The Board Cyber Brief: A Funding Decision with Evidence
Use a board decision brief to compare costed cyber actions, explain modeled mean and P95 loss, record assumptions and assign the next review.
A cybersecurity board brief should make a decision clear: what management recommends, what it costs, what evidence supports it, and what the board is being asked to approve or challenge. Start with the ungated board report template and annotated example. This article explains how to use that decision brief inside a broader board reporting cycle.
A funding brief does not replace incident updates, compliance reporting or the board's other oversight duties. It gives one budget question a consistent structure. Keep the decision owner and the evidence cut-off visible from the first page.
1. State the decision and the financial object
Name the company, business service, proposed action, budget cap and cost horizon. If you have a supported loss estimate, identify whether it is mean annual loss, a selected annual percentile, or another explicitly defined metric. Use “not modeled” when the inputs are insufficient.
The shared fictional example has a $100,000 first-year budget. It proposes a $90,000 plan for the lowest modeled P95 annual gross loss among the priced, affordable options. That plan combines a required $15,000 tabletop with a $75,000 recovery investment. The tabletop receives no modeled loss-reduction credit.
Baseline modeled mean annual loss is $791,066; baseline P95 is $3,512,449. These answer different questions. P95 is the annual loss threshold exceeded in about 5% of simulated years. It is not expected loss, a worst-case ceiling or a confidence interval around the estimate. The 50,000-trial sample records the assumptions and unrounded results. It models gross annual loss before insurance and does not adjust EBITDA or valuation.
2. Explain the drivers without inventing contributions
Identify the business event and evidence that drive the scenario: for example, disruption to a production service, recovery dependencies and the time needed to restore it. Record what was observed, what was assumed and what remains unknown.
Do not assign a dollar loss to every scanner finding simply because it has a severity score. Several findings can contribute to the same event, and losses or percentile reductions cannot generally be added across overlapping scenarios. A useful driver explanation shows which input matters and how the recommendation changes when that input is challenged.
For this example, recovery's assumed effectiveness matters enough to reverse the choice. If it lowers mean per-event severity to $800,000 instead of $650,000, modeled P95 rises to $2,348,379 and access hardening becomes the better P95 option. The investment-prioritization guide explains that sensitivity test.
3. Compare alternatives against the same objective
The proposed recovery plan costs $90,000 and produces modeled mean annual loss of $513,439 and P95 of $1,908,058. The access-hardening plan costs $70,000 and produces modeled mean of $402,566 and P95 of $2,092,283. Both totals include the required tabletop.
Recovery has the lower P95; access has the lower mean. Funding both costs $145,000 and exceeds the cap. State which objective the approver chose before calling an option preferable. A reduction-per-dollar ratio can inform the discussion, but it does not replace required work, dependencies, implementation capacity or the budget constraint.
Keep modeled financial movement separate from expected economic return. The difference between two P95 figures is not expected savings. Any economic business case also needs the cost horizon, recurring costs, implementation timing and evidence for the assumed control effect.
4. Give assumptions and unknowns an owner
Every material input needs a source, collection date, scope and accountable owner. A public prior can support an assumption; it is not observed evidence about the company. A missing quote is not a zero-dollar action, and an untested control is not verified effectiveness.
Benchmarking is optional. Include it only when the comparison set, units and method support the question being asked. The fictional sample has no independently validated peer benchmark. An unavailable benchmark should stay unavailable rather than becoming an invented percentile.
Use the CRQ data checklist to collect inputs, and show any condition that should hold the recommendation until evidence arrives.
5. Record approval and the next review
The board or authorized budget owner should be able to record approve, defer or obtain validation, with conditions, an execution owner and a due date. The next report should distinguish actual spend, observed control changes and any recomputed modeled loss. A lower model output is not an observed avoided loss.
A ticket marked closed is not enough. Request evidence appropriate to the approved action, scoped to the affected resource and collected after the change. A backup configuration check cannot substitute for a restore test. Failed or stale verification remains visible in the next cycle.
The 2026 NACD Principle Five guidance frames cyber measurement and reporting in the context of strategy, risk appetite, and business objectives. The practical implication is that a report has to do more than inform. It has to help directors ask better questions, give direction, identify who owns the response, and determine what will be reviewed again. The board brief is therefore an input to a governance cycle, not the finish line.
Use the template in your existing board pack
The blank decision brief keeps the recommendation, alternatives and approval together. Carry unresolved work into the 100-day plan, with an owner and review date. Add change-since-last-review and operating updates in the firm's existing reporting format.
Valty's public sample and authentic application captures are illustrative evidence of the workflow, not a customer result or NACD endorsement. A platform evaluation should establish which source collection, approvals, execution paths and verification are supported for the company before stronger claims are made.
Inspect the fictional sample decision memo, or request a platform demo to explore the supported workflow with illustrative data. Company scope, evidence handling, access, onboarding and commercial terms are agreed separately before evaluation.
