Operating PlanNew · live in Executive Intelligence

Decide what to fund. Defend it to your CFO.

Your risk register already prices every scenario in dollars. The Operating Plan spends against it: programs ranked by expected loss reduced per dollar, a funding line drawn by the budget you actually have, and every “no” recorded as a signed decision instead of discovered as a gap.

The gap

88% of executives say measuring cyber risk is essential. 15% actually measure it in dollars. The gap was never conviction — the math that turns risk into a defensible budget was built for companies with a risk team. The Operating Plan runs it for everyone else.

JumpCloud, 2025 · PwC Global Digital Trust Insights, 2025

Companies with a risk team

Risk quant leadFAIR analystThreat modelerReporting analyst

Four hires before the first model runs.

You, in vCISO Lite

You

Zero new hires.

Same math. None of the headcount.

Three moments in every budget cycle

Same three arguments, every year. This year you bring the math.

Today
With the Operating Plan

Budget season opens. The ask is due.

≈ six weeks · one spreadsheet · every year

Programs listed from memory. Costs from two vendor quotes and a guess. A number at the bottom you’ll defend with adjectives, because nothing ties it to loss.

01 The decision

Your ask becomes an investment case.

Programs proposed from your own gaps, priced against expected loss, ranked by what each dollar buys down. The CFO stops hearing a cost center asking for faith — and the first draft takes about an hour.

See it

Finance counters with a 10% top-line cut.

≈ a weekend · a second spreadsheet · fresh errors

The counter-scenario is a new workbook, which means new discrepancies — so the meeting becomes an argument about whose numbers are right instead of a decision about what to cut.

02 The compare

Cuts get priced before they get made.

Finance’s counter runs against the same exposure data, so the 10% arrives with its cost attached. Either the cut shrinks, or the business chooses it with eyes open — you never absorb it silently.

See it

Twelve months later, someone finds the gap.

≈ hope · nothing on record

The scenarios you didn’t fund lived in your head. Now there’s an incident retro or an auditor in the room, and the question is “who decided this?” — and the honest answer is nobody, formally.

03 The record

Unfunded risk stops being quietly yours.

What you can’t fund gets priced, put in front of leadership, and signed into the register. Ownership moves to the business that chose it — so “who decided this?” has an answer, and it isn’t you.

See it

Act 01 · The decision

The funding line, drawn.

Security budgets die as lists — everything sounds necessary, nothing is ranked, and whatever didn’t fit just quietly doesn’t happen. The line ends that: programs ordered by the loss each dollar buys down, your budget deciding where the money stops, and everything below it still on the table, with a reason. The argument stops being “do we really need all this?” and becomes “is this the right number?”

reporting · forecasting · operating plan
draft · autosaved
BUDGET ENVELOPE$9.5M
10 of 13programs funded
$6.4Mresidual, from $18.6M
1.9×return on spend
SUGGESTEDIdentity & access program — maturity two levels below target · ~$640K/yr, starting estimateAdd to plan
ProgramAnnual costLoss reduced / $1Status
Identity & access hardening$640K$5.20Funded
Endpoint detection rollout$910K$4.10Funded
Backup & recovery upliftPINNED$520K$3.60Funded
Vendor risk program$450K$2.90Funded
Awareness & phishing simulation$180K$2.40Funded
Funding line · $9.5M
Zero-trust segmentation$1.4M$2.10Skipped — doesn't fit the remaining budget
DLP expansion$610K$1.30Skipped — ranked below the funding line

Act 02 · The compare

Answer “what if we cut ten percent” while they’re still asking.

Both plans run against the same exposure data, so the difference is a decision, not a discrepancy — and the Δ column is the whole conversation.

RecommendedFinance counter · −10%Δ
Budget$9.5M$8.55M−$950K
Committed spend$9.07M$8.44M−$630K
Programs funded108−2
Residual exposure$6.4M$7.5M+$1.1M
Return on spend1.9×2.0×+0.1×
Drops out at −10%: Vendor risk program · Awareness & phishing simulation

the 10% cut, priced: $1.1M more expected annual loss

Act 03 · The record

A finding in a deck is a slide. An acceptance in the register is a decision.

78% of security leaders now worry about personal liability for incidents (Splunk CISO Report, 2026) — and the established cover is a signed record that the business chose the risk. That’s what acceptance is here: it goes through the risk register’s own decision path, rationale required, chain-attested, sealed when the plan is promoted. You’re the one who priced the risk, not the one who quietly held it.

#Risk scenarioExpected lossCovered by this planDecision
RS-01Ransomware via phishing$6.2MCovered by 2 funded programs
RS-02Business email compromise$3.8M1 funded · 1 in plan, unfunded
RS-03Vendor data breach$2.9MCovered by 1 funded program
RS-04Cloud misconfiguration exposure$1.9MAccepted · signed“Single-region estate; exposure priced into the DR contract.”
RS-05Insider data exfiltration$1.4MIn plan, unfunded this cycle
Funded coverageIn plan, unfundedNothing touches it
Accepting is a decision about the scenario and applies everywhere; descoping is a decision about one program’s delivery. Accepted exposure stays in your residual number instead of vanishing.

The deliverable

The board packet is generated, not assembled.

Board slide, CEO one-pager, CFO variance letter, and the signed accepted-risk register — four artifacts from one plan of record, each figure traceable back to it. No reformatting the night before.

FY2027 Security Operating PlanBoard of Directors · Q4 packet
The ask
$9.07M
Expected loss
−66%
Return
1.9×
Not funded this year
  • Zero-trust segmentation deferred
  • DLP expansion deferred
  • Cloud misconfiguration exposure accepted
Expected annual loss · glide path
Q1Q2Q3Q4$18.6M$6.4M
Generated from the plan of recordDeferred, descoped and accepted — three separate schedules

One plan, five rooms

The same numbers, shaped for whoever’s asking.

Funding decision
The budget, the ranked list, the line. Where the money argument gets settled.
Roadmap
Eight quarters of plan–build–deploy sequencing, with deferred work hatched, not hidden.
Cost build-up
Zero-based payroll, technology and ops — reconciled against the top-down number, variance named.
Plan compare
Your plan against finance's counter, on the same exposure data. Two columns by design.
Board & exports
The board slide, CEO one-pager, CFO letter and signed register — generated, not assembled.

For vCISOs, consultants and MSPs

A defensible budget cycle for every client, without rebuilding the spreadsheet.

Scenarios come from each client’s own business context. The plans are yours to model, and every artifact carries the client’s name, their numbers, and your recommendation. Nothing gets assembled the night before the QBR — it’s all generated from the plan you already built together.

Per-client plans

Model several budget shapes per client and keep them side by side without cloning a workbook.

Bottom-up when they ask

Headcount and contracts roll up and reconcile against the approved number, so variance is explainable line by line.

Artifacts they can forward

Board slide, CEO summary and CFO memo, each carrying the client’s name and the decisions you made together.

Partner program →

Where it lives

Already in your subscription.

Quantified cyber exposure is becoming a governance expectation rather than an ambition — SEC disclosure rules and NIST CSF 2.0’s Govern function both put it in front of your board. The Operating Plan is how you show up with it already done.

Plan tier

Business and above

The Operating Plan ships inside Executive Intelligence, alongside quantified risk analysis and the auto-derived risk register it draws from. No separate line item, no module to buy.

Where to find it

Reporting → Forecasting

Log in and open Reporting → Forecasting → Operating plan. If your risk scenarios are already calibrated, your first draft plan is about an hour away.

What it needs from you

A real budget number

The number is the only input the platform can’t suggest. Everything else — programs, costs, scenario links — arrives proposed and labeled, for you to accept, edit, or dismiss.

Not on Business yet? See pricing → ·  Want a guided pass with your own numbers? Book a demo →

Bring your real budget number.

Risk teams have budgeted this way for years. Your first plan takes about an hour. Available on Business plans and above.