The security board deck is the document that determines whether the security program gets funded, whether the CISO gets to keep their job, and whether the security team gets to hire the people they need. Most security board decks are bad. They are bad because they are written for the security team, not for the board. The field guide to writing the deck the board actually reads.
The board has 15 minutes for the security agenda item. They have 4 other items to get to. They are not security experts, they are not going to become security experts, and they are not going to read the 40 page deck you would rather give them. They want to know: are we safe, what the trend looks like, what we are asking for, and what could go wrong. A deck that answers those four questions in four slides gets the security program funded. A deck that buries those four questions in 40 slides gets the security program cut.
The four slides the board actually reads
Slide one: where we are. A single chart that shows the security posture over the last 12 months. Up is bad, down is good, the board does not need to be told which. Slide two: what we are doing. A single chart that shows the top three programs the security team is running. Each program is a single line, with a target date, a budget, and a status. Slide three: what we are asking for. A single slide that names the one or two things the security team is asking the board to fund, and the cost of each. Slide four: what could go wrong. A single slide that names the two or three risks the board should be aware of, and the mitigation in flight for each. Four slides. That is the deck.
What the board does not want to see
Three categories of content that belong in the appendix, not in the main deck. Technical detail: the board does not need to know the difference between a SIEM and a SOAR, the specific CVE that triggered the last incident, or the exact configuration of the firewall rule that blocked it. Vendor marketing: the board does not need to know which product the security team is using to do X, they need to know that X is being done and at what cost. Industry benchmark: the board does not need to know that other companies of similar size have X% more budget, they need to know what the security team is asking for and whether the budget is appropriate.
How to get the deck right
Three moves. Write the deck for the new board member, not for the existing one. The new board member has not been briefed on the security program, has not heard the jargon, and is reading the deck cold. If the deck makes sense to them, it makes sense to the rest of the board. Include the ask, because the board cannot fund what they do not know is being requested. Practice the deck out loud, because a deck that sounds good in the author’s head often sounds bad in the actual meeting room. The CISO who practices the deck with a peer before the board meeting is the CISO who gets the budget approved.

The bottom line
The security board deck is a 4 slide document that answers 4 questions: where are we, what are we doing, what are we asking for, and what could go wrong. Everything else is appendix. CISOs who write the 4 slide deck and practice it out loud are the ones who get the security program funded.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



