

The journal entry, the chart of accounts, the general ledger… all designed for a world of paper and quill pens.
It still tells you what happened, but not why.
Numeric’s webinar outlines how data-centric accounting answers the “why”, showing what your data needs before agents enter the picture.

👉🏼 Bent out of shape and need some advice? Send me your questions, and you might just see yourself in next week’s Mailbag. Submit anonymously using the button below:
Here’s what’s on today:
The CEO who wants his salary kept secret
Budgeting for cyber security
What to do in a failing transformation (surprise)
Now, let’s get into it.

Lonely CFO from Virginia, USA
I am working on an ownership transition: Gen one founder CEO selling 51% of the company, and Gen two CEO coming in at 25%.
The board wants a say in the new CEO's salary. However, the new CEO wants me to put mechanisms in place so that the board approves with parameters, but doesn't know exactly how much he makes.
Also, the partner-owned company does not want the GC or CFO to own equity. What should we ask for in terms of a closing bonus on this transaction and in lieu of equity?

Jeez, no wonder you are ‘lonely’ my dawg.
I would separate this into two issues: governance for the new CEO, and reward for you.
On the CEO salary point, this is ultimately a shareholder agreement and reserved matters question. It is a key commercial point that should be decided as part of the transaction documents, not engineered in the background.
Your job here is to make sure the issue is made explicit, agreed consciously by the relevant parties, and documented properly. Otherwise, you’ll have a governance mess and you’ll likely end up getting slapped for it.
And, being blunt, I do not think what the new CEO is asking for sounds reasonable.
If I have read this correctly, the new CEO will own 25% of the business. Which means 75% of the business is owned by other people. Claiming they can hide a salary funded primarily by other shareholders is a stretch.
CEO compensation is one of the reasons boards exist. Accountability at the top… reward for performance, consequences for underperformance, alignment with the company’s long-term value.
So this needs a proper compensation process. Maybe the full board sees it, maybe a small compensation committee sees it, maybe only non-conflicted board members see it. But someone with the right authority needs full visibility and sign-off of the CEO’s actual compensation.
I would push for the rules to be clear:
Who sets CEO pay?
Who reviews performance?
What metrics matter?
What happens if the CEO does a great job?
What happens if they do not?
How are salary, bonus, distributions, and any other economics considered together?
Those questions need answering now, while the ownership transition is being agreed. They will be much harder to fix later, once everyone has their feet under the table and their incentives baked in.
On your own economics, there is a key question here: is value being realized in this transaction?
If the founder is selling 51% and taking meaningful cash off the table, and you are doing real transaction work to make that happen, then yes, a transaction bonus is reasonable. The number depends on deal size, your role, market norms, and how critical you have been. But the principle is fair: if you are helping deliver liquidity for shareholders, you should share in some of the transaction success.
If this is more of an internal reshuffle, with limited cash realization, then a big closing bonus is harder to argue. You may still deserve something for the workload, but the stronger ask may be forward-looking.
If the ‘partner-owned’ does not want to invite the CFO or GC to the partner party… fine. I do not love it, but fine. Then ask for something that behaves economically like equity without being voting equity.
That could be a phantom equity plan, value creation bonus, exit bonus, synthetic equity, or LTIP tied to enterprise value growth.
Your argument is simple: “If you do not want me on the cap table, I understand that. But I need (and I think you need me) to be aligned with long-term value creation, beyond salary and annual bonus.”
I think it’s a reasonable ask. Good luck!!
TLDR: Ask the hard questions now, and get the comp rules documented. If the CEO gets to keep their salary a secret, make sure that principle is well understood and agreed.

Curious Cat from Dallas, TX, USA
Hi! First, thank you for all of your contributions to the broader finance function. Your newsletters have been the single most informative source for how to think about the finance function since I began my working career.
I'm currently the CFO of a consumer entertainment tech company. One thing I've been struggling with is how to budget for IT, and more specifically, security? It seems this is becoming a bigger threat with the advent of AI, but I'm struggling with how to think about spend allocation here.
I don't want to rely solely on benchmarking because that data does not reflect the current realities nor the specific circumstances of our company. Often, I think about allocating increased funds to these central functions when things start breaking or not performing (and after identifying root causes). But that's not really a privilege we have for cyber incidents. At least, these are my operating assumptions.
For context, we're a company with low hundreds of millions of revenue, and a couple hundred employees. Thanks for all of your help!

Curious Cat… I think this is one of the most difficult questions for CFOs right now.
On the one hand, cyber is a real issue, and it is going to need growing investment. On the other hand, it can become a floodgate for every IT wishlist item and a blizzard of technical bullshit. The easiest way for a CIO/CTO to get investment is to scare the board with what could go wrong.
It sounds like you have done what many CFOs do, including me, which is mostly react when things break. We can argue all day whether that was ever the right strategy. What I would say is that, if it ever was, it is becoming less right every day.
Especially with AI making attackers faster, cheaper, and more convincing.
So here is how I think about it. Not as a cyber professional. Just as a CFO who worries a lot.
First, do not assume you can insure the risk away. Cyber insurance may have a role, and you should explore it, but I have generally found it weaker than people think. Lots of conditions and exclusions, meaning it may not pay out when you need it.
And even if it does and you have a catastrophic cyber event, a check helps, but it does not put your business back together if a hack burns it down.
Second, do not think about cyber budget as a percentage of revenue benchmark. Cost benchmarking is useless in most situations; engineered by consultants to drive work, and used by management to justify investment. But in cyber… it’s especially useless. Your risk depends on your systems, data, architecture, customer exposure, internal capability, and how attractive you are as a target.
I worked in a finance role supporting a physical security function very early in my career, and one thing I learned from security professionals is that you are only as strong as your weakest point. You do not need to be the best in the world at everything. But you cannot afford to be in the bottom quartile anywhere important.
So the first thing I would invest in is regular independent penetration testing and a proper cyber maturity review.
How long does it take someone to get through your external walls? Once they are inside, how much havoc can they cause? Can they move laterally? Can they reach customer data? Can they interrupt revenue systems? Can they compromise finance workflows? Can they get to payments?
Yes, we are all being slightly manipulated by IT professionals, vendors, and clever PR around cyber threat. But it is also a real threat. Both can be true. My roving reporter Tim covered this in a recent Boardroom Brief.
The benefit of penetration testing is that it turns vague fear into specific evidence. It tells you where you are weak. Then you can direct investment to the most vulnerable areas, rather than throwing money into a generic “cyber” bucket and hoping it’ll be good.
I would want a ranked cyber risk register in business language. The top risks. The impact. The mitigation. The cost. The owner. The timeline.
Then budget against that.
Fund the critical gaps first. The things that reduce the chance of a catastrophic event or materially limit the blast radius if one happens. After that, build a steady-state annual program. As you do this discovery work, it should start to feel a lot clearer on what is important, and in what order.
You will never eliminate cyber risk, but you can make sure your business isn’t walking around the internet with your pants round your ankles.
TLDR: Don’t cost benchmark your way into cyber comfort. Push your IT team to get specific about the vulnerabilities. Test your weaknesses, rank the risks, and fund the biggest gaps first.

Are all accountants equal? from Midwest, USA
What's the playbook when you know the outcome of a transformation before leadership is willing to say it out loud?
I'm a finance leader at a Fortune 500 company where ERP-driven efficiency gains haven't materialized, and the response is increasing centralization of controllership activities. I don't agree with all of the decisions, but I also don't think I can stop them.
How do you stay supportive of the transformation, protect your team, and ensure you're still sitting in a meaningful chair when the music stops?

This one made me chuckle, because I suspect there are thousands of finance leaders right now experiencing some version of this.
Transformation programs become a runaway train that is hard to stop, even though most people deep down know it is heading nowhere good.
There is too much capital sunk into it to stop. And I do not just mean financial capital. If it were only money, you could help people see common sense. I mean relationship capital… credibility capital. Internally with bosses, peers, teams, and externally with vendors, consultants and careers attached to the program.
That is a MUCH harder train to stop.
It is also the thing that has fed the ERP industrial complex for the last 20 years. The rollouts cost more than expected, take longer than expected, distract more than expected, and deliver less than expected. Meanwhile, finding a better alternative is hard too.
So, what do you do?
It sounds like you have enough seniority to have your name stapled to its success, but not enough influence to change the direction. A dangerous combo…
I’ll assume you are a BU finance leader, divisional CFO, controller, or something similar, and this is being ‘done to you’ by corporate.
The way through this is delicate corporate politics.
Some people will tell you to keep your head down, get behind the program, and make the most of it. That is what most people do. Then, if it goes wrong, they distance themselves later and explain how they never really thought it was right in the first place.
That was never me.
I was always predisposed to say what I thought. Delicately, but clearly. I saw it as part of the job to challenge groupthink and test whether the plan was actually right.
But you have to do that with discipline.
ERP rollouts are grueling, it is not unusual to lose faith halfway through. So the first thing you need to work out is whether you are having a wobble in belief during a painful but broadly sensible transformation, or whether the plan is genuinely bad.
Start by testing that with your peers.
I would guess you are not the only one thinking it. Get around your peer group and understand how they feel. Are you the median or the outlier? My guess is you are less of an outlier than you think.
If you discover this is a wobble in confidence around a fundamentally decent plan, then you need to recommit. Adjust where needed, protect your team from the worst noise, and get properly behind the program. These transformations are hard to land with full belief. They are impossible if everyone only believes in them 90%.
But if you conclude the plan is genuinely wrong, then you need to be more surgical.
Get to the real decision-maker quickly. CFO, CIO, CAO, VP Transformation, whoever actually owns the path.
One of my paranoias as a CFO in a larger business was becoming disconnected. From the business, from my team, from reality. So I loved it when someone stepped forward to tell me something no one else was saying. I saw it as a way of keeping me, my insight, and my thinking sharp.
I would always actively seek non-consensus opinions, but I appreciate not every culture encourages this. Jeff Bezos has popularized the idea of ‘disagree and commit’ which I love. You should be able to openly disagree, accepting that, if the decision is to press on regardless, your job is to make it work like you think it’s the best idea since sliced bread.
So once you reach the right person, be direct. But do not let it look like you are playing politics. Articulate your concerns in a few clear points.
Not a laundry list of complaints, nor “everything is broken and the consultants are clowns,” even if both might be true.
You are going to tell someone that the thing they are working on, and probably believe in, is not going to deliver. That is like telling someone they have an ugly baby. There is no great way to do it.
So start with the shared objective.
“We all want the same thing here: stronger control, more automation, faster close, better data, and less manual work. My concern is whether the current path gets us there from where we are today.”
This is also where AI may be a useful framing. If this ERP journey started years ago, the world has moved. What is now possible in finance has changed dramatically. So there is a fair question to ask: should the roadmap and priorities be reviewed in that context?
You do not want to spend years designing a more precise slide rule just as the pocket calculator arrives.
Good luck!
TLDR: Test whether you’re right, challenge the plan cleanly, then either recommit or protect the landing.

A few of the biggest stories that CFOs should pay attention to. This is also the section you might not want to see your name in.
I liked this example from On Holding CFO Frank Sluis. It takes discipline to resist discounting during tough markets in the name of brand protection. They also signed up Kylian Mbappé for 10 years last week as a new brand ambassador.
A reminder for all boards that even if you don’t have an AI strategy yet… you do, you just can’t see it!
Soccer CFO jobs are tough jobs (as we saw with last month’s deep dive). I suspect new Chelsea CFO Adriel Lares is about to learn your average English football fan is much less charming than Ted Lasso would have you believe…

ICYMI, here are some of my favorite finance/business social media posts from this week.
The entire global company is being held up by the value of a business that defines profit ‘before expenses’. I can’t wait for that S1 to hit …
This made me laugh… It’s so true for so much AI work. I have seen so little in practice that extends beyond: “Oh, that’s cool”.

If you’re looking to sponsor CFO Secrets Newsletter, fill out this form, and we’ll be in touch.
If you enjoyed today’s content, don’t forget to subscribe.
You can help make sure this newsletter always stays free simply by spreading the word. And when you share CFO Secrets with your finance friends, you’ll earn rewards, including a 50-page PDF guide on what it takes to be a great CFO. Start sharing your unique referral code today: {{rp_refer_url}}
Last weekend’s Playbook was part three of “Inheriting a Shitshow Finance Function”, focusing on how to keep the wheels of a finance function moving while everything is crumbling.
Last week’s Boardroom Brief tackled what CFOs can actually do today in response to growing cyber threats.


Disclaimer: I am not your accountant, tax advisor, lawyer, CFO, director, or friend. Well, maybe I’m your friend, but I am not any of those other things. Everything I publish represents my opinions only, not advice. Running the finances for a company is serious business, and you should take the proper advice you need


