Cybersecurity as a Growth Enabler · Part 3 of 3
Governance & Strategy

The Board Conversation Your CISO Isn’t Having

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
July 2026 · 8 min read

Most CISOs and CTOs know the technical case for cybersecurity investment. They understand the threat environment, the compliance requirements, the talent constraints. What they struggle with is something far more consequential: translating all of that into the commercial language that boards actually respond to. Revenue impact. Contract access. Competitive positioning. Investor confidence. The conversation that matters most is the one security leaders are not having, and it is costing their organisations real money.

We have spent two articles in this series building the case. Part 1 showed how compliance gaps silently disqualify businesses from contracts they never even knew existed. Part 2 examined the talent shortage and the phased capability model that makes security staffing commercially viable. This final piece addresses the gap that sits above both: the governance conversation. The moment where a CISO or CTO must walk into the boardroom and present cybersecurity not as a technical necessity but as a commercial investment with measurable returns.

That translation, from security language to board language, is where good strategies go to die. A well-constructed security programme with genuine commercial value can be defunded in the same meeting where the board approves £500,000 in sales headcount. Not because the investment case is wrong, but because it was presented in the wrong language to an audience that measures success in entirely different terms.

The companies pulling ahead on cybersecurity are not simply spending more. They are the ones whose security leaders have learned to frame the investment in terms the board cares about: risk-adjusted return, revenue protection, and competitive advantage. That reframing is the subject of this article.

The translation problem

CISOs speak in threats, vulnerabilities, and frameworks. Boards speak in revenue, margin, and shareholder value. The distance between those two vocabularies is not a minor communications inconvenience. It is the primary reason cybersecurity budgets face disproportionate scrutiny in every spending review.

Consider the typical board presentation on security. The CISO presents a slide on the current threat environment, references the Verizon 2025 Data Breach Investigations Report (which found that 68% of breaches involved a human element), describes the technical controls in place, and requests additional budget for tooling or headcount. The board nods politely. Then, when the finance director presents the quarterly spending review, that same security budget is the first line item questioned. Why? Because the CISO presented a problem. The sales director, by contrast, presented an opportunity with a projected return.

72%
of boards cite cyber risk as top priority
29%
feel adequately informed on cyber posture
18 to 24 mo
average CISO tenure
£3.29m
average UK data breach cost

This disconnect has measurable consequences. Average CISO tenure sits at 18 to 24 months according to industry benchmarks from Heidrick & Struggles and IANS Research. That is roughly half the tenure of a typical CFO or COO. The churn reflects a structural governance failure, not a talent problem. Security leaders burn out not because the work is too hard, but because they cannot get organisational buy-in for strategies they know are correct. They present in the language of risk. The board responds to the language of return.

PwC’s 2025 Global Digital Trust Insights survey revealed that 72% of board directors identify cyber risk as a top strategic priority. Yet the same research found that only 29% of those directors feel adequately informed about their organisation’s cyber risk posture. The gap between “we care about this” and “we understand this” is precisely where the translation problem lives. And it is the CISO’s responsibility, not the board’s, to close it.

The four metrics that boards actually care about

If boards do not respond to threat briefings, what do they respond to? The same things they respond to in every other investment decision: commercial impact, quantified in terms they use every day. Here are the four metrics that consistently shift board-level conversations on cybersecurity.

Revenue at risk

Every organisation should be able to answer one question: what percentage of current and pipeline revenue depends on maintaining security certifications and passing supplier due diligence?

For a £20m SaaS business where 60% of revenue comes from enterprise clients who require ISO 27001, the revenue at risk from losing or failing to maintain that certification is £12m. That is not a hypothetical. It is a figure the CFO will immediately recognise and the board will take seriously. As we covered in Part 1, procurement filters are automated and binary. Lose the certification and you lose the contracts. The CISO who can present this number, mapped against specific customer accounts and pipeline opportunities, is speaking the board’s language.

Calculating it is straightforward. Review every current customer contract and active pipeline opportunity. Flag each one that includes a security certification requirement or supplier due diligence clause. Sum the revenue. That is the figure at risk if the security posture or compliance status deteriorates.

Cost of inaction

Breach cost statistics are useful context, but boards have heard the IBM numbers before. The UK average sits at £3.29m according to the 2025 Cost of a Data Breach Report. That figure matters, but it feels abstract to a board that has never experienced a breach. What is not abstract is the cost they are already paying because of governance gaps.

This means quantifying the contracts lost because the business lacked the required certification. It means calculating the excess insurance premiums paid because the risk profile is unmanaged. It means documenting the investor objections raised during due diligence because the security governance framework was absent or immature. The UK Government’s Cyber Security Breaches Survey 2025 found that 43% of businesses experienced a breach or attack in the past twelve months, and yet the silent cost of contracts never won dwarfs the direct breach cost for most mid-market companies.

“We lost three enterprise bids worth a combined £1.8m last year because we could not demonstrate ISO 27001 certification.” That is a cost of inaction the board can act on.

Time to commercial readiness

How long until the business can compete for contracts it is currently excluded from? This metric translates the compliance roadmap into a timeline the board can measure.

If ISO 27001 certification takes nine to twelve months from gap analysis to Stage 2 audit, and the business is currently losing £500,000 per quarter in addressable pipeline because of the gap, the commercial readiness timeline has a direct revenue implication. Every quarter of delay costs £500,000 in accessible revenue. Frame the investment in those terms, not in the cost of the certification itself, and the board will see a different equation entirely.

This metric also creates natural accountability. The board can track progress quarterly: are we on schedule to be certification-ready by Q3? What has moved? What is blocked? It converts cybersecurity from an open-ended spend into a time-bound investment with a clear commercial trigger.

Return on compliance investment

The ratio between certification costs and the incremental revenue those certifications provide access to. As we outlined in Part 1, the direct costs of achieving certifications are modest relative to the contract values they open. But the board needs to see that ratio explicitly.

A practical example: if the total cost of achieving ISO 27001 is £20,000 in year one (including gap analysis, policy development, and audit fees) and that certification provides access to enterprise procurement panels representing £2m in addressable revenue, the return ratio is 100:1. Even with a conservative 10% win rate on that addressable pipeline, the business is looking at £200,000 in incremental revenue against a £20,000 investment. Present it that way, and no board in the country turns it down.

The four metrics that shift board conversations on cybersecurity: revenue at risk, cost of inaction, time to commercial readiness, and return on compliance investment. Includes worked examples showing £12m revenue at risk, £1.8m in lost bids, £500k quarterly pipeline cost, and 100:1 return ratio.
The Four Board Metrics: present revenue impact, not vulnerability counts. Sources: IBM 2025, PwC 2025, UK Gov 2025.

What the board paper actually looks like

Knowing the right metrics is half the challenge. Structuring them into a paper that the board will actually read, and act on, is the other half.

The most effective board papers on cybersecurity investment share a common architecture. They open with commercial opportunity, not risk avoidance. The executive summary should read like an investment memo, not an incident report. Something along the lines of: “This paper proposes a phased £85,000 investment over eighteen months to achieve ISO 27001 and SOC 2 certifications, providing access to an estimated £4.2m in currently inaccessible enterprise pipeline. The projected return exceeds 15:1 within the first twenty-four months.”

After the executive summary, the paper should present a three-year investment model showing costs, projected revenue access, and expected returns in each year. Year one is predominantly investment. Year two is certification and early commercial returns. Year three is full commercial benefit with ongoing maintenance costs only.

The phased roadmap should tie directly back to the capability model from Part 2. Phase one: managed security services to establish baseline controls. Phase two: fractional CISO engagement to build governance and drive certification. Phase three: dedicated security hire once the organisation’s scale and complexity justify it. Each phase has a cost, a timeline, and a commercial milestone.

Include a competitive analysis. Identify three to five certified competitors who are winning the contracts your business is currently excluded from. Name them. Show the board what those competitors have that you do not. This is the section that creates urgency, because boards are motivated by competitive pressure more reliably than by theoretical risk.

Finally, define the governance ask clearly. What does the board need to approve? What is the total investment? Over what timeline? And critically, what does the board need to oversee going forward? This sets up the governance model, which is the next piece of the puzzle.

The board paper framework: five-section structure for cybersecurity investment memos. Executive summary (open with commercial opportunity), three-year investment model, phased roadmap, competitive analysis, and governance ask.
The Board Paper Framework: how to structure a cybersecurity investment memo that gets approved.

The governance model that works

Effective board-level cybersecurity governance is not a quarterly update from the IT director. In organisations getting this right, it is a structured, measurable, and accountable function with the same rigour applied to financial or operational oversight.

The governance model that works has four components.

A defined reporting cadence. Quarterly cyber risk reporting to the board or a designated sub-committee, with a standardised dashboard that tracks the metrics outlined above: revenue at risk, cost of inaction, compliance roadmap progress, and return on compliance investment. The ISC2 2024 Cybersecurity Workforce Study noted that organisations with formal board reporting on cybersecurity spend 38% less time in reactive mode and resolve incidents 27% faster. Governance drives operational performance.

A clear committee structure. Whether it sits within the existing audit and risk committee or operates as a standalone cyber oversight function depends on the organisation’s size and sector. What matters is that someone at board level owns it. The Gartner prediction that by 2026, 70% of boards will include a member with cybersecurity expertise reflects the direction of travel. Organisations ahead of that curve are already benefiting.

Legal and regulatory alignment. This is no longer optional. NIS2, the EU’s updated Network and Information Security Directive, imposes explicit board-level accountability for cybersecurity governance. Management bodies can be held personally liable for non-compliance, with fines reaching €10m or 2% of global annual turnover for essential entities. In the UK, the Corporate Governance Code and the FCA’s operational resilience framework are pushing in the same direction. Boards that continue treating cybersecurity as a delegated IT function face regulatory exposure they may not yet appreciate. The WEF Global Risks Report 2025 ranks cyber insecurity among the top five risks for the second consecutive year, reinforcing the expectation that boards must engage directly.

Accountability that runs both ways. The board must hold the CISO accountable for delivering against the roadmap and the metrics. But the CISO must also hold the board accountable for providing adequate resources and removing organisational blockers. Governance is not surveillance. It is partnership. The most effective CISOs we work with treat the board relationship as a strategic alliance, not a reporting obligation. They present commercial outcomes, not compliance checklists.

The integrated investment case

This series has built a single thesis across three parts. Cybersecurity, compliance, and talent are not three separate cost lines. They are one integrated commercial capability.

Part 1 established the revenue case: procurement gates are real, and the contracts lost to compliance gaps are invisible until you look for them. Part 2 established the capability case: the talent shortage is structural, and the phased model (managed services, fractional leadership, then dedicated hire) is the only commercially viable path for most mid-market organisations. This final part establishes the governance case: the investment only works when the board understands it, funds it appropriately, and oversees it with the same rigour they apply to any other strategic investment.

The board conversation succeeds when it connects all three elements. The security posture that protects revenue. The talent model that sustains it. The governance framework that gives the board both confidence and accountability. Presented separately, each element looks like a cost. Presented together, they form a commercial strategy with a measurable return.

One capability, three pillars, measurable return. Part 1: security posture protects revenue. Part 2: talent model sustains capability. Part 3: governance drives accountability. Presented separately, three costs. Presented together, a commercial strategy with measurable return.
The Integrated Model: security, talent, and governance as one commercial capability. The thesis of the entire series.

This is what we deliver at Garzon Cyber Solutions. Not three separate workstreams, but one integrated advisory capability across cybersecurity, compliance, and specialist recruitment. We work with CISOs and CTOs to build the strategy, and with boards to present the investment case in language that secures buy-in and drives action. The integration is the point. A compliance programme without the talent to maintain it degrades within months. A talented security hire without a clear compliance roadmap delivers operational security but misses the commercial returns. A governance framework without genuine capability behind it becomes a liability at the next audit.

Closing

The strongest cybersecurity strategies fail when they cannot translate into board-level language. This is not a communications problem. It is a governance problem with direct commercial consequences.

The companies winning in competitive procurement, in investor due diligence, and in the increasingly regulated operating environment we all face are not the ones with the largest security budgets. They are the ones whose security leaders have mastered the commercial case. They present revenue at risk, not vulnerability counts. They calculate return on compliance investment, not project costs. They build governance models that the board trusts, rather than producing reports the board tolerates.

If your CISO is having the technical conversation but not the commercial one, the investment case is incomplete. And an incomplete investment case, however technically sound, will be deprioritised in favour of the next sales hire or product feature.

We built Garzon Cyber Solutions to close that gap. Cybersecurity advisory, compliance certification, and specialist recruitment, integrated under one advisory partner and presented in the language that boards, investors, and procurement teams respond to. If that conversation is overdue in your organisation, we should talk.

Is the board conversation overdue?

A focused discussion about translating your cybersecurity investment into the commercial language your board responds to.

Discuss More →

Sources: IBM Cost of a Data Breach Report 2025 · UK Government Cyber Security Breaches Survey 2025 · ISC2 Cybersecurity Workforce Study 2024 · Verizon Data Breach Investigations Report 2025 · Gartner Security and Risk Management Predictions · NCSC Cyber Essentials Scheme Documentation · Ponemon Institute Third-Party Risk Management Survey · PwC Global Digital Trust Insights 2025 · World Economic Forum Global Risks Report 2025 · Heidrick & Struggles / IANS Research CISO Tenure Studies · European Commission NIS2 Directive (EU 2022/2555) · UK Financial Reporting Council Corporate Governance Code

#Cybersecurity #BoardGovernance #CISO #ComplianceUK #CyberResilience #NIS2 #GarzonCyberSolutions

Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification, and specialist technology recruitment as one integrated capability for organisations scaling into enterprise markets.