Numbers the board actually cares about
Alert-count and detection-count are internal metrics. They mean nothing at the board level. What lands: mean time to verdict, percentage of alerts investigated to conclusion, incidents contained under the SLA, cost per verdict, and dwell-time trend.
Present those five as a trailing-twelve-months curve. If the direction is right, the budget conversation is short. If it's wrong, the diagnosis — not the ask — is what needs to be defended.
The three-slide framing
Slide 1: what changed in the threat landscape (specific to your industry, with real numbers — not generic FUD). Slide 2: what we did with last year's budget and the resulting metrics. Slide 3: what we're asking for and what changes if we don't get it.
Slide 3 is the one boards remember. Frame the ask as options — not 'give us $X or we'll get breached'. Option A: current budget, coverage stays flat, MTTR trends up. Option B: +15%, add cloud detection engineering, MTTR trends down. Option C: +30%, add threat hunting. Boards respond to structured choices.
Budget lines to defend, trim, and consolidate
Defend: platform capabilities that produce measurable outcomes (agentic SOC, MDR coverage, detection engineering tooling). Trim: legacy SIEM ingestion where the marginal GB adds no detection value. Consolidate: SOAR + UEBA + case management into one platform if they're currently three vendors.
The consolidation math is usually where the biggest saving hides: three vendors at $200k each with overlapping capabilities can often become one at $350k. Show the CFO a line-item comparison table.
Rebuttals for the common objections
Our existing tools work fine → reply with the metric that shows they don't (e.g. 40% of alerts uninvestigated). We can't afford another vendor → reply with the consolidation math. AI security is unproven → reply with your shadow-mode metrics; not opinion, data. What if it fails? → reply with the kill switch, blast radius limits, and reversible-by-default architecture.
The pattern is always: reply with a number, not a claim. If you don't have the number, the conversation ends until next quarter — and by then someone else has made a decision.
What to promise vs what to deliver
Promise trailing outcomes, not target metrics. We committed to reducing MTTR from 14h to 4h in 12 months is a promise you can trace. We'll be more secure is a promise you can't defend when a board member asks how you measured it.
Every budget cycle should end with a written commitment to 3-5 metrics and a monthly report cadence. Boards that get the report on time trust the CISO — even in bad months.
Key takeaways
- Board metrics: MTTV, % investigated to verdict, incidents contained, cost per verdict, dwell time.
- Three-slide framing: threat change, prior-year outcome, structured options.
- Fear discounts; quantified risk lands.
- Consolidation math is where the biggest savings hide.
- Reply to every objection with a number, not a claim.
- Commit to 3-5 metrics and a monthly report — even in bad months.