Most security presentations to the board fail for the same reason: they talk about vulnerabilities, patches and compliance, the technical team’s language, to an audience that decides with three other variables: potential loss, cost and return.
The four questions
THE FULL FORMAT
- How much can we lose?: the realistic scenario, costed: days of disruption × operating cost + regulatory + reputational.
- What does reducing it cost?: the proposed program as an annual figure, not a list of tools.
- What is the return?: measured exposure reduction, insurance premium, commercial requirements it unlocks.
- What happens if we do nothing?: the same exposure projected with the sector’s attack trend.
The board decides between risks every day. Cyber risk just needs to arrive in the format it uses for the others.
The fifth slide
Credibility isn’t built by the first presentation but by the fifth: what we decided last quarter, what got implemented and what changed in the numbers. A program that reports against its own promises stops competing for budget, it becomes a stable line in the plan.
A Virtual CISO with live data from the operation builds this format in hours, not weeks: the exposure, detection and response numbers already exist, they just need translating.