In short
- Directors govern; they do not operate. The update should support oversight decisions, not describe technical activity.
- Four questions carry the whole report: what could materially hurt us, what are we doing, what are we obliged to do, what do you need from us.
- Comparability between meetings matters more than precision within one meeting.
- Every update should end with an explicit ask, even if the ask is only to note the residual risk being accepted.
Cybersecurity has moved from an IT topic to a board topic in most organizations, and the reporting has not always moved with it. A common pattern: a deck of technical metrics, patch counts, blocked emails, alert volumes, training completion rates, presented to directors who have no way to tell from any of it whether the organization is in good shape.
The metrics are not wrong. They are answers to operational questions being presented to a governance audience.
The four questions a board is actually asking
Whatever format you use, an update that answers these four questions will land.
1. What could materially hurt this organization?
Name the small number of scenarios that would genuinely disrupt operations, revenue or obligations, described in terms of consequence, not attack technique. Three to five is usually right. If the list runs to twenty, the prioritization work has not been done yet.
2. What are we doing about it?
Progress against a plan the board has already seen, with the same structure each time. Directors should be able to compare this meeting to the last one without re-learning the format. Where something has slipped, say so and say why; a report that never shows a delay stops being believed.
3. What are we obliged to do?
The regulatory, contractual and customer obligations that apply, and the organization’s current position against each. This is where directors’ own exposure sits, and it is the section most often missing.
4. What do you need from us?
An explicit ask: a decision, a funding approval, an acceptance of residual risk, or a note that no action is required this period. An update with no ask trains directors to treat the item as information rather than governance.
What to leave out
- Tool names and vendor branding, unless a decision about them is on the agenda.
- Raw alert, incident or ticket volumes without a trend and an interpretation.
- Threat-landscape commentary that is not specific to this organization.
- Maturity scores presented without explaining what the scale means or who assigned it.
- Anything the board cannot act on, unless it is legally required to be reported.
Make it comparable
The single most valuable property of board reporting is comparability over time. Use the same risk categories, the same rating scale and the same structure at every meeting. Directors build their judgment from the change between periods, and a format that shifts each quarter destroys that.
This is also why the underlying assessment should be anchored to a stable framework. Measuring against something published and durable makes movement meaningful rather than a function of who did the assessment.
Who should present it
Someone who can answer follow-up questions with authority and can say "we accepted that risk, here is why" without deferring. Reporting delivered by a person who cannot make or explain the decisions behind it undermines confidence, however good the material is.
In organizations without a full-time CISO, that is precisely the role a vCISO fills: not producing the slides, but owning the position they describe.
Sources
- NIST Cybersecurity Framework 2.0 , National Institute of Standards and Technology
Related service: Cyber Risk Management
One register of the risks that could genuinely disrupt the business, rated consistently, owned by name, and reviewed on a schedule leadership can rely on.