Most business cases for cyber exercising fail for the same reason: they lead with a frightening number that the finance director can disprove in a single search.
If you are about to tell your board that the average cyber breach costs millions, stop. In the UK, for most organisations, it does not, and the person you are trying to persuade may well know it.
This guide builds the case on ground that holds.
First, concede the point that undermines you
The Cyber Security Breaches Survey 2025/2026 asked UK organisations what their most disruptive breach actually cost them. The median answer was £0. For most businesses the cost fell between £0 and £200. Even the median cost of non-phishing cyber crime was £250.
If your business case rests on expected losses, it collapses here. A rational finance director looking at those numbers will conclude that the expected value of a breach is close to nothing and that spending several thousand pounds to avoid it is poor arithmetic.
They would be right about the median and wrong about the risk, and understanding why is the whole argument.
The real argument: this is a tail risk, not an average
Look at the same survey's upper percentiles. For the top 5% of cases, the perceived cost of the most disruptive breach reaches £4,000 for businesses overall and £10,000 for medium and large businesses. For non-phishing cyber crime, the top 10% ranges from £5,000 to £7,500.
The survey itself carries an important caveat: genuinely catastrophic incidents are rare, highly variable and difficult to capture reliably in a survey of this size, so extreme costs are not fully reflected in the headline figures. The numbers above are the visible part of the distribution, not its edge.
This is the shape of the risk. Most incidents cost nothing. A small number end an organisation's year, and occasionally the organisation.
That changes the argument entirely, because you are no longer making an efficiency case. You are making an insurance case, and boards already understand insurance. Nobody asks for the ROI on buildings cover by dividing the premium by the probability of fire. They ask whether the organisation could absorb the loss if it happened.
So the question to put to the board is not "what does a breach cost on average?" It is:
> If our core operating system were unavailable for five working days, and we were simultaneously managing customer notification and a regulator, what would that cost us, and could we absorb it?
That number is specific to you, your board can estimate it, and it is usually uncomfortable.
The second argument: you are buying decision speed
Here is what an exercise actually improves. Not whether you get attacked. Not whether malware gets in. It improves how quickly and how well people decide once something has gone wrong.
That matters because the gap between a contained incident and a crisis is almost always measured in hours of hesitation rather than in technical capability. The technical team usually knows what to do. What they cannot get is a decision: whether to take the platform down, who speaks to customers, whether this is notifiable, who authorises unplanned spend at 11pm on a Friday.
The UK data shows why this goes unpractised. Only 25% of businesses have a formal incident response plan. Only 39% have assigned incident roles to named individuals, 34% have written guidance on who to notify, and 32% have guidance on when to report externally.
So for most organisations, the first time anyone works out who decides is during the incident. Exercising moves that discovery to a Tuesday afternoon when it costs nothing.
Frame the spend accordingly: you are not buying protection, you are buying rehearsed decisions, and the saving is the hours you do not lose to working out who is in charge.
The third argument: someone is going to ask you for evidence
This is frequently the argument that actually releases budget, because it converts a discretionary spend into a cost of doing business.
Governance expectation. The Cyber Governance Code of Practice, published by DSIT and the NCSC in April 2025, sets out five principles for boards, one of which is incident planning and response. It expects response and recovery plans to be tested at least annually, with defined responsibilities for regulatory obligations and communications, and a post-incident review process. It is voluntary, but voluntary codes have a way of becoming the standard a board is measured against after something goes wrong.
Procurement. Enterprise and public sector buyers increasingly ask whether response arrangements have been tested. "We have a plan" is a weaker answer than "we tested it in March and here is the report", and in competitive procurement the difference is worth more than the exercise costs.
Insurance. Cyber insurers ask about incident response preparedness at renewal. Documented testing is a better position than an untested plan, both for terms and for the conversation that follows a claim.
Sector regulation. If you fall under DORA, NIS2 or the NCSC's Cyber Assessment Framework, testing is not a nice-to-have. Even outside those regimes, UK GDPR Article 32 requires a process for regularly testing and evaluating the effectiveness of your security measures, and an exercise is one of the few things that visibly satisfies it.
Taken together: you are likely to be asked to prove this at some point. Doing it deliberately, once a year, is cheaper than doing it urgently because a customer's due diligence questionnaire landed.
Building the paper
Keep it to one page. Boards reject long cyber papers for the same reason they reject long papers about anything.
Structure
The ask. A specific number and what it buys. Vagueness reads as uncertainty.
The exposure. Your own answer to the five-day question above, in your own numbers. Not an industry statistic.
What we do not know. Three or four specific unanswered questions: who authorises taking system X offline, who speaks to customers in the first hour, whether we could reconstruct our decisions for a regulator. These are more persuasive than any statistic because the board cannot answer them either.
What changes. The concrete outputs: a tested plan, named decision-makers, a timestamped record, a prioritised action list with owners.
The external driver. Whichever of governance, procurement, insurance or regulation actually applies to you. One is enough; four looks like padding.
The alternative. Be honest that free options exist. The NCSC's Exercise in a Box is genuinely good and costs nothing. Saying so makes everything else in the paper more credible, and lets you explain precisely what the paid version adds: independence, unscripted pressure, and evidence a third party will accept.
What to leave out
Industry breach-cost averages from vendor reports. Anything with "cyber attacks every 39 seconds" in it. Comparisons to organisations nothing like yours. Every one of these invites the reader to argue with the number instead of engaging with the risk.
Answering the four objections you will get
"We have never had an incident." True of most organisations, and it says nothing about the future. It is also worth checking gently: 43% of UK businesses identified a breach or attack last year, and organisations without monitoring are less likely to know. Not having noticed is not the same as not having had one.
"We have insurance." Insurance pays some costs afterwards. It does not make the decision about whether to take the platform offline, and it does not talk to your customers. Insurers increasingly ask what testing you have done, so this objection often argues for the spend rather than against it.
"IT handles this." IT handles the technical response. The decisions that determine how bad it gets are commercial, legal and reputational. If the exercise is IT-only, the part most likely to fail goes untested.
"We are too small to be a target." Most attacks are opportunistic rather than targeted, and smaller organisations are attractive precisely because controls are thinner. The survey also found small businesses moving backwards this year: risk assessments fell from 48% to 41%, formal policies from 59% to 52%, and business continuity plans covering cyber from 53% to 44%.
If the answer is no
Ask for something smaller rather than accepting a refusal.
A ninety-minute internal discussion costs nothing but time. The NCSC's Exercise in a Box is free. A short drill testing one decision, who authorises taking the core system offline, will produce a finding you can take back to the board, and a specific finding is a far better business case than a general argument.
That is usually the fastest route to a yes: stop arguing that exercising is valuable in principle and demonstrate one concrete thing your organisation cannot currently answer.