The Board’s cyber question arrives after something has gone wrong. Yours arrives every close.
Cyber spend, in most organisations, has no unit economics: it’s priced against a heat map instead of a return. What closes an audit committee’s question is a number with a reason behind it, not a number with a trend line behind it.
THE QUESTION THAT ARRIVES EVERY CLOSE
Before the Board approves the accounts, you declare that the records have been properly kept and the statements give a true and fair view. That declaration rests on internal control over the systems the numbers run through, and cyber control counts toward it only there. The larger exposure sits elsewhere. The audit and risk committee asks why the cyber line grew twelve percent again. Internal audit asks whether the spend matches the risks it was approved to address. Your insurer, pricing the renewal, asks what the money bought.
None of these questions waits for a breach. All of them expect what a breach investigation eventually demands: a number with a reason behind it. Qantas’s June 2025 breach (5M+ customer records taken through an offshore call centre) closed with the regulator declining to open a formal investigation in July 2026. Optus and Medibank are defending civil penalty proceedings over their 2022 breaches on the opposite finding; Medibank’s shareholders are separately suing over continuous disclosure. Each of those examinations runs through the finance function at some point. The budget, the control framework the auditor tests against, and the disclosure call all sit on your side of the table.
WHY THE NUMBERS YOU GET TODAY DON’T ANSWER IT
Capex on a new plant line is modelled against a return. A hedge is priced against a modelled exposure. Cyber spend is priced against a heat map (an opinion rendered in red, amber and green) or a maturity score that benchmarks activity against a framework rather than the loss it prevents. Neither survives the question an audit committee, an insurer or a regulator actually asks: not “is this activity mature?” but “why did we spend this amount, and not more or less, on this particular risk?” A budget that simply grew every year has an answer nobody wants to give out loud: we kept adding controls until the number felt big enough to defend. That is an invoice with confidence attached, not a defence.
EVERY DOLLAR NEEDS ONE OF THREE REASONS
You already use a version of each of these elsewhere in the business. In this model’s vocabulary they are the Floor, Above-Floor spend and Risk Acceptance, and the labels belong to the practitioners who run the model. What belongs to you is the reasoning underneath each one.
The law or the Board has taken it out of cost-benefit.
The same logic that puts certain safety spend outside a normal return hurdle. Mandated spend comes from two sources: what the law already requires (your General Counsel names it) and what the Board has separately refused to price. Each obligated control is funded at the least-cost option that demonstrably closes its pathway, and the list has first call on the budget.
The expected loss avoided justifies the cost.
The same test you already run on a hedge or a capital project, borrowed rather than invented: Learned Hand’s B < P × L, capped by the Gordon-Loeb ceiling of roughly 37% of the expected loss protected. A stopping rule stated before the money is committed, not justified after the fact.
The organisation priced the gap and chose to carry it.
The same discipline you already apply to an exposure you have chosen not to hedge: identified, sized, owned and revisited on a set cycle. Not silence, and not spend the numbers don’t support just to avoid an uncomfortable conversation.
WHAT “THE NUMBERS JUSTIFY IT” SOUNDS LIKE
A worked case, kept identical across every paper on this model because the number should not change with the audience.
Ask for the break-even probability on every case put to you. Two things this test does not answer: how much of the tail your balance sheet can absorb in the year the event lands (what your aggregate tolerance and your insurance renewal are for), and what you can say if the disclosure clock starts before the loss is fully known. Both are covered in full in the companion guide.
SIX QUESTIONS FOR YOUR NEXT CLOSE
Put these to your CISO and your controller together, and have the answers recorded. Where an answer is vague, that vagueness is itself the finding. Several deliberately overlap with the Director’s Guide questions, and both sets should be answerable from the same quarterly pack.
- Is our mandated list finite and named, does it separate what the law requires from what the Board refused, and how much of this year’s cyber budget did it take before a single discretionary dollar was funded?
- For the last cyber spending request we approved: what expected loss did it remove, at what annual cost, and did it clear the Gordon-Loeb ceiling as well as the Learned Hand test? At what probability would the answer have changed?
- Which risks are we knowingly carrying? For each: who owns it, which stated tolerance it exceeds, when it must be re-examined, and how much of its tail our insurance actually covers.
- Who modelled the loss and who modelled the probability on our last three funding decisions, and who with no stake in the outcome tested them before they reached my desk?
- If one of our carried risks became a serious incident tomorrow, could we explain it to the market from the record we already have, or would we be rebuilding our reasoning against the clock?
- How much of our risk portfolio carries an evidenced, refreshed probability, how much rests on a sector average carried forward from last year, and how much is honestly “not yet assessed”?
The model has running costs of its own: the independent reviewer, the testing cycle, the people who produce the numbers. They belong in the same budget, tested by the same scrutiny. It starts small. A handful of scenarios and an honest pack that names its gaps is defensible from the first quarter.