Board presentation template

Cyber Budget COMEX Template

A 3-slide framework to defend your cyber budget in the boardroom. Used by CISOs who present risk scenarios rather than line-item lists — and who get budget approved.

Get the template — book a demo

Template shared during our free 30-minute session.

The 3-slide framework

01Our current exposure

The 3 to 5 most probable cyber risk scenarios for your organization. For each: estimated probability, estimated financial impact, current coverage level.

Conclusion: here are the 2 risks where our coverage is insufficient today.

Signal: What it says to your board: you manage risk. You have structured visibility. You're in the same reasoning space as other COMEX members.
02What the 2026 budget covers

The 3 to 5 priority investments in business language. For each: which risk it reduces, by how much, at what cost.

The before/after heat map: visual representation of how exposure changes with the budget.

Signal: What it says to your board: every euro spent has a measurable counterpart in risk reduction. This is not spending — it's risk management investment.
03What we will not cover

Residual risks after the budget, with their exposure level. An explicit recommendation to management.

"Are these risks acceptable?" (yes/no — documented decision in meeting minutes).

Signal: What it says to your board: you're transparent about limits. You give them the final decision. You're not selling total security — you're proposing a reasoned risk level.

Present scenarios, not a request

A single budget request puts your board in a position to negotiate the number. Two or three scenarios put them in a position to choose a risk level.

Scenario A
Status quo

Current budget maintained. List of open risks and their estimated probability of impact over the next 12 months.

Scenario B — Recommended
Minimum NIS2 coverage

NIS2 compliance + coverage of the most critical risks. Residual risks explicitly listed and validated by management.

Scenario C
Target coverage

Robust security posture aligned with your risk profile. Overall exposure significantly reduced.

The cost of inaction — key figures

€250K–€1.2M
Ransomware — 500–1,000 employee SME
Direct + indirect costs (ANSSI / Hiscox 2025)
€4.5M
Average data breach cost
60% indirect costs — IBM 2025
21 days
Average downtime without BCP
Ransomware — SME without formal recovery plan

5 mistakes to avoid

Leading with technical terms
Translate "EDR renewal" to "ransomware protection in under 4 hours."
Leading with compliance
Replace "we need this for NIS2" with "here is the specific risk this covers for us."
Not anticipating objections
Prepare factual answers to: why is it higher, what happens if we don't, can we share with IT.
No data on last year's budget
Show what you did with last year's budget before asking for next year's.
No documented decision
Ensure the board's scenario choice is in the meeting minutes or a validation email.

Get the full presentation template

The complete template (with risk translation table, scenario framework, and board decision documentation sheet) is shared during a free 30-minute session.

Book a free session
Cyber Budget COMEX Template — Free for CISOs | Eyako