Skip to content
TRANSMISSION ACTIVE
// FREQ: HEALTHCARE EPISODE: 030 STATUS: SECURE

030 The Trust Deficit, Security Theater, and How to Pitch Security to Non-Technical Leaders

The best security posture in the world protects nothing if it never gets funded, and most security programs die in the budget meeting rather than the breach. This transmission covers how to brief executives in the only three currencies they buy in — revenue, risk, and reputation.

JUMP POINTS //

01:07

Why a Thousand Vulnerabilities Is Not a Business Case

The CISO opens with the core failure: walking into the boardroom wearing only the security hat. A scan result is true and useless at the same time. Some boards have banned acronyms outright.

03:13

The Basketball Analogy, and Who Is Missing From It

Actual builds the trainer-and-athlete comparison. The CISO rebuilds it: the engineer is the player, the security leader is the trainer, and the executive is the team owner nobody remembered to include.

07:26

The $5,000 Pitch: Spend, Points, Wins, Revenue

The full translation worked end to end. Not “buy the equipment” but what the spend produces, what that wins, and what winning is worth. Executives buy outcomes, not activity.

12:04

Quantify Risk in Dollars and the Argument Ends

High, medium, and low are interpretations. A dollar figure is not. The CISO on why actuaries and finance staff should be the first people a security leader befriends.

14:00

When Security Is Not the Priority Element

Actual on the uncomfortable truth that support functions rank below revenue-producing ones, illustrated with a deployment fight over encrypted radio equipment. Know where you sit before you ask.

17:52

Run Reconnaissance on Your Own Board

Who has a security background. What the culture rewards. Whether compliance or customer trust is the stronger lever. Plus the reputational cost of crying wolf one time too many.

21:36

Marching Orders: Three Moves Before Your Next Brief

Never go in cold. Scope the ask to a specific outcome. Bring problem, consequence, solution, cost, and recommendation — and be the advisor rather than the alarm.

24:03

For Executives: Send the Brief Back

The angle flipped. What leadership should demand from a security team, and why accepting a briefing you did not understand is a failure on both sides of the table.

// INCOMING SITREP

This episode makes the case for pricing risk in dollars. The SITREP shows you the math. Read the field guide.

ACCESS THE BRIEF »

TRANSMISSION LOG //

There is one skill that determines whether a security program lives or dies, and it has nothing to do with technology.

This week we set the threat feed aside and covered communication — specifically, how to pitch security to the people who control the budget but do not speak your language. For healthcare security leaders, this is the difference between a segmentation project that gets funded and one that sits in a backlog until a ransomware operator funds it for you.

Why Technically Brilliant Security Leaders Lose the Room

The CISO has watched this failure play out for years, and the diagnosis is consistent: the security leader walks in wearing only the security hat.

The scan says a thousand vulnerabilities. Every one of them is real. And to the people across the table, the statement is inert.

“Executives make decisions in revenue, risk and reputation. If you’re only talking about vulnerabilities, it doesn’t line up with them.”

The second failure compounds the first. Pressed to explain, the security leader retreats further into the weeds, because the weeds are comfortable. The executives grow frustrated, because no business decision can be made from a list of CVE scores. The CISO’s blunt correction: it is not the executive’s job to understand your job, your language, or your terms. She has sat on boards that formally banned acronyms from their meetings. That should tell you how the other side experiences a technical brief.

The Analogy That Explains the Whole Problem

Actual opened with a trainer and an athlete. A basketball player wants to jump higher. A trainer who walks into the gym, points at the bench press, and starts prescribing chest work without ever asking about the goal will lose the player — because nothing connects the activity to the outcome.

The CISO took the analogy and fixed what was missing from it.

Three Roles, Not Two

The player is the security engineer. The trainer is the security leader. And the person nobody accounted for is the owner of the team — the executive, the board, the one who signs.

The engineer knows a specific control will work. The security leader believes him. Neither of them is who has to be convinced.

The Translation, Worked End to End

Walk into the owner’s office and ask for equipment for fifty players, and the answer is: you are the trainer, train them harder, that is what I pay you for.

Walk in and say the spend is roughly five thousand dollars, the team scores thirty more points a game, the games you lost by twenty become games you win, more wins fill more seats, and more seats sell more merchandise — and now it is not an equipment request. It is a revenue argument that happens to involve equipment.

“You have to talk in business terms. If we invest in this, we can win more games, which translates into more revenue.”

Actual brought the military version: pitching for water-capable tactical boots on a dive team, and winning the resource not by describing the boots but by describing what happened to mission success probability once the team stopped burning time swapping footwear on a hostile beach.

The word the CISO seized on was outcome. Tactical teams live in what has to get done today. Executives live in results. Brief them accordingly.

Quantify the Risk and the Argument Ends

Every pen test, vulnerability scan, and security assessment comes back in the same vocabulary: low, medium, high, critical. Those labels are defensible, but they are also interpretations. What reads as medium to you may read as low to the person holding the budget, and there is no way to settle it.

A dollar figure has no such wiggle room.

“Learn to quantify risk into a dollar value. There’s no argument there.”

A server costs a specific amount to replace. A lost patient relationship carries a specific annual revenue value. The CISO’s advice is to stop treating finance as a separate department: actuaries and finance staff should become the security leader’s closest partners. You do not need to do their job. You need their numbers.

The shift is from “we have a thousand vulnerabilities that need patching” to “here is what remediation costs, and here are the specific clinical and revenue processes that spend protects.” Those are not two versions of the same conversation. Only one of them is a conversation an executive can act on.

This is the point where the episode hands off. We make the case for the dollar figure here; the companion SITREP shows you how to build one. How to Quantify Cyber Risk in Dollars: The Board-Ready Field Guide walks the four-step method — naming the loss event, estimating frequency, building magnitude from numbers your organization already owns, and presenting a range instead of a point — with a fully worked ransomware scenario for a regional health system.

Know Where Security Sits in the Org

Actual raised the part most security leaders would rather not say out loud. Unless your company sells security, security is a support function.

He illustrated it with a deployment: encrypted radio equipment in short supply, contested between a supply element at the main base and the teams running forward operations. The teams got the gear. Supply did not argue, because everyone understood which element the mission actually turned on.

The lesson is not that security is unimportant. It is that security competes for the same dollar as the revenue-producing core, and a leader who does not connect the ask to that core is asking an executive to choose between security and the product. That is a bad question to force.

Read the Room Before You Walk Into It

A strong security leader runs reconnaissance on their own leadership.

Find out whether any board member has a security background — that person is an ally. Learn what the executive team actually prioritizes and what the culture rewards. In a highly regulated environment like healthcare, compliance is the lever: the organization cannot operate, contract, or sell without it, and that reframes security as the cost of doing business rather than discretionary spend. Outside regulated industries, the lever is customer trust. The CISO cited LastPass, where lost trust sent customers to competitors.

The Crying Wolf Problem

One warning came with real force. Security leaders who walk in every cycle predicting millions in losses train their board to discount them. Save the extreme framing for genuinely extreme situations. Otherwise the reputation that forms is “our CISO is very intense,” and that reputation costs more than any single rejected budget line.

Marching Orders

1. Never Brief Cold

Rehearse the presentation more than once. Have someone outside security review it before the executives do. Confirm you are speaking in revenue risk, reputation risk, or both.

2. Right-Size the Ask

Scope it. Cost it. Tie it to a specific outcome and explain why that outcome matters to the organization. If someone on the executive team cannot follow it on the first pass, they will read it as another security escalation rather than a business proposal.

3. Become the Advisor, Not the Alarm

Bring problem, consequence, solution, cost, and recommendation. Do not arrive with an ask every single time — sometimes arrive with education and bring your executives along. You know you have succeeded when a board member calls you unprompted and opens with “I’m thinking about this, what do you think?”

For the Executives Listening

We flipped the angle at 24:03, because this is not a one-sided obligation.

If your security leader hands you a long report enumerating controls, send it back. Ask for it again as a business presentation. You would not accept a raw ledger from finance without a concise explanation, and you should not accept the security equivalent.

Then close the loop: tell them explicitly what you expect from a briefing, and tell them when they get it right. Many security leaders were promoted up through technical roles and were never trained to brief a board. Coaching them is how you mature the function instead of quietly losing confidence in it.

Execute the Standard

Mission success starts with translation — turning what you know into something that can be acted on.

The best security in the world protects nothing if it never gets funded, and it will not get funded if it is not pitched in language the decision-makers can use. This is ultimately about respect: acknowledging that the people across the table have a mission too, and handing them a decision they can actually make.

Trust but verify your posture. Translate before you brief. Right-size the ask. Become the advisor, not the alarm.

If your organization needs an outside read on its control baseline, a remediation sequence tied to real exposure, or representation when the auditor arrives, that is the work we do. Verify your security posture or book a strategy call.

Execute the standard.

// DECODED TRANSCRIPT

Access the full text logs of this transmission for compliance and review purposes.

SILENCE THE NOISE. AMPLIFY THE SIGNAL.

INTELLIGENCE IS USELESS IF YOU AREN'T LISTENING.

Join The Watch to receive New Episode Alerts, Strategic Breakdowns, and Guest Intel delivered to your inbox.