Twelve minutes on the agenda, and one question with no good answer.
You cannot prove the organisation is secure. What you can prove is that your reasoning holds — and that is the question the Board was actually asking.
THE QUESTION EVERY CISO DREADS
A CISO has twelve minutes on the agenda. A director asks the question directors always ask, in the plain language they use: “Are we secure?”
She can answer honestly — no organisation is ever fully secure — and watch the room’s confidence drain out of it. She can answer reassuringly — we meet every standard we are required to meet — and hope nobody asks what happens between audits. Either way she will be back next quarter asking for budget, and the Board will remember exactly how unconvincing the last answer was.
This is not a failure of competence. It is a failure of vocabulary: years of genuine technical judgment about where the risk actually sits, and no reliable way to say so in a sentence a Board can act on.
WHO GETS TO TEST “DEFENSIBLE”
A regulator investigating an incident. A plaintiff’s counsel probing what the organisation knew and when. An auditor testing whether controls operate as claimed. An insurer pricing a renewal. A shareholder asking why spend was allocated the way it was.
Each asks a version of the same question: show me the reasoning, not just the outcome. Which has a hard consequence for how the model is built — every figure it produces has to be traceable to a named owner and a named check. A number nobody can defend under questioning is worse than useless, because it creates the appearance of rigour without the substance of it.
TWO WAYS ORGANISATIONS GET THIS WRONG
Both look like diligence from the inside. Neither is defensible from the outside.
Compliance theatre
Chasing a checklist without ever testing whether the checklist addresses the organisation’s own expected loss. A certification tells you a control exists. It does not tell you whether that control is the one worth having, or whether it is proportionate to the loss it prevents. Two organisations can hold the same certification and be in wildly different real positions.
Unbounded spend
Treating “more security” as an unambiguous good and funding every proposal that sounds prudent. It feels safer than under-spending and is just as indefensible, because nobody can explain why spend stopped where it did. No stopping rule was ever applied — the budget simply ran out.
Both are also communication failures, which is why they matter here. Compliance theatre sounds reassuring right up until someone asks a follow-up question it cannot survive. Unbounded spend sounds responsible right up until someone asks why it stopped where it did.
WHERE THE MODEL COMES IN
This is the gap the Reasonable Allocation Model closes. Instead of chasing a checklist or spending until the budget runs out, it forces every resourcing decision through a single test — is this defensible, and can it be proven — and assigns each decision an owner who can answer for it later. That turns “are we secure?” from a question with no good answer into one a CISO can walk into the boardroom and actually answer.
“We took the risk appetite this Board already set and turned it into a floor — the handful of things that would be indefensible to get wrong, like a mass exposure of our customer data or losing control of one of our safety-critical systems — and I can show you, one by one, that we meet it today. Above that floor, we’ve spent further in three places where the cost of getting it wrong is genuinely out of proportion to everything else — the protection of our R&D data, the segmentation that keeps our corporate IT and our plant floor apart, and our suppliers’ access into our network — and I can walk you through why that extra spend was worth it in each case. Everywhere else, we’ve made a deliberate call not to spend further, within the appetite you set, and the business owner who made that call is in this room and can explain it. So the honest answer isn’t yes or no. It’s this: here’s every line we drew, who drew it, and why — all inside boundaries this Board already approved. Push on any one of them and I’ll give you the reasoning behind it.”