Skip to content

WHT Cyber  /  Field Notes  /  Seasonal

Seasonal

Q4 budget planning: how to justify cybersecurity spend to your board.

“Why are we spending more on security this year?” is a fair question. Here's the answer in the language your CFO and board actually respond to — risk transfer, expected loss, and four line items that pay for themselves.

By WHT Cyber Engineering August 6, 2026 8 min read

It's Q4 budgeting season. Every SMB leader we work with in North Carolina is being asked the same question by their CFO, board, or partners: why is the cybersecurity line item bigger this year? And the answer that lands — the one that actually gets the number approved — is almost never a threat statistic. It's a business case in language finance people already use.

Here's the framework we hand our clients when they walk into that board meeting. It works for a 30-person law firm and it works for a 300-person manufacturer. Nothing exotic, no scare tactics, no acronyms nobody's heard of.

Reframe: cybersecurity is not an IT budget, it's risk transfer

The mistake most technical leaders make in a budget meeting is presenting security as a line item next to servers and licenses. It loses that argument every time, because it's competing with tangible ROI (new revenue system) against intangible ROI (nothing bad happened).

Reframe it before you open your mouth: this is risk transfer spending, in the same category as commercial general liability insurance, E&O, D&O, and building fire suppression. Nobody demands ROI on fire sprinklers. Nobody asks the CFO to prove that fire sprinklers “paid for themselves” last year. The question is: do we have the coverage the risk demands, and is it priced reasonably against the exposure?

Once the conversation is in that frame, the math gets easier.

Do the expected-loss math — on one slide

Boards respond to numbers. Not scary numbers. Their numbers, applied to a realistic scenario. The formula is boring on purpose:

Annualized expected loss = probability of incident × cost per incident

Here's the input side, using widely-published benchmarks so the number defends itself in the meeting:

  • Probability of a material cyber incident this year for an SMB: Verizon's DBIR and Coveware's ransomware reports have SMBs experiencing detectable intrusions at low double-digit percentages annually, and closer to 1-in-3 over a three-year window for firms in high-target verticals (financial services, healthcare, professional services). Anchor at 10-15% for a single year in your model.
  • Cost per incident for an SMB: IBM's Cost of a Data Breach Report puts the average SMB breach cost in the mid-six figures — and for ransomware specifically, the Coveware quarterly data shows median incident cost (downtime + recovery + notification + legal, not counting ransom) well above $200K even excluding the largest events.

Apply the math for a 60-person NC professional services firm:

10% annual probability × $400,000 cost = $40,000/year expected loss.

Now compare that to your proposed security spend. If the number is $60K/year and reduces that probability from 10% to 3%, you just took $28K of expected loss off the table for a $60K premium. That is exactly how the board thinks about insurance renewals. You're speaking their language.

Two honest caveats to add in the meeting so nobody feels sold: (a) these are industry averages and your real numbers will vary, and (b) probability reduction is directional, not guaranteed. Boards trust presenters who name their own assumptions.

Add the second-order costs the model misses

Direct incident cost is not the whole story. The other losses that show up in the year after a breach are often what actually shuts firms down. Include them explicitly on the slide:

  • Cyber insurance premium jumps or non-renewal. Post-incident renewals routinely see 30-100% premium increases or outright non-renewal. If you're an RIA or professional services firm required by contract or regulator to carry cyber coverage, non-renewal is an operational crisis, not just a cost.
  • Regulatory exposure. SEC Reg S-P amendments (2024) create direct notification obligations for RIAs; HIPAA fines are calibrated to size and severity; NC's Identity Theft Protection Act (75-65) requires PII-breach notifications. None of these are cheap even when you handle them cleanly.
  • Client contract clauses. Post-incident audits from your enterprise clients frequently reveal a “notify us within X days of any incident” clause you didn't remember. Missing that clock can lose contracts worth more than your entire security budget.
  • Employee turnover. A material incident is a leadership drain. Weeks of your CEO's calendar disappear. IT staff burn out. That cost never shows up on a slide but it's real.

The four line items that boards approve without pushback

If you have to pick your battles — and everyone does — here are the four investments we see approved cleanly at SMB boards in Q4 because they map directly to insurance questionnaires and regulatory expectations. Present these four first:

1. Real 24/7 monitoring (EDR + SOC)

This is line item #1. Every cyber insurance carrier now asks whether you have an EDR watched by a SOC (see EDR in Plain English and What a SOC Actually Does at 3 AM). Absent, you don't get coverage or you get it at 2x. Boards understand the answer to “we don't want a 100% premium hike” is spending 30-40% of that hike on the control that avoids it.

2. Phishing-resistant MFA rollout

Passkeys and hardware keys (see MFA Isn't Enough Anymore). This is a small dollar amount for a huge risk reduction and every board approves it if you present it as "closing the specific gap that took down [name a peer firm]."

3. Immutable backups with a tested restore

Not just backups. Immutable. Tested annually. This is the difference between a 3-day ransomware event and a 3-week ransomware event, and it's on every insurance questionnaire in 2026.

4. Security awareness + phishing simulation program

Human risk is still the entry point on most incidents. A modest annual investment in training with real, measurable simulations is defensible on any budget slide. It also produces reportable metrics the board likes seeing quarter over quarter.

These four cover the questions on every insurance renewal, satisfy every regulator we deal with for SMB clients, and account for roughly 80% of the risk reduction you can buy for the dollar. Fancier controls (SIEM, XDR, deception, purple team) are excellent but come later — and pitching them first is what makes boards say no to the whole package.

The North Carolina angle

For NC RIAs, the amended SEC Reg S-P (2024) means “we already have MFA and antivirus” is not a defensible posture in an SEC exam. For NC healthcare practices, the OCR audit program is picking back up and the fine matrix is bracketed by number of records — even a small practice can look at a six-figure penalty on paper. For manufacturers with defense contracts, CMMC Level 2 is now a gating requirement for many primes. All three groups are looking at Q4 budgets that need to hold water in front of an auditor, not just a CFO. That helps the ask — the requirement is external.

What WHT recommends

A one-page board slide that gets approved on the first pass:

  1. Slide title: Cyber Risk Transfer — 2027 Plan (not “IT Security Budget”).
  2. Line 1: Current expected annual loss under status quo. One line, one number, one citation.
  3. Line 2: Proposed investment, broken into the four line items above with dollar amounts.
  4. Line 3: Post-investment expected annual loss. Show the delta.
  5. Line 4: Insurance / regulator / client-contract requirements this closes. List them by name.
  6. Line 5: Peer benchmark — what similarly-sized firms in the same industry are spending as a % of revenue. Gartner publishes ranges; 3-6% of IT budget, or 0.3-0.6% of revenue, is the mainstream SMB band.
  7. Line 6: One-sentence recommendation and ask.

Do not include a threat statistic on that slide. Do not include a screenshot of a ransomware note. Do not include the word “sophisticated.” The number defends itself if the math is honest. Save the war stories for the follow-up conversation with the CFO after the vote.

Need the actual slide for your Q4 board meeting?

We'll build a one-page cyber-risk-transfer slide tailored to your firm's size, industry, insurance posture, and NC regulatory exposure. Bring it to the board with the math already done.

Book the Q4 board-slide session See all services →