Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Board Reporting Data Collection Workbook

Consolidates the inputs required for each reporting cycle so the deck is assembled from a single verified source.

Available soon

Format
Excel
Size
67 KB
Length
10 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Cycle Control
  • Metric Data
  • Deck Feed
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Save a copy of this workbook for each reporting cycle, named for the cycle (for example 'Board data 2026-Q3'). Keep every copy: together they are the record of what the board was told and where each figure came from.
2Cycle Control: enter the cycle name and the board meeting date. The timetable counts each step back from the board date in working days (Monday to Friday) using the offsets from the Board & Executive Reporting Calendar. Enter your public holidays in the Non-working days list so they are skipped. Change an offset only if your calendar differs.
3Lists sheet: check the Measures list. It holds the pack's eight board measures (BM-01 to BM-08). If your board agreed a different selection in the Board Metric Selection Catalogue, replace or add measures there (yellow rows), with their unit and whether a higher value is better.
4Metric Data: delete the EXAMPLE rows, add one row per measure, and name the data owner. Send the data request on the date the timetable gives; the Date due column shows when figures must be back.
5When a figure arrives, enter the value in the measure's unit (a percentage as a number from 0 to 100), last period's value from the previous cycle's copy, the target and the tolerance limit the board agreed, a supporting figure in words, why it moved, the source and an evidence reference you could show an auditor.
6Status compares the value with the target, then with the tolerance limit (the worst value the board accepts before it must act): On target, Below target, within tolerance, Outside tolerance, No target set. The Position measure (BM-01) records two counts instead — top risks above appetite (Value this period) and top risks past their own tolerance limit (Past tolerance) — and its status follows the position rule: Outside tolerance if any top risk is past its own tolerance limit; otherwise Outside appetite, within tolerance if any top risk is above appetite; otherwise Within appetite. A measure with no target should not reach the board (BR-03). Where the board's target is for the year end, enter the level planned for this point in the year and give the year-end aim in the supporting figure.
7Someone other than the data owner checks each figure against its evidence and records their name and the date. The reporter, with the risk function, then signs each figure off by the sign-off date on the timetable (BR-08).
8Clear every Record check that does not say OK. Then read the Deck Feed: when its readiness check says 'Ready — build the deck', write the deck from it. Never change a figure in the deck without changing it here first.
9After the meeting, record the board's decisions and actions (BR-09) in the Board & Executive Reporting Calendar and start the next cycle's copy.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

Rule BR-08: "All figures come from one data collection workbook, checked and signed off before the deck is built." Rule BR-04: "Each measure shows its value, its target, its direction since last time and a status in words — never colour alone."

Direction compares this period's value with last period's using the measure's 'Higher is better': Better, Same, Worse, with last period's value in brackets, for example 'Worse (was 90%)'. It says nothing about whether the change matters; 'Why it moved' does.

The As-at date on Cycle Control holds a fixed EXAMPLE date, so the example statuses read the same on any day: replace with today's date, or =TODAY(). With =TODAY() the timetable and timeliness statuses move on as the cycle runs; type a fixed date again to freeze them for a record.

Tailoring — small organisation: one person may be data owner for most measures. Then the checker must be someone else — a finance or operations manager is often enough — and the timetable can be shortened by changing the offsets. Report quarterly or at each board meeting if less often.

Tailoring — regulated entity (NIS2, DORA): the management body must be kept informed, including of major ICT-related incidents (DORA Art 5(2)(i)), and approves and oversees the measures (NIS2 Art 20(1)). Keep each cycle's signed copy, with its evidence references, for supervisors; report out of cycle within [[5]] working days of a major incident or of any top risk moving outside its tolerance limit, to the chair (a move outside appetite but within tolerance waits for the next report).

Tailoring — IT run by a service provider: the provider will be data owner for several measures. Put the data request dates and the definitions in the service agreement, record the provider's report as the source, and have someone in your organisation check each figure — never let the provider check its own figures.

Cycle Control

Cycle control

The cycle, the board date and the timetable counted back from it in working days. Yellow cells are yours; dates calculate.

SettingValue
CycleQ3 2026EXAMPLE — your cycle name
Board or committee[[e.g. Board, or its Audit & Risk Committee]]
Board meeting date29 Oct 2026EXAMPLE — your board date
As-at date9 Oct 2026EXAMPLE — replace with today's date, or =TODAY()
Reporter[[e.g. Head of Information Security or CISO]]
Executive sponsor[[e.g. Chief Operating Officer or CFO]]
Ready to build the deck? (from the Deck Feed)Not ready

Timetable — counted back from the board date

StepOwnerWorking days from board dateDue dateCompleted onStatus
Data request sent to data ownersReporter-2524 Sep 202624 Sep 2026Done
Data returned in the data collection workbookData owners-185 Oct 20266 Oct 2026Done late
Figures checked and signed off (BR-08)Reporter with risk function-158 Oct 2026Overdue
Draft report and one-page summary writtenReporter-1213 Oct 2026Not yet due
Executive sponsor reviewExecutive sponsor-916 Oct 2026Not yet due
Question bank rehearsalReporter and executive sponsor-720 Oct 2026Not yet due
Papers submitted to the board secretaryReporter-522 Oct 2026Not yet due
Board meetingBoard029 Oct 2026Not yet due
Actions and decisions recorded (BR-09)Board secretary with reporter33 Nov 2026Not yet due

Working days are Monday to Friday, less the non-working days below. Negative numbers are before the board meeting. EXAMPLE completion dates show a cycle under way.

Non-working days in the cycle (public holidays)

DateHoliday

[[e.g. a public holiday that falls in the cycle]]

Metric Data

One row per measure for this cycle. Yellow columns are yours; values are in the measure's unit. The 8 EXAMPLE rows are one quarter's figures — delete them first.

ExampleMetric IDMeasure (calc)Unit (calc)Higher is better (calc)Data ownerDate due (calc)Date receivedValue this periodValue last periodTargetTolerance limitPast tolerance (Position measure only)Direction (calc)Status (calc)Supporting figure, in wordsWhy it movedSourceEvidence referenceChecked byChecked onSigned off bySigned off onTimeliness (calc)Record check (calc)
EXAMPLEBM-01Risks outside appetiteTop risks above appetite (count); past tolerance counted beside itNoHead of Risk5 Oct 20262 Oct 20262300Better (was 3)Outside appetite, within tolerance2 of 12 top risks above appetite; 0 past toleranceOne risk returned within appetite after the warehouse network was separated from the office network.Risk register, quarterly review 2026-09-30Risk register export 2026-09-30Information Security Manager7 Oct 2026Head of Information Security8 Oct 2026On timeOK
EXAMPLEBM-02Critical exposure fixed on time% fixed and verified on time (0–100)YesIT Operations Manager5 Oct 20265 Oct 202681909580Worse (was 90%)Below target, within tolerance81% within 14 calendar days (target 95%)The ordering platform team lost two engineers, so fixes on that platform queued.Vulnerability remediation trackerTracker export 2026-09-30Head of Risk7 Oct 2026Head of Information Security8 Oct 2026On timeOK
EXAMPLEBM-03Expired or high-risk exceptionsExceptions that expired unresolved (count)NoInformation Security Manager5 Oct 20261 Oct 20261001Worse (was 0)Below target, within tolerance4 open; 1 expiredOne exception expired in July before its renewal was decided; the risk owner closed it in August.Security exception registerRegister export 2026-09-30Head of Risk7 Oct 2026Head of Information Security8 Oct 2026On timeOK
EXAMPLEBM-04Significant incidents and time to containHours to contain the slowest significant incident (0 if none)NoInformation Security Manager5 Oct 20261 Oct 2026662448Same (was 6)On target1 significant incident (1 last quarter); contained in 6 hoursRansomware on 14 office PCs at one warehouse on 12 Aug 2026 was contained in 6 hours; ordering and dispatch were not affected.Incident logIncident closure report, 12 Aug 2026Head of Risk7 Oct 2026Head of Information Security8 Oct 2026On timeOK
EXAMPLEBM-05Critical suppliers assessed% of critical suppliers assessed (0–100)YesProcurement Manager5 Oct 20266 Oct 202664436450Better (was 43%)On target9 of 14 critical suppliers (plan: 9 by Q3, 14 of 14 by year end)Three logistics suppliers assessed this quarter, as planned; five remain for Q4.Third-party registerSupplier assessment log 2026-09-30Head of Risk7 Oct 2026Head of Information Security8 Oct 2026LateOK
EXAMPLEBM-06Critical services restored in tests% of critical services restored in tests (0–100)YesIT Operations Manager5 Oct 20265 Oct 202650255025Better (was 25%)On target2 of 4 critical services (plan: 2 by Q3, 4 of 4 each year)Warehouse management was restored in 5 hours in the August test, within its 8-hour objective.Recovery test recordsRecovery test report 2026-08-27Head of Risk8 Oct 2026Head of Information Security8 Oct 2026On timeOK
EXAMPLEBM-07Security programme delivery% of milestones due that were delivered on time (0–100)YesSecurity Programme Manager5 Oct 20265 Oct 2026787810075Same (was 78%)Below target, within tolerance7 of 9 milestones (target 9 of 9 by quarter end)Two milestones on the ordering platform slipped when its team lost two engineers.Security programme planProgramme report 2026-09-30Head of Risk8 Oct 2026On timeSign off the figure (BR-08)
EXAMPLEBM-08Board and staff security training% of staff trained in the last 12 months (0–100)YesHR Learning Lead5 Oct 20262 Oct 202692889585Better (was 88%)Below target, within toleranceBoard 6 of 7; staff 92% (target: all board; staff 95%)Warehouse shift staff completed the short course on the floor terminals.Training recordsLearning system report 2026-09-30Head of Risk7 Oct 2026Head of Information Security8 Oct 2026On timeOK

Deck Feed

Deck feed — the figures in the order of the report

Position, Direction, Exposure, Ask (BR-01), pulled from Metric Data. Build the Board Cybersecurity Report Deck Template and the Cyber Risk One-Page Board Summary from this sheet only, once the readiness check says so.

Before you build the deck

CheckResultStatusWhat to do
Measures in the Measures list with no row on Metric Data0Meets the checkEvery measure the board agreed gets a row, every cycle.
Values not yet entered0Meets the checkChase the data owner; the timetable shows the date.
Measures with no target0Meets the checkBR-03: no measure reaches the board without one.
Figures not checked0Meets the checkSomeone other than the data owner checks each figure against its evidence.
Figures not signed off1Action neededBR-08: sign-off is due on the timetable's sign-off date.
Rows with a record check to resolve1Action neededAny row on Metric Data whose Record check does not say OK.
Ready to build the deck?2Not ready2 check(s) above need action before the deck is built.

1 Position — Where do we stand against the risk appetite the board set?

Position statement, one sentence (BR-02)We are outside our cyber risk appetite on 2 of 12 top risks, both within tolerance, and we expect to be back within appetite by the end of Q4 2026 if the board approves today's decision.

EXAMPLE — write yours from the figures below once they are signed off. Use one of the position words: Within appetite; Outside appetite, within tolerance; Outside tolerance.

Metric IDMeasureAbove appetiteTargetPast toleranceDirectionPositionSupporting figure
BM-01Risks outside appetite200Better (was 3)Outside appetite, within tolerance2 of 12 top risks above appetite; 0 past tolerance

2 Direction — Is it getting better or worse, and why?

Metric IDMeasureLast periodThis periodTargetDirectionStatusWhy it moved
BM-01Risks outside appetite320Better (was 3)Outside appetite, within toleranceOne risk returned within appetite after the warehouse network was separated from the office network.
BM-02Critical exposure fixed on time908195Worse (was 90%)Below target, within toleranceThe ordering platform team lost two engineers, so fixes on that platform queued.
BM-03Expired or high-risk exceptions010Worse (was 0)Below target, within toleranceOne exception expired in July before its renewal was decided; the risk owner closed it in August.
BM-04Significant incidents and time to contain6624Same (was 6)On targetRansomware on 14 office PCs at one warehouse on 12 Aug 2026 was contained in 6 hours; ordering and dispatch were not affected.
BM-05Critical suppliers assessed436464Better (was 43%)On targetThree logistics suppliers assessed this quarter, as planned; five remain for Q4.
BM-06Critical services restored in tests255050Better (was 25%)On targetWarehouse management was restored in 5 hours in the August test, within its 8-hour objective.
BM-07Security programme delivery7878100Same (was 78%)Below target, within toleranceTwo milestones on the ordering platform slipped when its team lost two engineers.
BM-08Board and staff security training889295Better (was 88%)Below target, within toleranceWarehouse shift staff completed the short course on the floor terminals.

Every measure in the Measures list, in its order. Direction and status are in words (BR-04); explain the movement, not the activity.

3 Exposure — What could hurt us most, and how likely is it now?

Metric IDMeasureThis periodTargetToleranceDirectionStatusSupporting figure
BM-02Critical exposure fixed on time819580Worse (was 90%)Below target, within tolerance81% within 14 calendar days (target 95%)
BM-03Expired or high-risk exceptions101Worse (was 0)Below target, within tolerance4 open; 1 expired
BM-04Significant incidents and time to contain62448Same (was 6)On target1 significant incident (1 last quarter); contained in 6 hours
BM-05Critical suppliers assessed646450Better (was 43%)On target9 of 14 critical suppliers (plan: 9 by Q3, 14 of 14 by year end)
BM-06Critical services restored in tests505025Better (was 25%)On target2 of 4 critical services (plan: 2 by Q3, 4 of 4 each year)

Pick the measures for this part in the yellow Metric ID cells. The top risks themselves come from the risk register, described by service, harm and cost (BR-05).

4 Ask — What do you need the board to decide, note or fund?

EXAMPLE — Ask 1

FieldAnswer
Decision asked forApprove €180,000 to rebuild the ordering platform's recovery so it can be restored within 24 hours?
OptionsA: approve now, done by 15 Dec 2026. B: approve half now for backup isolation only, and the rest in the next budget. C: do not approve; accept the risk.
Recommended option and whyA. It brings the ransomware risk back within appetite this year and is about 15% of one week's lost orders.
Cost€180,000 one-off, plus about €20,000 a year to run.
Risk of not decidingThe ransomware risk stays outside appetite into 2027. A 2-day outage would cost about €1.2m per week of orders lost, plus contract penalties.
Decision needed byThis meeting, so work starts before the peak season in November.

Ask 2

FieldAnswer
Decision asked for[[The decision the board is asked to take]]
Options[[Options, with what each costs and achieves]]
Recommended option and why[[Recommended option and why]]
Cost[[Cost, one-off and yearly]]
Risk of not deciding[[What happens if the board does not decide]]
Decision needed by[[Date or meeting]]

Add an ask block for each further decision. Amounts in the examples are in euros (€); use your own currency. BR-06: Every ask is a decision with options, a recommendation, cost and the risk of not deciding.

Lists

MeasureIDMeasureNameMeasureUnitHigherIsBetterReportPartMeasureQuestionYesNo
BM-01Risks outside appetiteTop risks above appetite (count); past tolerance counted beside itNoPositionAre we within the risk appetite we set?Yes
BM-02Critical exposure fixed on time% fixed and verified on time (0–100)YesExposureAre the weaknesses attackers use being closed fast enough?No
BM-03Expired or high-risk exceptionsExceptions that expired unresolved (count)NoExposureWhere have we knowingly accepted risk, and is it still under control?
BM-04Significant incidents and time to containHours to contain the slowest significant incident (0 if none)NoExposureHave we been hurt, and how quickly did we recover?
BM-05Critical suppliers assessed% of critical suppliers assessed (0–100)YesExposureAre the suppliers we depend on held to our standard?
BM-06Critical services restored in tests% of critical services restored in tests (0–100)YesExposureCould we recover our most important services, and have we proved it?
BM-07Security programme delivery% of milestones due that were delivered on time (0–100)YesDirectionIs the plan the board funded being delivered?
BM-08Board and staff security training% of staff trained in the last 12 months (0–100)YesDirectionDo we, and our people, know enough to judge and act on cyber risk?

Columns A to F are the Measures list: the pack's board measures from the Board Metric Selection Catalogue. Yellow rows: add your own measures, or overwrite a row to replace one.

Definitions

Definitions

TermMeaning in this workbook
CycleOne round of board reporting, from the data request to the actions recorded after the meeting. The pack assumes quarterly board reporting.
Board dateThe date of the board or committee meeting the report is for. Day 0 of the timetable.
Working dayMonday to Friday, less the dates in the Non-working days list. The timetable counts in working days, not calendar days.
Data ownerThe person, by role, who supplies a measure's figure and its evidence — [[e.g. IT operations, risk, procurement, HR]].
Value this periodThe measure's figure at the end of the period being reported, in the unit on its row. Percentages are entered as numbers from 0 to 100.
Value last periodThe same measure's value in the previous cycle's copy of this workbook, as it was signed off then.
TargetThe level the board aims for.
Tolerance limitThe worst value the board accepts before it must act, not just be told. Under DORA the management body sets the ICT risk tolerance (Art 5(2)). Not used for the Position measure (BM-01), whose top risks each carry their own tolerance limit in the risk register.
Past toleranceFor the Position measure (BM-01) only: the number of top risks assessed past their own tolerance limit. With Value this period (top risks above appetite) it sets the position: Outside tolerance if any top risk is past its own tolerance limit; otherwise Outside appetite, within tolerance if any top risk is above appetite; otherwise Within appetite.
DirectionBetter, Same, Worse: this period's value against last period's, read with 'Higher is better', with last period's value in brackets. 'No previous value' when there is none.
Status — On targetAt or better than its target.
Status — Below target, within toleranceShort of its target but inside the tolerance the board set; a plan and date are given.
Status — Outside toleranceBeyond the limit at which the board said it must act, not just be told; an ask follows (BR-06).
Status — No target setReported without a target: it should not reach the board until one is set (BR-03).
Position — Within appetiteEvery top risk is assessed at or below the level of risk the board has said it is willing to accept. Used as the status of the Position measure (BM-01) and in the position statement (BR-02).
Position — Outside appetite, within toleranceAt least one top risk is above appetite but below the tolerance limit, with a plan and a date to bring it back. Used as the status of the Position measure (BM-01) and in the position statement (BR-02).
Position — Outside toleranceAt least one risk is above the tolerance limit: the point at which the board said it must act, not just be told. Used as the status of the Position measure (BM-01) and in the position statement (BR-02).
Awaiting valueStatus before this period's value is entered.
Supporting figureThe value in words the board recognises, such as '2 of 12 top risks'.
Evidence referenceWhere the figure can be checked: a report, export or record, with its date.
Checked bySomeone other than the data owner who compared the figure with its evidence.
Signed offThe reporter's confirmation, with the risk function, that the figure may go to the board (BR-08).
TimelinessOn time or Late: when the figure arrived against the date due. Overdue: not yet arrived and past due.
Deck feedThe figures in the order of the report (BR-01), for building the Board Cybersecurity Report Deck Template and the Cyber Risk One-Page Board Summary.
BR-nn, BM-nnReporting rules and board measures defined in the Board Reporting Narrative Model; the measures are explained in the Board Metric Selection Catalogue.
(calc)A column or cell the workbook calculates. Do not type or paste over it.
EXAMPLE rowA worked example showing one quarter for a fictional distributor. Delete before use.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 9.1 — Monitoring, measurement, analysis and evaluationMetric Data: what is measured, when, by whom, and the evidence; Direction and Status
ISO/IEC 27001:2022Clause 9.3 — Management reviewDeck Feed: the figures as an input to management review by the board
NIST CSF 2.0GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed”Metric Data and Deck Feed: performance reviewed against target and tolerance
DORA — Regulation (EU) 2022/2554Article 5(2)(i) — reporting channels that keep the management body informed, including of at least major ICT-related incidents and their impactCycle Control and Deck Feed: a regular reporting channel to the management body, incidents included (BM-04)
NIS2 — Directive (EU) 2022/2555Article 20(1) — management bodies approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringementsThe signed-off figures through which the management body oversees implementation

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA)