How to Get the Board to Fund Cybersecurity Without Using Fear

The fourth no arrived as a one-line email. “Let’s revisit next budget cycle.” You had attached twelve pages: eleven critical findings from the last pen test, a heat map with a lot of red, a slide about a competitor that got ransomwared in March. The CFO read the summary, agreed it sounded bad, and funded a sales enablement tool instead.

Here is the uncomfortable diagnosis. Nothing in that deck was wrong, and nothing in it was a decision. You presented a condition. Boards fund decisions, specifically decisions that unblock something they are already trying to do.

You get the board to fund cybersecurity by moving security out of the risk conversation and into three conversations the business already has every week: deals that are stalling, contracts that cannot be signed, and obligations someone has to personally sign their name to. Risk language is where security budgets go to die. Not because executives are reckless, but because every function arrives with a risk story and they have learned to discount all of them equally.

Why breach headlines will not fund cybersecurity twice

The first time you put a competitor’s breach in front of an executive team, you get attention. Maybe money. The second time you get a nod. By the third you have taught them something you did not intend: that you show up with scary news and no consequence ever follows. Fear is a non-renewable resource, and most security leaders spend it in year one.

The data barely cooperates anyway. IBM’s Cost of a Data Breach study, researched by the Ponemon Institute, put the global average at USD 4.44 million in its 2025 edition, down nine percent, with mean time to identify and contain a breach at 241 days, the lowest in nine years. The 2026 edition, covering 602 breached organisations from March 2025 to February 2026, then reported a record USD 4.99 million globally and USD 11.5 million in the US. The number fell, then rose. Quote one year as proof things are getting worse and your own source argues with you.

These are modelled costs built from interviews, not audited financials, and the sample skews large, so the average says little about a 340-person company. A CFO who has read one will ask which cost categories apply at your size. Have that answer ready or leave the number out.

Use breach research for mechanism, not price tags. Verizon’s 2026 DBIR is more useful in a boardroom than any cost average because it describes how attackers get in: exploitation of vulnerabilities has overtaken stolen credentials as the leading initial access route at 31 percent of breaches, and 48 percent of breaches now involve a third party. Third-party exposure is a sentence a board understands, because they signed those vendor contracts.

Tie the spend to a deal that is stuck

Security reviews sit in the middle of enterprise sales cycles, and when a deal dies there it gets logged in the CRM as “went with competitor” or “timing.” Nobody codes it as a security failure, so nobody funds security to fix it.

Fix that before you ask for anything. Get RevOps to add a closed-lost reason called “security review,” then read the email threads from four quarters of lost and stalled deals, looking for gating language: a SOC 2 Type II report, an ISO/IEC 27001 certificate, an independent penetration test within twelve months, phishing-resistant MFA on administrative access, a tested incident response plan.

Now you have a number that is not an estimate. It is pipeline.

What to say, almost verbatim: “Three deals worth $1.4 million in annual contract value stalled at security review last year. Same blocker each time, same document. A SOC 2 Type II costs roughly [audit fee] and needs an observation window of six to twelve months, so starting in October means we can answer yes from Q3. Not starting means we keep losing these. I need a decision either way today.”

A control has become a revenue unblock, and delay has acquired a visible cost. SOC 2 is an AICPA attestation reported on by a licensed CPA firm against the Trust Services Criteria; ISO/IEC 27001 is a management system certification from an accredited body. Both take real calendar time, and that lead time is your friend, because it makes “revisit next cycle” expensive in a way the board can see.

Which of the two you chase is not your call. Count your last twenty questionnaires: North American software buyers usually want SOC 2, European and multinational procurement more often ISO/IEC 27001, and many accept either. If your pipeline asks for neither, do not buy one yet.

Do not oversell the certificate as security, though. A Type II report says controls you defined operated over a period. It does not mean you are hard to breach, and a director who has been through one knows it. Say so before they do: “This buys us the ability to sell, and maybe forty percent of the security work as a side effect. I’ll come back for the rest.”

Use insurance, but not the argument everyone else uses

The lazy version is that cyber premiums are exploding so we must invest. That is currently false, and a CFO with a broker on speed dial knows it. Marsh’s Global Insurance Market Index shows cyber rates fell 4 percent globally in Q2 2026, the twelfth consecutive quarterly decline, after a 5 percent fall in Q1.

The real argument is conditions, not price. Renewal applications ask for specific control attestations, and someone in your company signs that form. So ask your CFO or general counsel one question: “Who signs the cyber renewal application, and did they read the MFA question before ticking it?”

That does more work than any heat map. If the attestation claims phishing-resistant MFA on all privileged and remote access, and you know three service accounts and the legacy VPN are exempt, you are not describing a technical gap. You are describing a signed statement that is inaccurate at the moment a claim gets examined. Take it to the general counsel, not the CFO. Legal escalates it for you.

Quantify what you can, then build a register the board signs

Executives do not want probability distributions. They want a comparable number. FAIR, Factor Analysis of Information Risk, is the standard worth knowing: maintained openly by The Open Group through the O-RT and O-RA standards, it expresses risk as probable frequency and probable magnitude of loss in money rather than as a red square.

Its real value is forcing a decomposed conversation: how often would this plausibly happen, what fraction of those events produce loss, what would the loss consist of, how confident are we in each input. That survives challenge far better than “high.” State the limits yourself, though. Frequency estimates for rare events are soft, and loss magnitude rests on finance’s assumptions about downtime and churn. Anyone quoting a FAIR result to four significant figures is selling something.

With no appetite for a full analysis, quantify only the loss side, using numbers finance already owns. Revenue per hour with order entry down. Cost of the last unplanned outage. Service credits owed at 24 hours. A week of manual workaround in headcount. Assemble that in an afternoon and nobody disputes it, because finance produced it.

Then put it in a register. A findings list is a document about your work; a risk register is a document about their decisions, and the difference is one column: named owner, never you. Seven fields, one line each: the risk as an event with a business consequence, the affected process, the executive owner, status, treatment and cost, decision, review date. No CVSS scores. No colours.

Write each risk as a sentence a non-technical director can repeat. Not “unpatched critical CVE on internet-facing Citrix.” Instead: “An attacker can reach the customer database from the internet without a password, which would trigger notification to 40,000 customers and to our three largest enterprise accounts under their contract terms.” The second has a legal consequence attached, which is why it gets read.

This is where NIST’s Cybersecurity Framework 2.0 earns its place. Released in February 2024, it added a sixth Function, Govern, alongside Identify, Protect, Detect, Respond and Recover: the organization’s cybersecurity risk management strategy, expectations and policy being established, communicated and monitored. NIST puts Govern at the centre of the wheel because it informs how the other five get implemented, and it explicitly covers risk appetite and tolerance statements and assigning roles and authorities to foster accountability.

Read that as the leverage it is. The most widely used security framework in the world says deciding how much risk to accept is a governance activity, not a security team activity. You are not asking the board for a favour, you are asking them to do their part.

For a defensible starting scope, CISA’s Cross-Sector Cybersecurity Performance Goals are the cleanest free reference: 29 goals mapped to CSF 2.0, written to help small and medium organisations prioritise a limited set of high-impact actions. CISA says plainly they are not comprehensive, which is why they work at board level. You can show a board 29 goals and a traffic light each, not 300 controls.

Risk acceptance is the tool. Use it deliberately.

This is the tactic that changes careers. Stop asking for money as the primary ask. Ask for a decision, and make formal written acceptance the alternative you are equally happy with.

The script: “I’m not asking you to approve spend right now. I’m asking you to choose. Option one, we fund the fix at $Xk and it closes by March. Option two, you accept the risk as it stands. I’ve brought the acceptance form. It names you as owner, states the risk in one sentence, and sets a review date of 31 March. Either is a legitimate business answer and I’ll support whichever you pick. What I can’t do is leave it undecided.”

Then be genuinely willing to take the signature, because that willingness is what stops it being a bluff. A meaningful share of risks presented this way get funded on the spot: signing your name under a one-sentence consequence feels nothing like declining a budget line. The ones that do get accepted are still a win, since they are now owned and dated.

Rules that keep this from becoming a career-limiting move. Never frame acceptance as a threat, and never reference regulators or personal liability. Route it through your normal governance channel rather than ambushing someone mid-meeting. Keep the register visible to the audit committee, and re-present accepted risks at every review date without editorial.

At a public company there is one extra lever. SEC rules already require annual disclosure under Regulation S-K Item 106 of your processes for assessing and managing cybersecurity risk, the board’s oversight role, and management’s role and expertise, with material incidents reported on Form 8-K Item 1.05 generally within four business days of the materiality determination. A register with named owners and review dates is most of that disclosure already written. Say so to the general counsel and watch it get adopted in a week.

The tabletop converts better than any deck

If I could keep one tactic from this list it would be this. A 90-minute tabletop with the executive team funds more security work than a year of reporting. A deck lets executives evaluate your competence; a tabletop makes them experience their own exposure. Very different rooms.

  • Invite the right eight. CEO, CFO, general counsel, heads of sales, operations, people and comms, plus your senior engineer. Security should be the smallest contingent in the room.
  • Pick a scenario tied to revenue, not to IT. Ransomware in the system that takes orders or pays people. Not “malware on a laptop.”
  • Ground it in current mechanics. With vulnerability exploitation now the leading entry route and third parties in 48 percent of breaches, compromise through a supplier’s remote access is more realistic than a phished intern.
  • Use injects that cost money. Hour four: a customer asks why their integration is down. Hour nine: a journalist calls. Day two: your largest customer invokes a notification clause. Day three: payroll runs Friday.
  • Stop the clock and ask who, not what. “Who authorises paying a ransom, and up to what amount?” “Who calls our top ten customers, and what do they say?” The silence in that room is your budget case, and you did not have to make it yourself.
  • Send the after-action report within 48 hours. Three to five decisions the group could not make, each with a named owner and a cost to fix. That report, not your original deck, is the funding document.

Run it annually, plus after any acquisition or major migration, and whenever a new CFO arrives. A new CFO is the best budget opportunity you will get, and has no history of saying no to you yet.

Metrics that survive contact with a board

Most security dashboards report effort. Boards fund outcomes and exposure. Stop reporting attacks blocked, alerts triaged, patches deployed, tickets closed and phishing click rate as a headline; every one of them moves when things get worse and when things get better, which is why they persuade nobody.

Report five to seven of these instead, the same ones every quarter, each with a trend and a target:

  • Critical vulnerabilities on internet-facing systems open beyond SLA, as a count plus the age of the oldest. The DBIR’s 31 percent finding is what makes this the headline metric.
  • Coverage on your top three controls. Endpoints with working EDR, privileged accounts with phishing-resistant MFA, systems with tested restorable backups. Gaps are where incidents happen, and 78 percent moving to 94 percent is a story a director can follow.
  • Mean time to contain, from your own incidents, with IBM’s 241-day mean as context rather than a target.
  • Deals gated at security review, count and pipeline value, with the blocking requirement named. This belongs on the CRO’s slide too.
  • Third parties with critical data access and a current assessment, as a percentage.
  • Open accepted risks, with owner names and review dates. Nothing focuses a board like seeing their own name in a standing report.

One discipline: lead with the metric that got worse. Volunteering bad news before you are asked is the fastest route to becoming the executive whose numbers get believed, and being believed is the entire budget mechanism.

One argument to leave at home: the industry benchmark. Published “percent of IT spend” figures are mostly self-reported survey data, and quoting one invites the reply that we are not them.

Sometimes the answer is still no and the business is right. A 40-person company with no enterprise deals and no regulated data probably should not buy a SIEM this year, and saying so unprompted buys you more than any argument. Sometimes no means you are asking the wrong person: spend that unblocks sales should be argued by the CRO using your numbers, and spend that protects a production line belongs in the COO’s operational risk budget. A vCISO with no budget authority should spend ninety days finding the executive who already holds money for the problem, then make them the sponsor.

If the real gap is that you cannot answer buyer questionnaires or insurer attestations truthfully because the evidence does not exist, that is a staffing and tooling problem more than a strategy one. AB7 Solutions provides SOC monitoring, VAPT and penetration testing, and firewall and server security work, including the recurring test reports and coverage evidence that security reviews and renewal applications keep asking for. For a second opinion on which gap to close first, call +1 321 341 7733, email ab@ab7solutions.com or director@ab7solutions.com, or start at www.ab7solutions.com.

Sources: IBM, Cost of a Data Breach Report, 2025 and 2026 editions (Ponemon Institute research; 602 breached organisations); Verizon, 2026 Data Breach Investigations Report; NIST, Cybersecurity Framework (CSF) 2.0, February 2024; CISA, Cross-Sector Cybersecurity Performance Goals; U.S. Securities and Exchange Commission, 2023 final rules on cybersecurity risk management, strategy, governance and incident disclosure; Marsh, Global Insurance Market Index, Q2 2026; The Open Group Open FAIR standards (O-RT, O-RA), via the FAIR Institute.

Leave a Comment

Your email address will not be published. Required fields are marked *