Back to blog
CISO Management10 min read

Cyber Budget 2026
How SME CISOs Win the Resources They Deserve

Budget cyberRSSICOMEXPME ETIPilotage

A cyber budget presentation is not a technical exercise. It's a strategic one. The A/B/C scenario framework used by CISOs who actually get budget approved.

Key takeaways

  • Defending a cyber budget is a strategic exercise, not a technical one: talk risk, exposure and value, not CVEs.
  • The A/B/C scenario framework lets leadership decide the level of risk they accept — not just an amount.
  • A well-equipped CISO (real-time posture, board reporting) defends a quantified, prioritised budget far more easily.

The CISO who got 40% more budget — and the one who got nothing

Two CISOs. Two French SMEs in the same sector. Same size, around 800 employees. Same regulatory exposure, NIS2 approaching.

The first CISO arrives in the management committee with a 12-line spreadsheet. Licenses, hardware, contractors. Total: €380,000. Management asks why it's higher than last year. He explains threats are increasing. Management says they'll have to make do with €300,000. Meeting over.

The second CISO arrives with three slides. He starts with uncovered current risks — with an estimated impact if any of them materialized. He shows the gap between current posture and NIS2 requirements by end of 2026. He proposes two scenarios: €320,000 (minimum coverage, listed residual risks) or €410,000 (target coverage, acceptable residual risks). Management chose the €410,000 scenario. And approved it.

The difference was not in the numbers. It was in the framework.

Step 1 — Translate cyber risks into business risks

Cyber riskBusiness translationEstimated impact
Ransomware on production systemsPartial or total business outage€50K–€500K depending on duration
Customer data breachGDPR fine + loss of trust4% of global revenue or €20M (GDPR)
Critical supplier compromiseService disruption + contractual liabilityVariable by SLA
NIS2 incident not declared in timeANSSI sanctionUp to €10M or 2% of global revenue

Step 2 — Present scenarios, not a request

A single budget request puts your board in a position to negotiate the number. Two or three scenarios put them in a position to choose a risk level.

Scenario A
Status quo

Current budget maintained. Here are the open risks and their estimated probability of impact over the next 12 months.

Scenario B — Recommended
Minimum NIS2 coverage

NIS2 compliance + coverage of the most critical risks. Residual risks explicitly listed.

Scenario C
Target coverage

Robust security posture aligned with your risk profile. Overall exposure significantly reduced.

Step 3 — Quantify the cost of inaction

  • Cost of a ransomware incident for a 500–1,000-employee SME: €250K to €1.2M (direct + indirect costs, ANSSI and Hiscox 2025)
  • Average cost of a data breach for an SME: €4.5M (IBM 2025), 60% indirect costs
  • Average downtime after ransomware: 21 days for an SME without a formal recovery plan

The question becomes: "Are we accepting an €800K risk to save €80K?" That's a very different conversation.

5 mistakes that sink a cyber budget request in board meetings

Mistake 1 — Presenting in technical terms

"EDR renewal, SIEM upgrade" means nothing to a CFO. Translate: "Enhanced ransomware protection, with detection in under 4 hours instead of 48."

Mistake 2 — Leading with compliance

"We need this for NIS2 compliance" is external pressure, not internal conviction. Boards respond better to "here is the specific risk this covers for our organization."

Mistake 3 — Not anticipating objections

Your CFO will ask why it's higher than last year. Prepare factual answers to the top 3 objections before the meeting.

Mistake 4 — No data on last year's budget

Before asking for next year's budget, show what you did with last year's. If you can't, it signals a management problem, not a budget problem.

Mistake 5 — Not requesting a documented decision

When management chooses a scenario, ensure it is documented — board minutes, validation email. This protects both you and the organization if a residual risk materializes.

Frequently asked questions

How should a CISO present a cyber budget to the board?+
In 3 slides: (1) Our current exposure — the 3 to 5 most probable risk scenarios with estimated financial impact. (2) What the budget covers — key investments in business language with associated risk reduction. (3) What we won't cover — residual risks and a documented management decision on their acceptability.
What is the recommended cyber budget for an SME?+
French SMEs allocate 3–6% of IT budget to cybersecurity on average. For organizations subject to NIS2 or DORA, the European benchmark recommends 8–12%. The gap is structural — linked to how budgets are presented rather than actual board resistance.
What is the average cost of a ransomware attack on a French SME?+
According to ANSSI and Hiscox 2025 data, a ransomware incident for a 500–1,000-employee SME costs between €250K and €1.2M (direct + indirect costs). Average downtime without a formal recovery plan is 21 days.

Prepare your 2026 cyber budget

Download the Eyako COMEX budget presentation template — or request a 30-minute session to structure your request.

Request a demo
Cyber Budget 2026: How SME CISOs Win the Resources They Deserve | Eyako