing their budget season.

It's that time of year again. And so, you know, to be able to pick your brain and hear how you've approached this successfully over the past few years, I think will be really important to our listeners. So if anybody has any further questions, they can reach out to us at info at klogicsecurity .com.

directly on our LinkedIn. And as always, you can hear this in any of our podcasts at klogicsecurity .com forward slash podcasts. Chuck, thanks again.

Great job. All right. Thank you, Kevin.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How Enterprise Software Buyers Now Demand a Vendor AI Training Data AuditB2B SaaS Talks with Fexingo · on HIPAA compliance90 / 100
  • Why Your Engineering Team's Size Doesn't Matter Anymore w/ Michael Kopko | Episode 207The Software Leaders Uncensored Podcast · on HIPAA compliance84 / 100
  • Why Most Productivity Apps Fail Neurodivergent PeopleColorado Tech People · on HIPAA compliance83 / 100
  • Episode 015: The Last Flintstones LawyerAI Tools for Practicing Lawyers · on HIPAA compliance82 / 100
  • Data, AI, and Knowing When to Let Go - with Tommy CotterDefinitely, Maybe Agile · on GDPR compliance81 / 100
  • Network Segmentation to Prevent Ransomware: What the UCSF Attack Taught UsThe Backup Wrap-Up · on HIPAA compliance80 / 100

More from Cyber Security Business

All episodes →
  • AI Compute as a Business Risk70 / 100
  • The Path to CISO61 / 100
  • Creating an AI Security Culture63 / 100
  • Future-proofing and Storytelling80 / 100
  • Hungry for CISO Trends72 / 100
All Cyber Security Business episodes →