Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Board Cybersecurity Reporting Pack — Guide

Board Cybersecurity Reporting Pack

Most security reports to a board list what the team did last quarter and colour each line red, amber or green. The board nods and moves on. Nothing is decided, because nothing was put to it. This pack helps you turn a technical status update into a governance conversation.

Is this for you?

This pack is for you if:

  • you report on security to a board or committee, and it is not your only job;
  • your report is a list of activity, and you are not sure what the board does with it;
  • you gather the figures by hand the week before the meeting.

What a board actually needs

A board needs to know whether the organisation is within the risk it agreed to carry, and what it must decide. Every report in this pack follows four parts, in this order:

PartThe board’s questionWhat you give it
PositionWhere do we stand against the risk appetite we set?One sentence, then the few measures that show it.
DirectionIs it getting better or worse, and why?Movement since the last report, with the cause, not a list of activity.
ExposureWhat could hurt us most, and how likely is it now?The top risks in business terms: which service, what harm, what it would cost.
AskWhat do you need us to decide, note or fund?Each ask stated as a decision, with its options and the recommended one.

Open with a one-sentence answer to “are we within appetite?”. Put technical detail in an appendix, and give each measure’s status in words, never by colour alone.

Start with these three

  1. Board Reporting Narrative Model — the four parts and the ten reporting rules every other document follows.
  2. Board Cybersecurity Report Deck Template — a ten-slide deck built around decisions rather than dashboards.
  3. Board Reporting Data Collection Workbook — one place for every figure, checked and signed off before the deck is built.

Your first cycle

Count back from your next board date, in working days. Adjust to your own calendar.

WhenWhat to doWho
25 days beforeSend the data request.You
18 days beforeFigures back in the workbook.Data owners
15 days beforeCheck and sign off the figures.You, with the risk function
12 days beforeWrite the report and one-page summary.You
9 days beforeSponsor review.Executive sponsor
7 days beforeRehearse with the question bank.You and your sponsor
5 days beforePapers to the board secretary.You
3 days afterRecord decisions and owned actions.Board secretary, with you

The board measures

Eight measures, each answering a question a board asks: risks outside appetite; critical exposure fixed on time; expired or high-risk exceptions; significant incidents and time to contain; critical suppliers assessed; critical services restored in tests; security programme delivery; and board and staff security training. You set the targets.

Everything in the pack

DocumentWhat it doesFormat
Board Reporting Narrative ModelTurns measures into a report that asks for decisionsWord
Board Cybersecurity Report Deck TemplateThe quarterly deck, ready to fill from the workbookPowerPoint
Board Metric Selection CatalogueWhich measures belong at board level, and which do notExcel
Board Reporting Data Collection WorkbookEvery figure for the cycle, from one checked sourceExcel
Board Question Bank & Preparation BriefThe questions a board will ask, including the uncomfortable onesWord
Cyber Risk One-Page Board SummaryThe position on one page, for boards that read no furtherPowerPoint
Board & Executive Reporting CalendarThe cycle scheduled back from each board dateExcel
Board Reporting Effectiveness Self-CheckScores your current report once a year and shows what to changeExcel

Adapting it

  • Small organisation with no board committee: report to the full board or the owners, using the one-page summary as the paper. If you also hold the risk role, ask your sponsor to check the figures.
  • Regulated entity (NIS2, DORA): the duty sits with your management body. Under NIS2 it approves and oversees the security measures and can be held liable; under DORA it sets the risk tolerance and bears ultimate responsibility for ICT risk. Both require its members to be trained, so report training at least once a year.
  • IT run by an outside provider: make the provider a data owner, put the data request in the contract, and report it under critical suppliers. Accountability stays with your board.

Where it maps

  • ISO/IEC 27001:2022 — Clause 9.3, management review.
  • NIST CSF 2.0 — GV.OV-01 and GV.RR-01.
  • NIS2 — Article 20(1) and (2).
  • DORA — Article 5(2) and (4).