Building a risk-first cyber budget your board will back
Your influence on the board starts long before your formal presentation. This session, the second in The CISO’s Guide to Risk-First Budgeting series, explores how to collaborate with your executive team from day one, align on priorities, and be prepared when the board inevitably asks about cybersecurity.
Rob Brown, Senior Director of Cyber Resilience, brings 25+ years of experience as a strategic planner and decision science advisor, including as a contributor to books on measuring cybersecurity risk. Chris Wheeler, Resilience’s Chief Information Security Officer, adds the CISO’s perspective on creating, defending, and communicating a risk-first cybersecurity budget with confidence.
About Speakers

Chris Wheeler is a seasoned cybersecurity leader with a diverse background in military service and the private sector. He currently serves as the Chief Information Security Officer at Resilience. Previously, Wheeler spent nearly five years as a vice president at Morgan Stanley, where he was the SOAR Lead and Senior Security Analyst (L3) Manager for the Cyber Incident Response Team (CIRT).
His earlier experience includes leading an analytic engineering team at Arbor Networks and serving as an Officer in the U.S. Navy for six years. He received his Bachelor’s degree in Computer Science and Information Technology from the United States Naval Academy.

Rob Brown brings 25+ years of experience serving organizations from startups to government agencies and Fortune 100 companies as a senior strategic planner and decision science advisor. His support spans multiple commercial verticals including electronics manufacturing, telecommunications systems, petroleum exploration, pharmaceutical product development, and aerospace and other industrial manufacturing. Not only is he the author of Business Case Analysis with R – Simulation Tutorials to Support Complex Business Decisions (2018), he contributed as a technical editor to Richard Seiersen’s book The Metrics Manifesto: Confronting Security with Data (2022) and as an author of an appendix chapter to Douglas Hubbard’s and Richard Seiersen’s book How to Measure Anything in Cybersecurity Risk (2nd Edition, 2023).
Any company that sells hardware or software with network connectivity into an EU member state has to report vulnerabilities and incidents affecting that product. The regulation calls these products with digital elements, and it applies to the manufacturer regardless of where the manufacturer is based, so a US firm with no EU presence is covered from the moment its first unit ships into the single market.