# Cyber risk investment committee memo

INVESTMENT COMMITTEE MEMO — CYBER RISK SECTION
Target / scope / evidence cut-off: [company, services and date]
Deal sponsor / evidence owner / reviewer: [names and roles]

DECISION REQUESTED
[Proceed subject to conditions / obtain further diligence / other decision]
Cyber funding envelope and cost horizon: [amount, currency and period]

WHAT IS KNOWN
[material finding] — [source, collection date, coverage and limitation]
Business service and plausible loss scenario: [description]
Controls actually tested: [test, scope, result and date]

WHAT IS STILL ASSUMED OR MISSING
[input or gap] — [assumption, source basis, owner and due date]
Effect on the decision: [what could change / hold condition]

FINANCIAL ANALYSIS, IF SUPPORTED
Annual gross loss: [mean and selected percentile, or not modeled]
Model / inputs / uncertainty / exclusions: [version and source links]
Priced alternatives: [cost, horizon, implementation assumptions]
Required spend: [source of obligation and cost]
Insurance recovery: [separate analysis or not modeled]
Do not subtract annual loss from EBITDA or multiply it by an exit multiple.

POST-CLOSE HANDOFF
Action | fund / defer / validate | owner | first-year cost | evidence | review date
[row]
Conditions requiring escalation before close: [specific conditions]
First post-close funding review: [date and approver]
Next evidence review and unresolved owner: [date and name]

Source: https://valty.ai
Free to adapt for your organization. Replace placeholders with reviewed, scoped evidence.
