06-reference

secret cfo secret salary cyber security mailbag

2026-09-22·reference·source: CFO Secrets (The Secret CFO, anon)·by The Secret CFO (anon)
cfo-frameworkscyber-security-budgetingceo-compensationgovernancefinance-transformation

Why this is in the vault

Tue Mailbag, three anonymous CFO Q&As — a gen-2 CEO transition wanting a hidden salary, how to size a cyber-security budget without benchmarking, and how to survive a transformation you privately think is failing — kept for the cyber-budgeting answer, a reusable risk-register-first framework that's directly applicable to RDCO's own security posture and to any client conversation about security spend.

The core argument

Three reader questions, answered in the anon CFO's voice:

  1. CEO wants his salary kept secret from the board (Lonely CFO, Virginia) — a gen-1 founder is selling 51%, a gen-2 CEO is coming in at 25% and wants board sign-off on comp parameters without the board seeing the actual number; the partner-owner also won't let the CFO/GC hold equity. Answer: split it into two issues. CEO comp secrecy is a governance non-starter — 75% of the company is owned by people who aren't the CEO, so hiding the number from the body that's supposed to hold him accountable doesn't survive contact with "why boards exist"; get the rules (who sets pay, who reviews performance, what metrics, what happens on over/under-performance) explicit and documented now, before the transaction closes and incentives calcify. On the CFO's own ask: if real cash is being realized in the deal and the CFO did real transaction work, a completion/transaction bonus is fair; if it's an internal reshuffle, a big bonus is a harder sell — but if the partner structure permanently excludes non-partners from the cap table, ask for something that behaves economically like equity without being voting equity: phantom equity, a value-creation bonus, an exit bonus, synthetic equity, or an LTIP tied to enterprise-value growth.
  2. How to budget for cyber security without benchmarking (Curious Cat, Dallas — consumer entertainment tech, low hundreds of millions revenue) — don't insure the risk away (cyber insurance is full of exclusions and a payout doesn't reassemble a burned-down business) and don't budget off a percent-of-revenue benchmark (useless everywhere, especially useless in cyber, because risk is a function of your specific systems/data/architecture/exposure, not your peer group's). Instead: commission independent penetration testing and a cyber maturity review to convert vague fear into specific evidence — how fast can someone get through the perimeter, how far can they move laterally, can they reach customer data or payment systems. Build a ranked cyber risk register in business language (risk, impact, mitigation, cost, owner, timeline), fund the items that reduce catastrophic-event odds or blast radius first, then build a steady-state annual program from what's left.
  3. Staying supportive of a transformation you think is failing (Are all accountants equal?, Midwest US — Fortune 500, ERP centralization not delivering) — the sunk cost isn't just capital, it's relationship and credibility capital across bosses/peers/vendors, which is why these programs are so hard to kill even once everyone privately knows. First test whether it's a wobble in confidence or a genuinely bad plan — check with peers before acting, most people underestimate how many others share the doubt. If it's a wobble, recommit fully (half-belief kills these programs). If it's genuinely wrong, go to the actual decision-maker directly, lead with the shared objective ("we all want stronger control/faster close/less manual work, I have doubts the current path gets us there"), and use "the world has moved since this roadmap was written" (AI-driven capability shift) as the legitimate reason to ask for a re-review rather than framing it as a personal loss of faith.

Footnote confirms last weekend's Sat Playbook was Part III of "Inheriting a Shitshow Finance Function" (already filed, [[2026-09-19-cfo-secrets-keeping-the-lights-on-repair-mode]]) — this issue is the regular Tue Mailbag cadence, not a Part IV of that series.

Mapping against Ray Data Co

Q2's cyber-budgeting framework — reject benchmarking, commission a specific vulnerability assessment first, build a ranked risk register, fund the biggest gaps before a generic steady-state program — is a direct, reusable decision lens for RDCO's own security posture: the standing rule to security-review every third-party MCP/plugin/skill install before adoption (feedback_mcp_install_security_review_default) and the Scribble Works architectural choice to keep kids off-screen entirely with no third-party IdPs (project_scribble_works_product_principle_parents_site_kids_paper, SW-R18) are both "fund the identified gap, don't buy a generic security feeling" decisions made without a formal risk register — this framework is a usable template if RDCO ever needs to justify security spend to a client or formalize its own. It's also directly reusable client-advisory content if an OI/phData engagement ever touches a CFO's security budget conversation — this is a ready-made talk track.

Q1's equity-without-a-cap-table-seat menu (phantom equity, value-creation bonus, exit bonus, synthetic equity, LTIP-on-EV-growth) is the concrete instrument list for the "upside STAKE" wall of Ray's own FOUR-WALLS career-commitment spec (user_career_commitment_shape) — relevant if a future phData or OI arrangement offers scope without formal equity, the same shape the founder already rejected once in the employment-frame seat-gap thread (project_income_seat_gap_400k). Q3's "test whether it's a wobble or a genuinely bad plan by checking peers first" is a cleaner articulation of the same title/scope-under-external-control problem already mapped from this sender's 2026-09-01 mailbag ([[2026-09-01-secret-cfo-mailbag-pe-boss-title-walkback]]) against the CAF→Organizational Intelligence reframing (project_caf_pm_role).

⚠️ Sponsorship

Sponsored placement: Numeric (numeric.io, "data-centric accounting" webinar pitch — positions the journal entry/COA/general-ledger stack as pre-AI-agent infrastructure that tells you what happened but not why), a paid UTM-tracked block (utm_medium=paid_email) with no disclosed author relationship. This is a NEW entrant to CFO Secrets' rotating third-party sponsor pool — not previously confirmed (prior pool: Campfire, Zip, Pulley, Stuut, Una, Ledge, Summation, Nominal, CloudZero, Aleph per 01-projects/process-newsletter/README.md). Treat as the pool's 11th confirmed member; not independently decision-worthy (the pool has grown by roughly one new entrant per 1-2 issues for months), noted for the standing tracker rather than escalated.

Related