Board Cybersecurity Reporting Pack — Guide
- Version 1.0
- Updated
- Next review
Board Cybersecurity Reporting Pack
Most security reports to a board list what the team did last quarter and colour each line red, amber or green. The board nods and moves on. Nothing is decided, because nothing was put to it. This pack helps you turn a technical status update into a governance conversation.
Is this for you?
This pack is for you if:
- you report on security to a board or committee, and it is not your only job;
- your report is a list of activity, and you are not sure what the board does with it;
- you gather the figures by hand the week before the meeting.
What a board actually needs
A board needs to know whether the organisation is within the risk it agreed to carry, and what it must decide. Every report in this pack follows four parts, in this order:
| Part | The board’s question | What you give it |
|---|---|---|
| Position | Where do we stand against the risk appetite we set? | One sentence, then the few measures that show it. |
| Direction | Is it getting better or worse, and why? | Movement since the last report, with the cause, not a list of activity. |
| Exposure | What could hurt us most, and how likely is it now? | The top risks in business terms: which service, what harm, what it would cost. |
| Ask | What do you need us to decide, note or fund? | Each ask stated as a decision, with its options and the recommended one. |
Open with a one-sentence answer to “are we within appetite?”. Put technical detail in an appendix, and give each measure’s status in words, never by colour alone.
Start with these three
- Board Reporting Narrative Model — the four parts and the ten reporting rules every other document follows.
- Board Cybersecurity Report Deck Template — a ten-slide deck built around decisions rather than dashboards.
- Board Reporting Data Collection Workbook — one place for every figure, checked and signed off before the deck is built.
Your first cycle
Count back from your next board date, in working days. Adjust to your own calendar.
| When | What to do | Who |
|---|---|---|
| 25 days before | Send the data request. | You |
| 18 days before | Figures back in the workbook. | Data owners |
| 15 days before | Check and sign off the figures. | You, with the risk function |
| 12 days before | Write the report and one-page summary. | You |
| 9 days before | Sponsor review. | Executive sponsor |
| 7 days before | Rehearse with the question bank. | You and your sponsor |
| 5 days before | Papers to the board secretary. | You |
| 3 days after | Record decisions and owned actions. | Board secretary, with you |
The board measures
Eight measures, each answering a question a board asks: risks outside appetite; critical exposure fixed on time; expired or high-risk exceptions; significant incidents and time to contain; critical suppliers assessed; critical services restored in tests; security programme delivery; and board and staff security training. You set the targets.
Everything in the pack
| Document | What it does | Format |
|---|---|---|
| Board Reporting Narrative Model | Turns measures into a report that asks for decisions | Word |
| Board Cybersecurity Report Deck Template | The quarterly deck, ready to fill from the workbook | PowerPoint |
| Board Metric Selection Catalogue | Which measures belong at board level, and which do not | Excel |
| Board Reporting Data Collection Workbook | Every figure for the cycle, from one checked source | Excel |
| Board Question Bank & Preparation Brief | The questions a board will ask, including the uncomfortable ones | Word |
| Cyber Risk One-Page Board Summary | The position on one page, for boards that read no further | PowerPoint |
| Board & Executive Reporting Calendar | The cycle scheduled back from each board date | Excel |
| Board Reporting Effectiveness Self-Check | Scores your current report once a year and shows what to change | Excel |
Adapting it
- Small organisation with no board committee: report to the full board or the owners, using the one-page summary as the paper. If you also hold the risk role, ask your sponsor to check the figures.
- Regulated entity (NIS2, DORA): the duty sits with your management body. Under NIS2 it approves and oversees the security measures and can be held liable; under DORA it sets the risk tolerance and bears ultimate responsibility for ICT risk. Both require its members to be trained, so report training at least once a year.
- IT run by an outside provider: make the provider a data owner, put the data request in the contract, and report it under critical suppliers. Accountability stays with your board.
Where it maps
- ISO/IEC 27001:2022 — Clause 9.3, management review.
- NIST CSF 2.0 — GV.OV-01 and GV.RR-01.
- NIS2 — Article 20(1) and (2).
- DORA — Article 5(2) and (4).