
Authored by
Foo Wui Ngiap
Chief Scientist & President at FailSafe
Founding CISO of Grab (2015–2022)
FailSafe Research
The CISO's 100-Day Guide to the 2027 Security Budget
A framework for AI-enabled security budgeting. Profile what you run today, score where it leaves you exposed, turn each row into an increase, decrease or justify decision, and cost the gap.
Inside
- A scorecard that profiles what you actually run, and where it leaves you exposed
- A budget map that turns every scored row into increase, decrease or justify
- The fully loaded cost, including the term most requests leave out
- A 100-day plan, counted back from the date your planning closes
Grounded in established public guidance
- Gartner
- Outcome-Driven Metrics, Protection-Level Agreements
- NIST
- CSF 2.0, AI RMF and GenAI Profile
- MITRE
- ATLAS
- OWASP
- LLM Top 10, Agentic Top 10
Questions & answers
Frequently asked questions
What the guide covers, who wrote it, and what it is based on.
It is a 28-page handbook for CIOs, CISOs, and the security, finance, and risk teams who plan alongside them. It sets out how to find where you are exposed, agree a target protection level, and build a 2027 security budget request that a CFO or board can assess.
Foo Wui Ngiap, Chief Scientist and President at FailSafe, and founding CISO of Grab from 2015 to 2022. It was published by FailSafe Research on 15 September 2026.
An executive briefing, then eight sections that move from risk to a funded, measurable decision: a scorecard for finding where you are exposed, a master budget map of increase, decrease and justify moves, the research behind that thesis, how AI changes enterprise risk, a 2027 market landscape organised by buyer portfolio, turning your profile into a costed budget request, a 100-day plan, and eight recommended actions. It closes with sources and methodology.
It draws on Gartner Outcome-Driven Metrics and Protection-Level Agreements, NIST CSF 2.0 and the AI RMF with its GenAI Profile, MITRE ATLAS, and the OWASP LLM Top 10 and Agentic Top 10. These organisation and framework names are used to identify the public guidance the handbook draws on. Their use does not imply review, endorsement, affiliation, or sponsorship by Gartner, NIST, MITRE, or OWASP.
Nothing. Enter your email and company and we will send the PDF to your inbox.