Cyber Budget 2026
How SME CISOs Win the Resources They Deserve
A cyber budget presentation is not a technical exercise. It's a strategic one. The A/B/C scenario framework used by CISOs who actually get budget approved.
Key takeaways
- Defending a cyber budget is a strategic exercise, not a technical one: talk risk, exposure and value, not CVEs.
- The A/B/C scenario framework lets leadership decide the level of risk they accept — not just an amount.
- A well-equipped CISO (real-time posture, board reporting) defends a quantified, prioritised budget far more easily.
The CISO who got 40% more budget — and the one who got nothing
Two CISOs. Two French SMEs in the same sector. Same size, around 800 employees. Same regulatory exposure, NIS2 approaching.
The first CISO arrives in the management committee with a 12-line spreadsheet. Licenses, hardware, contractors. Total: €380,000. Management asks why it's higher than last year. He explains threats are increasing. Management says they'll have to make do with €300,000. Meeting over.
The second CISO arrives with three slides. He starts with uncovered current risks — with an estimated impact if any of them materialized. He shows the gap between current posture and NIS2 requirements by end of 2026. He proposes two scenarios: €320,000 (minimum coverage, listed residual risks) or €410,000 (target coverage, acceptable residual risks). Management chose the €410,000 scenario. And approved it.
The difference was not in the numbers. It was in the framework.
Step 1 — Translate cyber risks into business risks
| Cyber risk | Business translation | Estimated impact |
|---|---|---|
| Ransomware on production systems | Partial or total business outage | €50K–€500K depending on duration |
| Customer data breach | GDPR fine + loss of trust | 4% of global revenue or €20M (GDPR) |
| Critical supplier compromise | Service disruption + contractual liability | Variable by SLA |
| NIS2 incident not declared in time | ANSSI sanction | Up to €10M or 2% of global revenue |
Step 2 — Present scenarios, not a request
A single budget request puts your board in a position to negotiate the number. Two or three scenarios put them in a position to choose a risk level.
Current budget maintained. Here are the open risks and their estimated probability of impact over the next 12 months.
NIS2 compliance + coverage of the most critical risks. Residual risks explicitly listed.
Robust security posture aligned with your risk profile. Overall exposure significantly reduced.
Step 3 — Quantify the cost of inaction
- Cost of a ransomware incident for a 500–1,000-employee SME: €250K to €1.2M (direct + indirect costs, ANSSI and Hiscox 2025)
- Average cost of a data breach for an SME: €4.5M (IBM 2025), 60% indirect costs
- Average downtime after ransomware: 21 days for an SME without a formal recovery plan
The question becomes: "Are we accepting an €800K risk to save €80K?" That's a very different conversation.
5 mistakes that sink a cyber budget request in board meetings
Mistake 1 — Presenting in technical terms
"EDR renewal, SIEM upgrade" means nothing to a CFO. Translate: "Enhanced ransomware protection, with detection in under 4 hours instead of 48."
Mistake 2 — Leading with compliance
"We need this for NIS2 compliance" is external pressure, not internal conviction. Boards respond better to "here is the specific risk this covers for our organization."
Mistake 3 — Not anticipating objections
Your CFO will ask why it's higher than last year. Prepare factual answers to the top 3 objections before the meeting.
Mistake 4 — No data on last year's budget
Before asking for next year's budget, show what you did with last year's. If you can't, it signals a management problem, not a budget problem.
Mistake 5 — Not requesting a documented decision
When management chooses a scenario, ensure it is documented — board minutes, validation email. This protects both you and the organization if a residual risk materializes.
Frequently asked questions
How should a CISO present a cyber budget to the board?+
What is the recommended cyber budget for an SME?+
What is the average cost of a ransomware attack on a French SME?+
Prepare your 2026 cyber budget
Download the Eyako COMEX budget presentation template — or request a 30-minute session to structure your request.
Request a demo