Skip to content
BOARD MAY 2026 · 5 MIN read

How to present cyber risk to the board in 4 questions

How much can we lose, what does reducing it cost, what is the return and what happens if we do nothing.

VC
Virtual CISO
Governance & leadership
Service: CISO Virtual →
THE ESSENTIALS

The board doesn't reject cybersecurity: it rejects the language it's usually presented in.

The four questions turn any security decision into a business decision comparable with the rest.

The fifth slide, what we decided last quarter and what happened, is what builds long-term credibility.

Most security presentations to the board fail for the same reason: they talk about vulnerabilities, patches and compliance, the technical team’s language, to an audience that decides with three other variables: potential loss, cost and return.

The four questions

THE FULL FORMAT

  • How much can we lose?: the realistic scenario, costed: days of disruption × operating cost + regulatory + reputational.
  • What does reducing it cost?: the proposed program as an annual figure, not a list of tools.
  • What is the return?: measured exposure reduction, insurance premium, commercial requirements it unlocks.
  • What happens if we do nothing?: the same exposure projected with the sector’s attack trend.

The board decides between risks every day. Cyber risk just needs to arrive in the format it uses for the others.

The fifth slide

Credibility isn’t built by the first presentation but by the fifth: what we decided last quarter, what got implemented and what changed in the numbers. A program that reports against its own promises stops competing for budget, it becomes a stable line in the plan.

A Virtual CISO with live data from the operation builds this format in hours, not weeks: the exposure, detection and response numbers already exist, they just need translating.

Material like this, every week.

The CERT-CBRT bulletin: what is being exploited in the region and what the shift learns by operating. No marketing.