Operating PlanNew · live in Executive Intelligence
Decide what to fund. Defend it to your CFO.
Your risk register already prices every scenario in dollars. The Operating Plan spends against it: programs ranked by expected loss reduced per dollar, a funding line drawn by the budget you actually have, and every “no” recorded as a signed decision instead of discovered as a gap.
The gap
88% of executives say measuring cyber risk is essential. 15% actually measure it in dollars. The gap was never conviction — the math that turns risk into a defensible budget was built for companies with a risk team. The Operating Plan runs it for everyone else.
JumpCloud, 2025 · PwC Global Digital Trust Insights, 2025
Companies with a risk team
Four hires before the first model runs.
You, in vCISO Lite
Zero new hires.
Same math. None of the headcount.
Three moments in every budget cycle
Same three arguments, every year. This year you bring the math.
Budget season opens. The ask is due.
≈ six weeks · one spreadsheet · every year
Programs listed from memory. Costs from two vendor quotes and a guess. A number at the bottom you’ll defend with adjectives, because nothing ties it to loss.
01 The decision
Your ask becomes an investment case.
Programs proposed from your own gaps, priced against expected loss, ranked by what each dollar buys down. The CFO stops hearing a cost center asking for faith — and the first draft takes about an hour.
See itFinance counters with a 10% top-line cut.
≈ a weekend · a second spreadsheet · fresh errors
The counter-scenario is a new workbook, which means new discrepancies — so the meeting becomes an argument about whose numbers are right instead of a decision about what to cut.
02 The compare
Cuts get priced before they get made.
Finance’s counter runs against the same exposure data, so the 10% arrives with its cost attached. Either the cut shrinks, or the business chooses it with eyes open — you never absorb it silently.
See itTwelve months later, someone finds the gap.
≈ hope · nothing on record
The scenarios you didn’t fund lived in your head. Now there’s an incident retro or an auditor in the room, and the question is “who decided this?” — and the honest answer is nobody, formally.
03 The record
Unfunded risk stops being quietly yours.
What you can’t fund gets priced, put in front of leadership, and signed into the register. Ownership moves to the business that chose it — so “who decided this?” has an answer, and it isn’t you.
See itAct 01 · The decision
The funding line, drawn.
Security budgets die as lists — everything sounds necessary, nothing is ranked, and whatever didn’t fit just quietly doesn’t happen. The line ends that: programs ordered by the loss each dollar buys down, your budget deciding where the money stops, and everything below it still on the table, with a reason. The argument stops being “do we really need all this?” and becomes “is this the right number?”
Act 02 · The compare
Answer “what if we cut ten percent” while they’re still asking.
Both plans run against the same exposure data, so the difference is a decision, not a discrepancy — and the Δ column is the whole conversation.
the 10% cut, priced: $1.1M more expected annual loss
Act 03 · The record
A finding in a deck is a slide. An acceptance in the register is a decision.
78% of security leaders now worry about personal liability for incidents (Splunk CISO Report, 2026) — and the established cover is a signed record that the business chose the risk. That’s what acceptance is here: it goes through the risk register’s own decision path, rationale required, chain-attested, sealed when the plan is promoted. You’re the one who priced the risk, not the one who quietly held it.
The deliverable
The board packet is generated, not assembled.
Board slide, CEO one-pager, CFO variance letter, and the signed accepted-risk register — four artifacts from one plan of record, each figure traceable back to it. No reformatting the night before.
- Zero-trust segmentation deferred
- DLP expansion deferred
- Cloud misconfiguration exposure accepted
One plan, five rooms
The same numbers, shaped for whoever’s asking.
For vCISOs, consultants and MSPs
A defensible budget cycle for every client, without rebuilding the spreadsheet.
Scenarios come from each client’s own business context. The plans are yours to model, and every artifact carries the client’s name, their numbers, and your recommendation. Nothing gets assembled the night before the QBR — it’s all generated from the plan you already built together.
Model several budget shapes per client and keep them side by side without cloning a workbook.
Headcount and contracts roll up and reconcile against the approved number, so variance is explainable line by line.
Board slide, CEO summary and CFO memo, each carrying the client’s name and the decisions you made together.
Where it lives
Already in your subscription.
Quantified cyber exposure is becoming a governance expectation rather than an ambition — SEC disclosure rules and NIST CSF 2.0’s Govern function both put it in front of your board. The Operating Plan is how you show up with it already done.
Business and above
The Operating Plan ships inside Executive Intelligence, alongside quantified risk analysis and the auto-derived risk register it draws from. No separate line item, no module to buy.
Reporting → Forecasting
Log in and open Reporting → Forecasting → Operating plan. If your risk scenarios are already calibrated, your first draft plan is about an hour away.
A real budget number
The number is the only input the platform can’t suggest. Everything else — programs, costs, scenario links — arrives proposed and labeled, for you to accept, edit, or dismiss.
Not on Business yet? See pricing → · Want a guided pass with your own numbers? Book a demo →
Bring your real budget number.
Risk teams have budgeted this way for years. Your first plan takes about an hour. Available on Business plans and above.