Cybersecurity leaders are under pressure to explain which risks matter, which investments reduce loss and which exposures the business can accept.