The CEO Security Decision Framework

The CEO Security Decision Framework

Five questions for evaluating any security investment against actual business exposure.

A CIO once spent $90,000 on a security tool that was never used. Not because anyone was careless, but because there was no way to test the decision before it was made.

Security is proposed in threats, controls and vendors. It is decided in dollars. These five questions translate between the two.

What you get

  • Five questions that work on any security proposal
  • What a good answer to each sounds like, and what to push back on
  • A way to evaluate spend in under ten minutes, without a technical background

It also works backwards. Run it across the security spend you already have.

Get your copy

This field is required.
This field is required.
This field is required.
This field is required.

We collect your name, work email, company and (optionally) phone so we can send you this resource and respond if you have questions. We handle personal information in accordance with the Privacy Act 1988 and the Australian Privacy Principles. See our privacy policy. We will only send you further material if you tick the box above, and you can unsubscribe at any time.

Prepared by Ilya Polyakov, principal of IronGate IT Consulting. Formerly Chief Security Architect at NSW Government, Executive Manager of Cyber Architecture at CBA, and security advisory at APRA. General information only, current as at August 2026, and not legal advice.