How to explain risk to leadership

Leadership doesn't refuse security. It refuses a request it cannot translate into consequences.

The most common communication failure in security isn't a lack of technical arguments — it's a surplus of them. A list of vulnerabilities is not a decision. A decision has an impact, a likelihood, and a cost of doing nothing.

The formula that works: what concretely happens if we do nothing, how likely it is, what it costs to reduce it, and what risk remains accepted afterwards. Three sentences, not thirty slides.

Back to writing