[an error occurred while processing this directive]

How to Actually Talk to Your Board About cyber security (When You Have No Budget)

[an error occurred while processing this directive]

You need to talk to your board about cyber security. But every time you try, one of three things happens:

TL;DR
  • Libraries face ransomware attacks with 3+ month downtime and recovery costs of $7M+ (British Library). Boards must understand cyber security is a strategic priority, not an IT overhead.
  • Most library IT budgets (7-10% of operations) are insufficient for modern threats. Budget 12-15% minimum, with separate allocation for security hardening and incident recovery.
  • Key board decisions: multi-factor authentication everywhere, regular backup testing, vendor security audits, and ransomware response planning with insurance coverage review.
  • Attack patterns show libraries are high-value targets: patron data, operational criticality, and historically weak security budgets. Delays in funding create exploitable vulnerabilities.
  • You can fix this. This article gives you the exact language, visuals, and objection-handling scripts that get boards to approve funding. Use them as-is.
  1. They glaze over when you mention "multi-factor authentication"
  2. They panic and think you're saying the library\'s been hacked
  3. They ask "Why didn't this come up last year?" and shut down the conversation

Here\'s the problem: You\'re speaking IT, and they\'re hearing budget threat. That\'s not your fault. It\'s a communication gap. And it\'s fixable.

Let me give you the script that actually works. The one that gets cyber security funding approved without causing board panic or political fallout. Use these slides, these words, and these responses. You have permission to copy, modify, and present all of it.

The Three-Slide Presentation That Gets Budget Approval

Your board doesn\'t have time for 30 slides. They have 15 minutes, maybe 20. Here\'s what you show them:

Slide 1: "This Is Happening to Libraries Like Ours"

Title: Library Ransomware: The New Reality

Content:

The line that matters:

"These aren\'t theoretical risks. These are peer institutions that got hit in the last 24 months. And they all thought "it won\'t happen to us" until it did."

Visual: Show logos/photos of British Library, Toronto Public Library, Seattle Public Library. Make it real.

Why this works: Boards respond to peer comparisons. "This happened to libraries like ours" is more compelling than "cyber security experts say..."

Slide 2: "Here's What It Would Cost Us"

Title: The Math: Prevention vs. Recovery

Content (create a simple table):

Scenario Prevention Cost Recovery Cost (if attacked)
Do nothing $0 $250K-$1M (based on Seattle)
Basic security (our proposal) $25K-$50K/year $50K-$100K (much faster recovery)
Comprehensive security $100K+/year $10K-$50K (minimal disruption)

The line that matters:

"Seattle Public Library spent $1 million recovering from ransomware. For a fraction of that cost, we can reduce our risk by 90% and speed recovery if something does happen."

Add this detail:

Source: British Library Cyber Incident Review, March 2024.

Why this works: Boards understand ROI. "Spend $25K to avoid spending $1M" is a simple business case.

Slide 3: "Our Recommended Three-Tier Approach"

Title: Phased Investment: Year 1, Year 2, Year 3

Year 1: Foundation (Budget Request: $20K-$30K)

What this gets us:

Year 2: Remediation (Budget Based on Audit: Est. $30K-$50K)

Year 3: Ongoing Maintenance (Budget: $20K-$30K/year)

The line that matters:

"We\'re not asking for $100K upfront. We\'re asking for $20K-$30K in Year 1 to establish a foundation, then adjusting based on what the audit tells us."

Why this works: Phased budgets feel manageable. You\'re not dropping a huge unfunded mandate. You\'re building incrementally.


The Exact Language That Works (Copy-Paste This)

Here's what you actually say when presenting:

Opening (30 seconds):

"I want to talk about cyber security. Not because we\'ve been attacked. We haven\'t. But because in the last two years, three major libraries were hit with ransomware attacks that cost them millions of dollars and months of downtime. I want to make sure we're not next."

Why this works: You\'re establishing urgency without panic. "We haven\'t been attacked" prevents immediate board freakout. "I want to make sure we're not next" establishes proactive leadership.

The Ask (60 seconds):

"Based on what happened to Seattle, Toronto, and the British Library, I'm recommending a three-tier approach starting with a $25K investment in Year 1 for cyber insurance and a security audit. This is like buying fire insurance. We hope we never need it, but if we do, it covers most of the cost."

"For context: Seattle spent $1 million recovering from a ransomware attack. Our Year 1 ask is 2.5% of that cost. It\'s not a question of if ransomware attacks continue. They\'re accelerating. It\'s a question of whether we\'re prepared when it happens."

Why this works: You're framing it as insurance (concept boards understand) and showing clear ROI (2.5% of recovery cost).

Handling Objections:

Board Member: "Why didn't this come up last year?"

Your Response:

"Great question. Ransomware attacks on libraries increased dramatically in 2023-2024. British Library and Toronto were both attacked in October 2023. Seattle was hit in May 2024. This went from "low probability threat" to "peer libraries are being hit regularly." We're responding to a rapidly changing threat landscape."

Board Member: "Can't IT just handle this?"

Your Response:

"Our IT staff are excellent at keeping systems running, but cyber security requires specialized expertise. British Library had professional IT staff. They still needed outside forensic investigators and consultants. The $1M Seattle spent was mostly on specialized consultants. We need those experts before we have an incident, not after."

Board Member: "What if we just don't pay the ransom if we get attacked?"

Your Response:

"British Library, Toronto, and Seattle all refused to pay. Good for them. But their recovery still took 3-4 months and cost $1-7M. Not paying the ransom doesn't make recovery free or fast. Our goal is to prevent attacks and minimize recovery time if one happens."

Board Member: "Is this really a priority compared to [books/programs/staff]?"

Your Response:

"It\'s not either/or. It\'s about protecting everything else we do. If we get hit like Toronto did, we can't check out books, run programs, or provide services for months. Our Year 1 ask is about 1-2% of our annual budget to protect 100% of our operations."


The Budget Breakdown by Library Size

Boards want to know "What do libraries like us spend?" Here's real-world guidance:

Small Library (1-3 branches, <$1M budget):

Year 1 Investment: $5K-$15K

Realistic alternatives if you have $0:

Medium Library (5-25 branches, $5M-$15M budget):

Year 1 Investment: $20K-$50K

Large Library (25+ branches, $15M+ budget):

Year 1 Investment: $50K-$150K

Key point: Scale to your budget. Don\'t let "we can\'t afford $50K" stop you from doing the $5K version. Some protection is infinitely better than zero protection.


The "But We Have No Money" Strategy

Here\'s what you do when your board says "We\'d love to, but there's no budget":

Strategy 1: Reallocate Existing Funds

Script:

"I understand we\'re budget-constrained. Let me propose this: We\'re currently spending $X on [identify low-priority line item]. If we reallocate $20K from that to cyber security in Year 1, we can establish baseline protection. Then we revisit annually."

Examples of possible reallocations:

Strategy 2: Emergency Reserve Funding

Script:

"Our emergency reserves are designed for unexpected crises. A ransomware attack is exactly that kind of crisis. Seattle spent $1M from reserves recovering. Can we allocate $20K proactively from reserves to prevent needing to spend 50x that amount reactively?"

Strategy 3: Grant Funding

Script:

"I\'ll apply for IMLS, state library, or regional foundation grants to fund Year 1 security improvements. In the meantime, I\'ll implement all the free actions (MFA, backup testing, staff training) so we're making progress even without new funding."

Real grants to pursue:

Strategy 4: Multi-Year Gradual Approach

Script:

"If $25K in Year 1 isn\'t feasible, let\'s phase it differently: $10K this year for cyber insurance only. Year 2: Add the security audit. Year 3: Address findings. It\'s not ideal, but it\'s better than zero."


The Follow-Up Memo Template

After your presentation, send this memo to cement your ask:

TO: Library Board of Directors

FROM: [Your Name], Library Director

DATE: [Today's Date]

RE: cyber security Investment Proposal – Follow-Up

Thank you for the opportunity to present on library cyber security risks today. As discussed, I'm recommending a phased investment starting with $[X] in [Year] to establish baseline protection.

Key Points from Presentation:

  • Three major libraries (British Library, Toronto Public Library, Seattle Public Library) experienced ransomware attacks in 2023-2024 with recovery costs ranging from $1M-$7M
  • Library of Congress survived an attack attempt because they had multi-factor authentication enabled
  • Our proposal: $[X] investment in Year 1 for cyber insurance and security audit (2-3% of typical recovery costs)

Requested Action:
Approve $[X] budget allocation for FY[Year] cyber security program, to include:

  1. Cyber insurance: $[X]
  2. Security audit: $[X]
  3. Implementation of free/low-cost security measures (MFA, backup testing, staff training)

Next Steps if Approved:

  • Secure cyber insurance quotes (3-4 vendors)
  • Solicit security audit proposals (state consortium, regional IT firms)
  • Implement MFA across all library systems within 60 days
  • Brief staff and create patron-facing communications

Alternative if Budget Not Available:
I will pursue grant funding and implement all free security measures immediately. Without cyber insurance, the library assumes 100% financial risk for a potential $1M+ breach recovery.

I'm happy to answer questions or provide additional information.

Respectfully,
[Your Name]

Why this works: You've documented your recommendation. If the board says no and you get breached later, you have evidence you raised the issue and were denied resources.


The Nuclear Option: When Your Board Won't Act

If your board refuses to fund cyber security despite your best efforts:

Document everything.

Send a formal memo stating:

Copy this memo to:

Why this matters: If you get breached and sued, you need evidence you tried to prevent this and were denied resources. This protects you personally.

Then do everything free:

You can\'t eliminate risk with zero budget, but you can reduce it significantly. And you\'ve documented that you tried to do more.


Sample Board Resolution

If your board approves funding, pass a formal resolution:

RESOLUTION 2026-[X]

Library cyber security Program Authorization

WHEREAS, ransomware attacks on libraries have increased significantly, with major incidents at Seattle Public Library ($1M recovery cost), British Library (£7M recovery cost), and Toronto Public Library (4 months offline);

WHEREAS, the Library Director has identified cyber security risks and recommended mitigation measures;

WHEREAS, cyber insurance and security audits represent prudent risk management;

NOW, THEREFORE, BE IT RESOLVED that the [Library Name] Board of Directors authorizes expenditure of $[X] for FY[Year] to establish a library cyber security program including:

  1. Cyber insurance coverage
  2. Professional security audit
  3. Implementation of security measures as identified by audit
  4. Staff cyber security training

BE IT FURTHER RESOLVED that the Library Director shall report quarterly to the Board on cyber security status and any incidents.

Adopted this [Date] day of [Month], [Year].

Why this matters: Formal resolutions show you're taking this seriously. It also creates accountability for ongoing oversight.


What Success Looks Like

If you execute this plan successfully, here\'s what you\'ll have in 12 months:

And most importantly: You\'ll sleep better knowing you're prepared.


Further Resources:


Next Steps: Execute This Week

Don't wait for the next budget cycle. Do this now:

  1. Tomorrow: Copy the three slides above. Fill in your library's numbers. Adjust the language to match your voice.
  2. Next 3 days: Request a 15-minute slot on the next board agenda. Say "I need to brief you on a risk I've identified."
  3. One week: Present. Use the exact language from this article. Answer objections using the scripts provided.
  4. After presentation: Send the follow-up memo. Document everything.
  5. If approved: Execute the three-year plan starting immediately.
  6. If denied: Document the denial. Implement everything free. Protect yourself.

You know your board. You know what will move them. Use this playbook to speak their language. The funding is available if you ask in a way they can understand.

You have permission to use every template, script, and resolution in this article as-is. Modify them. Use them in your board packet. Share them with peer directors. This isn\'t proprietary. It\'s library advocacy.

Need help preparing your board presentation? Get in touch. Or just execute the plan above. You've got this.

Filed under: Library Management, cyber security, Board Relations, Budgeting

Want updates (or backup)?

Get new posts by email, or book a free 30-minute call if you're facing a contract, AI policy, or vendor decision.

Get the newsletter Get help
[an error occurred while processing this directive]