How to explain risk to leadership
Leadership doesn't refuse security. It refuses a request it cannot translate into consequences.
The most common communication failure in security isn't a lack of technical arguments — it's a surplus of them. A list of vulnerabilities is not a decision. A decision has an impact, a likelihood, and a cost of doing nothing.
The formula that works: what concretely happens if we do nothing, how likely it is, what it costs to reduce it, and what risk remains accepted afterwards. Three sentences, not thirty slides.