TL;DR: Presenting cybersecurity risk to executives fails when the update answers a question nobody asked. Leadership wants to know whether the business keeps running, what a bad day costs, and what they’re being asked to decide. Skip the borrowed breach statistics, build the report around two or three business scenarios, and give every risk an option with a price attached.
Presenting cybersecurity risk to executives goes wrong in a specific way, and it usually happens about four minutes in.
You’re walking through patch compliance, or a vulnerability count, or the new detection tool. Someone asks a question that sounds simple. “So are we okay?” You answer honestly, which means starting with “it depends,” and you can watch the room decide this isn’t a decision meeting.
That’s not a failure of intelligence on either side. Executives are trying to work out whether the exposure is acceptable and whether the people running technology are making sensible calls. The trouble is that most technical updates never answer either question.
Directors know it. In the National Association of Corporate Directors’ 2026 handbook on cyber-risk oversight, 43% of public company directors and 57% of private company directors said improving the quality of management’s cyber-risk reporting was very or extremely important for the year ahead. The private company number is the higher one, which tells you where these conversations are roughest.
Why do cybersecurity updates lose the room?
They answer a question nobody asked. Technical reporting describes the state of the systems. Executives are trying to price a business decision. Until the update connects to operations, revenue, or a choice they have to make, it’s information rather than something to act on.
Think about what the people in the room are responsible for. They approve budgets, accept risk, and answer to partners, lenders, or a board. None of those jobs require knowing your patch cadence. All of them require knowing what happens on the worst plausible day.
A dashboard full of green checkmarks doesn’t help either. It proves your tools ran. It doesn’t say whether you could still invoice customers on Thursday if the server room went dark Wednesday night. Those are different claims, and only one is a risk report.
Stop borrowing someone else’s breach number
Here’s the move almost everyone makes, and it backfires. You open with a headline statistic to prove this matters. IBM’s 2026 Cost of a Data Breach report puts the global average at $4.99 million and the US average at $11.5 million.
Now picture a 40-person Louisville firm hearing that. The number is real and completely disconnected from anything they recognize, because everyone knows the company doesn’t have $11.5 million to lose. The statistic meant to create urgency instead files the topic under “things that happen to other people.”
The persuasive number is smaller and closer to home. When a cyberattack stopped Jaguar Land Rover’s production for five weeks in 2025, the UK’s Cyber Monitoring Centre put the economic damage near £1.9 billion and made the point that matters most for the rest of us: operational disruption generated virtually all of the financial loss. Not fines. Not lawsuits. Idle plants and a supply chain that couldn’t move.
That’s the version of the story that scales down to any business. Do the arithmetic for your own company instead of quoting someone else’s:
- Your headcount times the loaded hourly cost of an employee, for every hour people can’t work.
- Revenue per operating hour, for the work that doesn’t get billed or shipped.
- The overtime, the vendor emergency rates, and the week of catching up afterward.
For a 40-person professional services firm, a day and a half of downtime lands in the low tens of thousands. That number is small enough to be believed and specific enough to argue with, which is why it works. A board that shrugs at $11.5 million will engage seriously with $38,000 and a lost Tuesday.
What do executives actually want to know?
Three things: whether the business can keep operating, what a bad day costs, and what you’re asking them to decide. Every slide should serve one of those. If it doesn’t, it belongs in the appendix.
That third one gets skipped most often. Technical leaders present exposure and then wait, hoping someone volunteers budget. Executives don’t respond well to open-ended worry, because there’s nothing to approve.
Give each risk an option instead. Name the gap, the fix, the price, and the risk that remains after you spend the money. Now it’s a trade-off, which is what executives decide on all day. That framing is also the heart of managed IT services in Louisville done well, where the reporting is built into the engagement.
Build the report around scenarios, not systems
Organize by what could happen to the business, not by which technology you manage. NACD’s guidance points the same way: pick a few high-impact scenarios and walk each through quantified exposure, current controls, gaps, and timelines.
Two or three is plenty. For most small and mid-sized companies they’re some version of these:
- Ransomware hits core systems. How long until we’re operating again, and what does that gap cost? This is where tested backup and recovery either saves you or doesn’t.
- A critical vendor goes down or gets breached. What do we lose access to, and for how long?
- Someone gets paid who shouldn’t. Fraudulent invoice, redirected payroll, changed bank details.
For each, keep it to four lines: what happens, what it costs in hours and dollars, what’s in place now, and what would meaningfully reduce it. A page that leads to a decision beats twelve slides that lead to a nod.
How often should you brief leadership on cyber risk?
At least quarterly, plus immediately after any material incident or significant change in exposure. NACD recommends that cadence and it works for smaller companies too. Agreeing in advance on what triggers an unscheduled update matters as much as the calendar.
Consistency is underrated. When the format stays the same quarter to quarter, executives can see the direction of travel, which is what they’re really after.
Set escalation thresholds ahead of time, in business language: a dollar figure, a number of customers affected, or an outage length. Deciding what counts as serious while something is on fire never goes well. It’s worth working through with an outside advisor, and it’s a standard part of cybersecurity consulting work.
What if you don’t have time to prepare?
Then it doesn’t happen, and you present something assembled the night before. That’s the honest reality for most internal IT leaders, who are also handling escalations, projects, vendors, and whatever landed Monday.
Good reporting takes real work. Someone has to pull the evidence, run the numbers, keep the format consistent, and prepare for the budget questions that always arrive.
That’s a large part of why co-managed IT support exists. When the day-to-day load is shared, the analysis gets done properly instead of at speed. You still lead the conversation. You just walk in with the groundwork finished.
The takeaway
Risk conversations don’t fail because executives are non-technical. They fail because the numbers are borrowed, the scenarios are missing, and nobody’s been asked to decide anything.
Fix those three and the room changes. Use your own arithmetic, organize around two or three things that could really happen to your business, and end every risk with a priced option. It’s less impressive than a threat briefing and far more useful. The same logic applies to security awareness training and every other line item you have to defend.
If you’d like a second set of eyes on how technology risk gets reported to your leadership, book a short intro call.
Frequently Asked Questions
How do you explain cybersecurity risk to a non-technical executive?
Translate it into operations and money. Describe what would stop working, how long recovery takes, and what that gap costs in labor and lost revenue. Then present the choice you want them to make, with a price and the risk that remains.
What should be in a board-level cybersecurity report?
A short summary of current posture, two or three quantified risk scenarios, incident and recovery readiness, any compliance obligations, and the investment decisions you’re bringing forward. NACD recommends business and financial framing over technical metrics.
Should I use average breach cost statistics in a board presentation?
Use them carefully. Averages like IBM’s $11.5 million US figure are accurate but rarely relatable for a smaller company, and an unbelievable number invites everyone to dismiss the topic. Your own downtime arithmetic is more persuasive.
How often should leadership receive a cybersecurity update?
At least quarterly, with immediate updates after a material incident or a significant change in exposure. Agree on the escalation triggers in advance, expressed in business terms like outage length or number of customers affected.
How do I quantify cyber risk without a formal risk model?
Start with time. Estimate how long each scenario keeps people from working, multiply by headcount and loaded hourly cost, then add lost revenue per hour and recovery expenses. It’s rough but defensible, and built from numbers leadership already recognizes.
Get a Second Opinion Before Your Next Board Meeting
Technology risk is easier to explain when someone has helped you build the case. Z-JAK works alongside internal IT teams and leadership groups across Louisville to turn technical exposure into reporting executives can act on. Reach out to start the conversation and we’ll review what you’re presenting today.
