Cyber Budget COMEX Template
A 3-slide framework to defend your cyber budget in the boardroom. Used by CISOs who present risk scenarios rather than line-item lists — and who get budget approved.
Get the template — book a demoTemplate shared during our free 30-minute session.
The 3-slide framework
The 3 to 5 most probable cyber risk scenarios for your organization. For each: estimated probability, estimated financial impact, current coverage level.
→ Conclusion: here are the 2 risks where our coverage is insufficient today.
The 3 to 5 priority investments in business language. For each: which risk it reduces, by how much, at what cost.
→ The before/after heat map: visual representation of how exposure changes with the budget.
Residual risks after the budget, with their exposure level. An explicit recommendation to management.
→ "Are these risks acceptable?" (yes/no — documented decision in meeting minutes).
Present scenarios, not a request
A single budget request puts your board in a position to negotiate the number. Two or three scenarios put them in a position to choose a risk level.
Current budget maintained. List of open risks and their estimated probability of impact over the next 12 months.
NIS2 compliance + coverage of the most critical risks. Residual risks explicitly listed and validated by management.
Robust security posture aligned with your risk profile. Overall exposure significantly reduced.
The cost of inaction — key figures
5 mistakes to avoid
Get the full presentation template
The complete template (with risk translation table, scenario framework, and board decision documentation sheet) is shared during a free 30-minute session.
Book a free session