I'm trying to get a better handle on how financial institutions and VC analysts assess the true impact of cybersecurity investments. Beyond ticking boxes or hitting compliance targets, how do you measure the tangible reduction in risk or the quantifiable boost to business continuity that these investments actually deliver, especially when pitching to stakeholders who aren't security experts?