What doing nothing costs
Security budgets are hard to approve because we discuss the price of the solution, never the price of its absence.
Any security budget request should come with two numbers next to it: what the measure costs, and what one day of downtime costs. That second number can be estimated in any company, with finance, in under an hour.
When those two numbers sit side by side, the conversation changes entirely. It's no longer "why are we spending this on IT", it's "how many days of downtime can we afford".
I've seen this calculation done after the incident far too often. Done beforehand, it's the cheapest security instrument available.