Security budgets are rarely decided by analysis. They are decided by how well whoever proposes them can explain what happens if the money does not come. A security function that describes threats often gets a polite no. One that describes consequences in the language of the business more often gets a yes. This chapter is about making the second explanation possible.
It opens with the investment question, how the level is derived from the actual exposure of the business rather than from a percentage taken out of somebody else's budget. Industry benchmarks answer what others are doing, which is a different question from what you need. Then comes the opposite, the cost of not investing, the calculation that makes security comparable with every other investment the board weighs it against. One section deals with how the value of security is communicated without becoming either alarmism or a technical report, two traps that both lead to the same outcome. After that follows the structure of a board presentation that leads to a decision, and a review of metrics that work at board level, with a clear distinction between measuring activity and measuring effect. Number of training sessions delivered is activity. A change in reporting rate is effect. Quantification of cyber risk gets its own section, with reasonable claims to precision rather than false exactness. The chapter closes with practical advice on the budget process and a review of cyber insurance as a complement rather than a replacement. The evidence base all of this rests on comes out of chapter 14 on risk and gap analysis.
The question has gained weight since the Cybersecurity Act made security work a leadership responsibility with supervision behind it. A board that rejects an investment now needs to be able to justify the decision against some basis, which assumes the basis existed and could be understood. That makes the decision material a security measure in itself, since it determines which other measures actually happen.
This page shows what the chapter covers and why the numbers decide whether the work happens. The calculation models, the metrics and the presentation structure are in chapter 12 of the book.
A budget is a strategy in numbers. What is not budgeted for will not happen.
Key insights
- Industry benchmarks answer what others are doing, not what your operation needs.
- The cost of not investing is the only figure that makes the investment comparable with other decisions.
- Metrics that measure activity rather than effect give a board false comfort.
- A board presentation should lead to a decision. Without a decision point it is a report.
- Cyber insurance does not replace capability, and the terms usually assume the basic protection is already in place.
Tools that belong to this chapter
The templates and interactive tools are in the Toolbox, free of charge.
System tools
Maturity measurement and follow up that builds an evidence base over time.
Read on
Next step
Where does your organisation stand?
The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.