A CEO is not the person who patches a server. A CEO is the person who decides whether patching that server was worth more than the three other things the budget could have funded instead. That decision needs a number, not a maturity score.
The decision a CEO is actually making
Cyber risk reaches a CEO’s desk as a resourcing question: how much of this year’s budget goes toward reducing exposure, and which exposure gets funded first. A qualitative rating, such as a heat map colour or a maturity level, does not answer that question, because it cannot be compared against the cost of a control or against any other line item competing for the same budget.
An exposure figure calibrated to P50 and P95 can be compared. It sits next to a revenue forecast or a capital expenditure request using the same unit, euros, and the same logic: expected value against cost. That is what lets a CEO treat a security investment as an investment rather than a compliance line item.
Why the evidence behind the number matters as much as the number
Not every input to an exposure figure carries the same weight. Some come from a company’s own control environment; others come from public information alone because target cooperation was not available yet. Evidence-labelling keeps that distinction visible, so a CEO reviewing the figure knows whether it is ready to anchor a transaction decision or whether it is a first-pass screen that will tighten once more evidence arrives.
This is also what makes the number defensible outside the room it was built in. A figure that traces cleanly through a scenario, a control, a dependency, and a business process survives the first hard question from a board or an acquirer. A maturity score does not, because there is no chain to inspect.
What changes across a company’s lifecycle
The same quantification logic applies whether the question is screening an acquisition target before diligence begins, confirming exposure on a deal already under exclusivity, or tracking how a portfolio company’s exposure moves quarter to quarter after close. A CEO evaluating an acquisition target benefits from an early exposure read that does not require the target’s cooperation to start. A CEO running a portfolio benefits from the same figure being re-quantified on a cadence, so a change in exposure shows up before it becomes an incident.
The practical takeaway
Protecting a business from cyber attacks is not a checklist a CEO signs off on once. It is a recurring decision about where to spend, made easier when the exposure behind it is expressed as a number with a stated confidence range, built from evidence that is labelled rather than assumed, and comparable to every other decision already running through the same budget.
