Should IT report to the CFO? What a CFO owns when there is no CIO
# Should IT report to the CFO? What a CFO owns when there is no CIO
General information for finance leaders. Not accounting, legal, or insurance advice.
Who owns technology when the company has no CIO? In our view, whoever the board calls when a system fails or a bill jumps. At a mid-market company with no CIO, that is often the CFO. Owning it does not mean running it. It means you can state what technology costs, name who runs each part, and show what you were told about risk.
This applies to companies owned by sponsors or families. It also applies to founder-owned and public companies. Findings from outside sources are attributed in the text. Opinions are ours and are written that way.
Has technology landed on the CFO by default?
Many CFOs say it has. The IBM Institute for Business Value surveyed 1,500 CFOs and equivalent senior finance leaders across 33 geographies. Oxford Economics worked with IBM, and fieldwork ran from February to April 2026. IBM’s release of September 30, 2026 says 62% of respondents say their role has expanded into enterprise technology or AI strategy leadership. The release states no company size band. IBM sells cloud, AI and consulting services. Read this as a vendor-published study.
We would read the number carefully. “Expanded into” is not “owns.” A CFO can sit on the AI steering group and still have a CIO who runs everything else. The harder case is the company where nobody holds the CIO job. We found no sourced count of how many mid-market companies are in that position, and we will not guess at one.
What work is left without an owner when there is no CIO?
The U.S. Bureau of Labor Statistics says computer and information systems managers “plan, coordinate, and direct computer-related activities in an organization.” It lists chief information officer among the titles and notes that job titles may vary by organization size and structure. Its duties include maintaining processes to detect, prevent, and mitigate IT security threats. They also include assessing the costs and benefits of new projects, negotiating with vendors, and determining personnel needs. BLS describes an occupation across all employers. It does not describe your company.
If nobody at your company holds that job, each duty still exists. The IT manager covers some. The managed service provider (MSP) covers others. You cover the rest, or nobody does. We think the duties with no name beside them are the real exposure, and the CFO is the person who gets asked about them.
NIST published its Cybersecurity Framework 2.0 in February 2024. It lists the outcome “Organizational leadership is responsible and accountable for cybersecurity risk.” NIST says any organization can use the framework “regardless of its size, sector, or maturity.” The framework does not mention the CFO. Our read is that at a company with no CIO, “organizational leadership” includes you.
Suppose the person who runs IT at your company resigns on a Friday. On Monday the controller asks who holds the administrator password for the ERP system. The MSP says it handles monitoring, and you realize nobody has read what the contract says about incident response. A customer’s security questionnaire is due Wednesday. Nothing is broken yet. But every question that week lands on you, and each one is a duty that nobody was assigned.
Should IT report to the CFO?
Sometimes. Start with the data that exists. Deloitte surveyed 622 U.S.-based senior technology leaders online from March 7 to April 1, 2025. It released the results on November 13, 2025. It reports that 65% of CIOs report directly to the CEO, up from 41% a decade ago. Its size comparison covers companies of $1 billion or more in revenue, so mid-market results may differ. The finding is about companies that have a CIO. We found no current sourced figure for how many IT leaders report to the CFO.
Our view is that the line on the org chart matters less than whether anyone translates between finance and technology. A CFO asks what it costs, what could go wrong, and what needs a decision. A technical lead asks what is failing, what is out of date, and what needs fixing. Both are right. Neither question answers the other, and each person hears the other’s answer poorly in their own terms. Reporting to the CFO does not close that gap. A strong IT lead does not close it either.
What closes it is someone who can carry what matters in both directions. For the CFO, that means turning a patching backlog or a contract renewal into cost, risk, and a decision. For the technical team, it means turning a budget limit or a board concern into a priority they can act on. It also means advising on how to get from where the company is to where it needs to be. Where the path is not yet clear, it means supplying the information so that finance, technology, and the board can each make progress. Without that person, the CFO decides without the facts or waits on a report written in someone else’s language.
The need is sharpest in three situations:
- A large change is planned. An ERP replacement or a multi-site rollout needs senior direction with real hours, and someone to explain the trade-offs to both sides.
- Nobody inside can judge the MSP’s work. Someone independent of the MSP has to read what it produces and say what it means for the business.
- A sale or refinancing is coming. An IT lead who reports to you is poorly placed to grade the function alone, and a buyer or lender will want the picture in financial terms.
Whether that person is a CIO, a fractional leader, or an outside partner is a second decision. The requests below work with any of them, and they show where your gaps are.
What should a CFO ask for this quarter?
Structure is a long conversation. These five requests take a quarter and show where the gaps are.
- One number for total technology cost, tied to the ledger. Ask your controller and your IT lead. Include software that departments bought on their own and the MSP invoice. If nobody can produce it, you answer for a figure no one can state.
- The page of the MSP agreement that says who is responsible. A May 2022 joint advisory from U.S. agencies and their counterparts in four allied countries says each customer should ensure “their contract specifies whether the MSP or the customer owns specific responsibilities.” It names hardening, detection and incident response. The U.S. agencies are CISA, the NSA and the FBI. It also says “contracts should detail how and when MSPs notify the customer of an incident.” Ask the MSP to point to the page. If the contract is silent, take that to counsel.
- A named answer to “if the person who runs IT left next month, what stops?” Ask the IT lead and the MSP separately. Two different answers are the finding.
- A risk figure with its inputs, or an honest “not yet.” Ask for the top few exposures as an annual dollar range. Ask for the chance per year, the cost if it happens, and the source of each number.
- One page on a schedule you set. Cost against budget. Renewals coming due. Incidents that reached customers. One decision that needs a business owner. If the IT lead or MSP cannot produce it, the data may not exist. That is a different problem from reluctance and needs a different fix.
On the fourth request, NIST’s December 2025 guidance on cybersecurity risk (NIST IR 8286A Rev. 1) offers likelihood times impact as one example of how to calculate exposure and leaves the method to each enterprise. It also warns that “without supporting data, well-intentioned but misguided methods of risk analysis amount to little more than a guess.” So the inputs matter more than the output.
Illustration, not data. Assume a billing outage would cost $2 million in lost billings, recovery effort, and credits. Assume a 5 percent chance of one in a year. The exposure is $100,000 a year. A board will probe the 5 percent and the $2 million before it looks at the product of the two.
The same NIST document says that if exposure is within risk tolerance limits, the risk may be “accepted.” We think an accepted risk should carry a name and a date. It should also carry the figure it rested on. If the name is yours, you want to have chosen that.
Who else will read your answers?
Your board and any lender or insurer will read them if something goes wrong. A buyer will read them sooner. RSM US authors describe pre-close technology diligence as work “to identify and quantify undisclosed risks related to scalability, stability and supportability of IT systems and processes.” That is one firm’s description, written for private equity.
The word that matters to us is “undisclosed.” A password in one person’s head, or a control that exists only in memory, becomes a finding when someone else finds it first. Having the answers to the five requests on paper before a buyer asks is the cheapest preparation we know of.
We do not state what any auditor, lender, or insurer requires. Those points belong to your own advisors, and the closing questions below are for them.
If you have a sponsor
A sponsor changes who asks, not what the answers are. Accordion, with Wakefield Research, surveyed 200 private equity sponsors and 200 CFOs at PE-backed companies with $50 million or more in annual revenue. The samples were collected in April 2025. The report says AI adoption “has been far slower than sponsors want.” It adds that CFOs say it is because “they have no idea where to start or who to turn to for help.” That is about AI in finance, not IT leadership, and it covers only sponsor-backed companies. We use it only here. Accordion sells financial consulting.
Our read is that a sponsor’s operating team will ask the CFO about technology cost and risk because the CFO is the nearest person who reports in dollars. The one page in request 5 is the answer in a format they can use. It is also reasonable to ask the operating team how other portfolio companies handle the reporting line.
What should you put to your auditor, counsel, and broker?
These are questions only. We do not state an answer, a requirement, or a treatment.
- To your auditor: what did the last audit say about technology controls, and who at the company answered?
- To your auditor: which technology costs are capitalized, and does the policy match what is booked?
- To counsel: does the credit agreement mention cyber, data, systems or insurance? Who certifies?
- To counsel: what do the MSP agreement’s exit and data-return terms say?
- To your broker: who signs the cyber insurance application, and what evidence supports each answer?
- To your broker: what happens if an answer on the application proves wrong?
Where Preside fits
Preside is a Technology Operating Partner. It owns the reporting on technology cost, risk, and direction to the CFO and the board.
The core of the work is translation in both directions. It turns what the technical team is dealing with into terms finance can decide on. It turns what finance needs into priorities the technical team can act on. Where the path is not clear, it supplies the information each side needs to move.
It works with your IT lead or MSP, manages specialists when the work needs them, and covers the leadership layer where there is no technology leader. It does not run IT operations or hold the CIO role. Preside is not paid by the providers it recommends.
The first request above maps to the Cost Optimization Initiative, which produces a technology P&L for vendor, licensing, and managed-service spend. More on the model is on the Technology Operating Partner page.
FAQ
Should IT report to the CFO?
It can. In our view the line on the org chart matters less than having someone who carries what matters between finance and technology, in both directions. Reporting to the CFO works when the company uses technology more than it builds it and the CFO has a regular hour for it. It fits poorly when a large change is planned, a sale is coming, or nobody inside can judge the MSP’s work.
Who does a CIO normally report to?
In one 2025 U.S. survey, most often the CEO. Deloitte reported in November 2025 that 65% of CIOs report directly to the CEO, up from 41% a decade ago. The sample was 622 U.S. senior technology leaders. Its size comparison covers companies of $1 billion or more in revenue, so mid-market results may differ.
What is the difference between a CIO and an IT director?
In U.S. federal labor data, both are titles within one occupation, computer and information systems managers. BLS lists chief information officer as one title and says job titles may vary by organization size and structure. Some of these managers oversee a whole IT department. Others run one area.
Is the CFO responsible for cybersecurity?
NIST’s Cybersecurity Framework 2.0 says organizational leadership is responsible and accountable for cybersecurity risk. It does not name the CFO. Who signs for what at your company, including on an insurance application, is a question for your counsel and your broker.
Get a brief
If you want to talk through the five requests for your company, get a brief. We send a note back, and a conversation takes about twenty minutes.
Sources
- IBM Study: As AI Scales Enterprise-Wide, CFOs Play an Expanded Role in Transformation. IBM Newsroom, September 30, 2026. https://newsroom.ibm.com/2026-09-30-ibm-study-as-ai-scales-enterprise-wide,-cfos-play-an-expanded-role-in-transformation. Used for the sample (1,500 CFOs and equivalent senior finance leaders, 33 geographies, February to April 2026), the 62% figure, and IBM’s self-description. Limits: press release, not the full report. No company size band. Global sample. IBM sells related services.
- The State of the PE Sponsor & CFO Relationship (AI in the finance function). Accordion with Wakefield Research, samples collected April 2025. https://www.accordion.com/state-pe-sponsor-cfo-relationship-artificial-intelligence-in-the-finance-function/. Used for the sample (200 sponsors, 200 CFOs, $50M or more revenue) and the two quoted phrases. Limits: about AI in finance, not IT leadership. Sponsor-backed companies only. Accordion sells financial consulting.
- Computer and Information Systems Managers, Occupational Outlook Handbook. U.S. Bureau of Labor Statistics, page last modified August 27, 2026. https://www.bls.gov/ooh/management/computer-and-information-systems-managers.htm. Used for the occupation definition, titles, the title-variation sentence, and the duties. Limits: covers the whole occupation and states no reporting lines.
- The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29, February 26, 2024. https://doi.org/10.6028/NIST.CSWP.29. Used for the leadership accountability outcome and the applicability sentence. Limits: guidance for cybersecurity risk management. It does not name the CFO.
- Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management. NIST IR 8286A Rev. 1, December 2025. https://doi.org/10.6028/NIST.IR.8286Ar1. Used for likelihood times impact as an example, the “little more than a guess” warning, and risk acceptance against tolerance. Limits: guidance, not a requirement.
- Protecting Against Cyber Threats to Managed Service Providers and their Customers. Joint advisory AA22-131A, CISA, NSA, FBI, with counterparts in the UK, Australia, Canada, and New Zealand, May 11, 2022. https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a. Used for the two contract sentences. Limits: written about MSP cyber threats, not cost or general IT oversight. Four years old.
- The critical role of technology due diligence in private equity. RSM US (Neal Cao, Craig Coffaro, Ernie Charles), May 6, 2024. https://rsmus.com/insights/industries/private-equity/the-critical-role-of-technology-due-diligence-in-private-equity.html. Used for the description of pre-close technology diligence. Limits: one firm’s description, written for private equity.
- New Deloitte Survey Shows Tech Execs Driving Growth, Shaping Strategy, and Eyeing the CEO Seat. Deloitte press release, November 13, 2025. https://www.deloitte.com/us/en/about/press-room/deloitte-tech-survey-reveals-how-leaders-redefine-enterprise-value.html. Used for the 65% and 41% figures, the sample (622, fielded March 7 to April 1, 2025), and the size comparison. Limits: size comparison covers $1B or more. No reporting-line figure for the CFO. Deloitte sells related services.
- Preside offerings. Technology Operating Partner page and deliverables catalog. Used only for the Preside section. Limits: Preside’s own statements about what it does.
