The scale of cyber risk is no longer a matter of debate. The question for boards and investors is whether the numbers are informing the decisions they make about cyber leadership, or simply sitting in a report that nobody acts on.
Here are the figures that should be shaping how organisations think about the CISO mandate.
$4.88 million: the average cost of a data breach
This is IBM’s latest figure, and it represents an all-time high. For PE-backed businesses where EBITDA margins directly affect valuation, a single breach can erode a meaningful portion of the value the investment thesis was designed to create. The cost includes detection, containment, lost business and regulatory response, but it does not include the longer-term reputational damage that is harder to quantify.
194 days: the average time to detect a breach
Nearly six and a half months. If a portfolio company is breached on day one of a hold period, the board may not know until month seven. Add a further 292 days on average to contain the breach once detected, and the timeline extends to well over a year. In a three-to-five-year hold period, that is a significant proportion of the investment window consumed by incident response rather than value creation.
78%: the surge in supply chain attacks
Third-party risk is expanding faster than most organisations can track it. As businesses scale through cloud infrastructure, SaaS platforms and outsourced services, every new vendor relationship introduces a potential attack surface. For PE portfolio companies that are being built through acquisition, each bolt-on brings its own vendor contracts, technology dependencies and inherited security posture.
90%: the proportion of incidents caused by human error
The most sophisticated firewall in the world does not protect against a phishing email opened by a senior executive. This statistic reinforces why the CISO mandate needs to extend beyond technology controls into culture, training and organisational behaviour. A CISO who only thinks in terms of systems and tools is missing the largest single source of risk.
73%: the proportion of firms that consider themselves at risk
Nearly three quarters of organisations acknowledge they are exposed, yet many of them still do not have a senior cyber leader in place, or have one whose mandate is unclear. The gap between awareness and action is where the real risk sits.
What these numbers mean for the CISO mandate
Each of these statistics points in the same direction: the CISO mandate cannot be defined in isolation from the business. It needs to be linked to the value chain, the investment thesis and the risk tolerance of the organisation. A CISO who is appointed without that context will be managing abstract risk rather than protecting specific value.
Our whitepaper, Defining the CISO Mandate: How Do You Align Risk & Value, sets out the framework for translating these numbers into a defined leadership remit. It includes a formula for mapping business risk to CISO skill profiles, with investment thesis-specific guidance for buy-and-build, product-led growth, geographic expansion and IPO strategies.
Download the whitepaper

Defining the CISO Mandate Report