Board Reporting Data Collection Workbook
Consolidates the inputs required for each reporting cycle so the deck is assembled from a single verified source.
Available soon
- Format
- Excel
- Size
- 67 KB
- Length
- 10 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Cycle Control
- Metric Data
- Deck Feed
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Save a copy of this workbook for each reporting cycle, named for the cycle (for example 'Board data 2026-Q3'). Keep every copy: together they are the record of what the board was told and where each figure came from. |
| 2 | Cycle Control: enter the cycle name and the board meeting date. The timetable counts each step back from the board date in working days (Monday to Friday) using the offsets from the Board & Executive Reporting Calendar. Enter your public holidays in the Non-working days list so they are skipped. Change an offset only if your calendar differs. |
| 3 | Lists sheet: check the Measures list. It holds the pack's eight board measures (BM-01 to BM-08). If your board agreed a different selection in the Board Metric Selection Catalogue, replace or add measures there (yellow rows), with their unit and whether a higher value is better. |
| 4 | Metric Data: delete the EXAMPLE rows, add one row per measure, and name the data owner. Send the data request on the date the timetable gives; the Date due column shows when figures must be back. |
| 5 | When a figure arrives, enter the value in the measure's unit (a percentage as a number from 0 to 100), last period's value from the previous cycle's copy, the target and the tolerance limit the board agreed, a supporting figure in words, why it moved, the source and an evidence reference you could show an auditor. |
| 6 | Status compares the value with the target, then with the tolerance limit (the worst value the board accepts before it must act): On target, Below target, within tolerance, Outside tolerance, No target set. The Position measure (BM-01) records two counts instead — top risks above appetite (Value this period) and top risks past their own tolerance limit (Past tolerance) — and its status follows the position rule: Outside tolerance if any top risk is past its own tolerance limit; otherwise Outside appetite, within tolerance if any top risk is above appetite; otherwise Within appetite. A measure with no target should not reach the board (BR-03). Where the board's target is for the year end, enter the level planned for this point in the year and give the year-end aim in the supporting figure. |
| 7 | Someone other than the data owner checks each figure against its evidence and records their name and the date. The reporter, with the risk function, then signs each figure off by the sign-off date on the timetable (BR-08). |
| 8 | Clear every Record check that does not say OK. Then read the Deck Feed: when its readiness check says 'Ready — build the deck', write the deck from it. Never change a figure in the deck without changing it here first. |
| 9 | After the meeting, record the board's decisions and actions (BR-09) in the Board & Executive Reporting Calendar and start the next cycle's copy. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
Rule BR-08: "All figures come from one data collection workbook, checked and signed off before the deck is built." Rule BR-04: "Each measure shows its value, its target, its direction since last time and a status in words — never colour alone."
Direction compares this period's value with last period's using the measure's 'Higher is better': Better, Same, Worse, with last period's value in brackets, for example 'Worse (was 90%)'. It says nothing about whether the change matters; 'Why it moved' does.
The As-at date on Cycle Control holds a fixed EXAMPLE date, so the example statuses read the same on any day: replace with today's date, or =TODAY(). With =TODAY() the timetable and timeliness statuses move on as the cycle runs; type a fixed date again to freeze them for a record.
Tailoring — small organisation: one person may be data owner for most measures. Then the checker must be someone else — a finance or operations manager is often enough — and the timetable can be shortened by changing the offsets. Report quarterly or at each board meeting if less often.
Tailoring — regulated entity (NIS2, DORA): the management body must be kept informed, including of major ICT-related incidents (DORA Art 5(2)(i)), and approves and oversees the measures (NIS2 Art 20(1)). Keep each cycle's signed copy, with its evidence references, for supervisors; report out of cycle within [[5]] working days of a major incident or of any top risk moving outside its tolerance limit, to the chair (a move outside appetite but within tolerance waits for the next report).
Tailoring — IT run by a service provider: the provider will be data owner for several measures. Put the data request dates and the definitions in the service agreement, record the provider's report as the source, and have someone in your organisation check each figure — never let the provider check its own figures.
Cycle Control
Cycle control
The cycle, the board date and the timetable counted back from it in working days. Yellow cells are yours; dates calculate.
| Setting | Value | |
|---|---|---|
| Cycle | Q3 2026 | EXAMPLE — your cycle name |
| Board or committee | [[e.g. Board, or its Audit & Risk Committee]] | |
| Board meeting date | 29 Oct 2026 | EXAMPLE — your board date |
| As-at date | 9 Oct 2026 | EXAMPLE — replace with today's date, or =TODAY() |
| Reporter | [[e.g. Head of Information Security or CISO]] | |
| Executive sponsor | [[e.g. Chief Operating Officer or CFO]] | |
| Ready to build the deck? (from the Deck Feed) | Not ready |
Timetable — counted back from the board date
| Step | Owner | Working days from board date | Due date | Completed on | Status |
|---|---|---|---|---|---|
| Data request sent to data owners | Reporter | -25 | 24 Sep 2026 | 24 Sep 2026 | Done |
| Data returned in the data collection workbook | Data owners | -18 | 5 Oct 2026 | 6 Oct 2026 | Done late |
| Figures checked and signed off (BR-08) | Reporter with risk function | -15 | 8 Oct 2026 | Overdue | |
| Draft report and one-page summary written | Reporter | -12 | 13 Oct 2026 | Not yet due | |
| Executive sponsor review | Executive sponsor | -9 | 16 Oct 2026 | Not yet due | |
| Question bank rehearsal | Reporter and executive sponsor | -7 | 20 Oct 2026 | Not yet due | |
| Papers submitted to the board secretary | Reporter | -5 | 22 Oct 2026 | Not yet due | |
| Board meeting | Board | 0 | 29 Oct 2026 | Not yet due | |
| Actions and decisions recorded (BR-09) | Board secretary with reporter | 3 | 3 Nov 2026 | Not yet due |
Working days are Monday to Friday, less the non-working days below. Negative numbers are before the board meeting. EXAMPLE completion dates show a cycle under way.
Non-working days in the cycle (public holidays)
| Date | Holiday |
|---|
[[e.g. a public holiday that falls in the cycle]]
Metric Data
One row per measure for this cycle. Yellow columns are yours; values are in the measure's unit. The 8 EXAMPLE rows are one quarter's figures — delete them first.
| Example | Metric ID | Measure (calc) | Unit (calc) | Higher is better (calc) | Data owner | Date due (calc) | Date received | Value this period | Value last period | Target | Tolerance limit | Past tolerance (Position measure only) | Direction (calc) | Status (calc) | Supporting figure, in words | Why it moved | Source | Evidence reference | Checked by | Checked on | Signed off by | Signed off on | Timeliness (calc) | Record check (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | BM-01 | Risks outside appetite | Top risks above appetite (count); past tolerance counted beside it | No | Head of Risk | 5 Oct 2026 | 2 Oct 2026 | 2 | 3 | 0 | 0 | Better (was 3) | Outside appetite, within tolerance | 2 of 12 top risks above appetite; 0 past tolerance | One risk returned within appetite after the warehouse network was separated from the office network. | Risk register, quarterly review 2026-09-30 | Risk register export 2026-09-30 | Information Security Manager | 7 Oct 2026 | Head of Information Security | 8 Oct 2026 | On time | OK | |
| EXAMPLE | BM-02 | Critical exposure fixed on time | % fixed and verified on time (0–100) | Yes | IT Operations Manager | 5 Oct 2026 | 5 Oct 2026 | 81 | 90 | 95 | 80 | Worse (was 90%) | Below target, within tolerance | 81% within 14 calendar days (target 95%) | The ordering platform team lost two engineers, so fixes on that platform queued. | Vulnerability remediation tracker | Tracker export 2026-09-30 | Head of Risk | 7 Oct 2026 | Head of Information Security | 8 Oct 2026 | On time | OK | |
| EXAMPLE | BM-03 | Expired or high-risk exceptions | Exceptions that expired unresolved (count) | No | Information Security Manager | 5 Oct 2026 | 1 Oct 2026 | 1 | 0 | 0 | 1 | Worse (was 0) | Below target, within tolerance | 4 open; 1 expired | One exception expired in July before its renewal was decided; the risk owner closed it in August. | Security exception register | Register export 2026-09-30 | Head of Risk | 7 Oct 2026 | Head of Information Security | 8 Oct 2026 | On time | OK | |
| EXAMPLE | BM-04 | Significant incidents and time to contain | Hours to contain the slowest significant incident (0 if none) | No | Information Security Manager | 5 Oct 2026 | 1 Oct 2026 | 6 | 6 | 24 | 48 | Same (was 6) | On target | 1 significant incident (1 last quarter); contained in 6 hours | Ransomware on 14 office PCs at one warehouse on 12 Aug 2026 was contained in 6 hours; ordering and dispatch were not affected. | Incident log | Incident closure report, 12 Aug 2026 | Head of Risk | 7 Oct 2026 | Head of Information Security | 8 Oct 2026 | On time | OK | |
| EXAMPLE | BM-05 | Critical suppliers assessed | % of critical suppliers assessed (0–100) | Yes | Procurement Manager | 5 Oct 2026 | 6 Oct 2026 | 64 | 43 | 64 | 50 | Better (was 43%) | On target | 9 of 14 critical suppliers (plan: 9 by Q3, 14 of 14 by year end) | Three logistics suppliers assessed this quarter, as planned; five remain for Q4. | Third-party register | Supplier assessment log 2026-09-30 | Head of Risk | 7 Oct 2026 | Head of Information Security | 8 Oct 2026 | Late | OK | |
| EXAMPLE | BM-06 | Critical services restored in tests | % of critical services restored in tests (0–100) | Yes | IT Operations Manager | 5 Oct 2026 | 5 Oct 2026 | 50 | 25 | 50 | 25 | Better (was 25%) | On target | 2 of 4 critical services (plan: 2 by Q3, 4 of 4 each year) | Warehouse management was restored in 5 hours in the August test, within its 8-hour objective. | Recovery test records | Recovery test report 2026-08-27 | Head of Risk | 8 Oct 2026 | Head of Information Security | 8 Oct 2026 | On time | OK | |
| EXAMPLE | BM-07 | Security programme delivery | % of milestones due that were delivered on time (0–100) | Yes | Security Programme Manager | 5 Oct 2026 | 5 Oct 2026 | 78 | 78 | 100 | 75 | Same (was 78%) | Below target, within tolerance | 7 of 9 milestones (target 9 of 9 by quarter end) | Two milestones on the ordering platform slipped when its team lost two engineers. | Security programme plan | Programme report 2026-09-30 | Head of Risk | 8 Oct 2026 | On time | Sign off the figure (BR-08) | |||
| EXAMPLE | BM-08 | Board and staff security training | % of staff trained in the last 12 months (0–100) | Yes | HR Learning Lead | 5 Oct 2026 | 2 Oct 2026 | 92 | 88 | 95 | 85 | Better (was 88%) | Below target, within tolerance | Board 6 of 7; staff 92% (target: all board; staff 95%) | Warehouse shift staff completed the short course on the floor terminals. | Training records | Learning system report 2026-09-30 | Head of Risk | 7 Oct 2026 | Head of Information Security | 8 Oct 2026 | On time | OK |
Deck Feed
Deck feed — the figures in the order of the report
Position, Direction, Exposure, Ask (BR-01), pulled from Metric Data. Build the Board Cybersecurity Report Deck Template and the Cyber Risk One-Page Board Summary from this sheet only, once the readiness check says so.
Before you build the deck
| Check | Result | Status | What to do | ||||
|---|---|---|---|---|---|---|---|
| Measures in the Measures list with no row on Metric Data | 0 | Meets the check | Every measure the board agreed gets a row, every cycle. | ||||
| Values not yet entered | 0 | Meets the check | Chase the data owner; the timetable shows the date. | ||||
| Measures with no target | 0 | Meets the check | BR-03: no measure reaches the board without one. | ||||
| Figures not checked | 0 | Meets the check | Someone other than the data owner checks each figure against its evidence. | ||||
| Figures not signed off | 1 | Action needed | BR-08: sign-off is due on the timetable's sign-off date. | ||||
| Rows with a record check to resolve | 1 | Action needed | Any row on Metric Data whose Record check does not say OK. | ||||
| Ready to build the deck? | 2 | Not ready | 2 check(s) above need action before the deck is built. | ||||
1 Position — Where do we stand against the risk appetite the board set?
| Position statement, one sentence (BR-02) | We are outside our cyber risk appetite on 2 of 12 top risks, both within tolerance, and we expect to be back within appetite by the end of Q4 2026 if the board approves today's decision. | ||||||
EXAMPLE — write yours from the figures below once they are signed off. Use one of the position words: Within appetite; Outside appetite, within tolerance; Outside tolerance.
| Metric ID | Measure | Above appetite | Target | Past tolerance | Direction | Position | Supporting figure |
|---|---|---|---|---|---|---|---|
| BM-01 | Risks outside appetite | 2 | 0 | 0 | Better (was 3) | Outside appetite, within tolerance | 2 of 12 top risks above appetite; 0 past tolerance |
2 Direction — Is it getting better or worse, and why?
| Metric ID | Measure | Last period | This period | Target | Direction | Status | Why it moved |
|---|---|---|---|---|---|---|---|
| BM-01 | Risks outside appetite | 3 | 2 | 0 | Better (was 3) | Outside appetite, within tolerance | One risk returned within appetite after the warehouse network was separated from the office network. |
| BM-02 | Critical exposure fixed on time | 90 | 81 | 95 | Worse (was 90%) | Below target, within tolerance | The ordering platform team lost two engineers, so fixes on that platform queued. |
| BM-03 | Expired or high-risk exceptions | 0 | 1 | 0 | Worse (was 0) | Below target, within tolerance | One exception expired in July before its renewal was decided; the risk owner closed it in August. |
| BM-04 | Significant incidents and time to contain | 6 | 6 | 24 | Same (was 6) | On target | Ransomware on 14 office PCs at one warehouse on 12 Aug 2026 was contained in 6 hours; ordering and dispatch were not affected. |
| BM-05 | Critical suppliers assessed | 43 | 64 | 64 | Better (was 43%) | On target | Three logistics suppliers assessed this quarter, as planned; five remain for Q4. |
| BM-06 | Critical services restored in tests | 25 | 50 | 50 | Better (was 25%) | On target | Warehouse management was restored in 5 hours in the August test, within its 8-hour objective. |
| BM-07 | Security programme delivery | 78 | 78 | 100 | Same (was 78%) | Below target, within tolerance | Two milestones on the ordering platform slipped when its team lost two engineers. |
| BM-08 | Board and staff security training | 88 | 92 | 95 | Better (was 88%) | Below target, within tolerance | Warehouse shift staff completed the short course on the floor terminals. |
Every measure in the Measures list, in its order. Direction and status are in words (BR-04); explain the movement, not the activity.
3 Exposure — What could hurt us most, and how likely is it now?
| Metric ID | Measure | This period | Target | Tolerance | Direction | Status | Supporting figure |
|---|---|---|---|---|---|---|---|
| BM-02 | Critical exposure fixed on time | 81 | 95 | 80 | Worse (was 90%) | Below target, within tolerance | 81% within 14 calendar days (target 95%) |
| BM-03 | Expired or high-risk exceptions | 1 | 0 | 1 | Worse (was 0) | Below target, within tolerance | 4 open; 1 expired |
| BM-04 | Significant incidents and time to contain | 6 | 24 | 48 | Same (was 6) | On target | 1 significant incident (1 last quarter); contained in 6 hours |
| BM-05 | Critical suppliers assessed | 64 | 64 | 50 | Better (was 43%) | On target | 9 of 14 critical suppliers (plan: 9 by Q3, 14 of 14 by year end) |
| BM-06 | Critical services restored in tests | 50 | 50 | 25 | Better (was 25%) | On target | 2 of 4 critical services (plan: 2 by Q3, 4 of 4 each year) |
Pick the measures for this part in the yellow Metric ID cells. The top risks themselves come from the risk register, described by service, harm and cost (BR-05).
4 Ask — What do you need the board to decide, note or fund?
EXAMPLE — Ask 1
| Field | Answer | ||||||
|---|---|---|---|---|---|---|---|
| Decision asked for | Approve €180,000 to rebuild the ordering platform's recovery so it can be restored within 24 hours? | ||||||
| Options | A: approve now, done by 15 Dec 2026. B: approve half now for backup isolation only, and the rest in the next budget. C: do not approve; accept the risk. | ||||||
| Recommended option and why | A. It brings the ransomware risk back within appetite this year and is about 15% of one week's lost orders. | ||||||
| Cost | €180,000 one-off, plus about €20,000 a year to run. | ||||||
| Risk of not deciding | The ransomware risk stays outside appetite into 2027. A 2-day outage would cost about €1.2m per week of orders lost, plus contract penalties. | ||||||
| Decision needed by | This meeting, so work starts before the peak season in November. | ||||||
Ask 2
| Field | Answer | ||||||
|---|---|---|---|---|---|---|---|
| Decision asked for | [[The decision the board is asked to take]] | ||||||
| Options | [[Options, with what each costs and achieves]] | ||||||
| Recommended option and why | [[Recommended option and why]] | ||||||
| Cost | [[Cost, one-off and yearly]] | ||||||
| Risk of not deciding | [[What happens if the board does not decide]] | ||||||
| Decision needed by | [[Date or meeting]] | ||||||
Add an ask block for each further decision. Amounts in the examples are in euros (€); use your own currency. BR-06: Every ask is a decision with options, a recommendation, cost and the risk of not deciding.
Lists
| MeasureID | MeasureName | MeasureUnit | HigherIsBetter | ReportPart | MeasureQuestion | YesNo |
|---|---|---|---|---|---|---|
| BM-01 | Risks outside appetite | Top risks above appetite (count); past tolerance counted beside it | No | Position | Are we within the risk appetite we set? | Yes |
| BM-02 | Critical exposure fixed on time | % fixed and verified on time (0–100) | Yes | Exposure | Are the weaknesses attackers use being closed fast enough? | No |
| BM-03 | Expired or high-risk exceptions | Exceptions that expired unresolved (count) | No | Exposure | Where have we knowingly accepted risk, and is it still under control? | |
| BM-04 | Significant incidents and time to contain | Hours to contain the slowest significant incident (0 if none) | No | Exposure | Have we been hurt, and how quickly did we recover? | |
| BM-05 | Critical suppliers assessed | % of critical suppliers assessed (0–100) | Yes | Exposure | Are the suppliers we depend on held to our standard? | |
| BM-06 | Critical services restored in tests | % of critical services restored in tests (0–100) | Yes | Exposure | Could we recover our most important services, and have we proved it? | |
| BM-07 | Security programme delivery | % of milestones due that were delivered on time (0–100) | Yes | Direction | Is the plan the board funded being delivered? | |
| BM-08 | Board and staff security training | % of staff trained in the last 12 months (0–100) | Yes | Direction | Do we, and our people, know enough to judge and act on cyber risk? |
Columns A to F are the Measures list: the pack's board measures from the Board Metric Selection Catalogue. Yellow rows: add your own measures, or overwrite a row to replace one.
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Cycle | One round of board reporting, from the data request to the actions recorded after the meeting. The pack assumes quarterly board reporting. |
| Board date | The date of the board or committee meeting the report is for. Day 0 of the timetable. |
| Working day | Monday to Friday, less the dates in the Non-working days list. The timetable counts in working days, not calendar days. |
| Data owner | The person, by role, who supplies a measure's figure and its evidence — [[e.g. IT operations, risk, procurement, HR]]. |
| Value this period | The measure's figure at the end of the period being reported, in the unit on its row. Percentages are entered as numbers from 0 to 100. |
| Value last period | The same measure's value in the previous cycle's copy of this workbook, as it was signed off then. |
| Target | The level the board aims for. |
| Tolerance limit | The worst value the board accepts before it must act, not just be told. Under DORA the management body sets the ICT risk tolerance (Art 5(2)). Not used for the Position measure (BM-01), whose top risks each carry their own tolerance limit in the risk register. |
| Past tolerance | For the Position measure (BM-01) only: the number of top risks assessed past their own tolerance limit. With Value this period (top risks above appetite) it sets the position: Outside tolerance if any top risk is past its own tolerance limit; otherwise Outside appetite, within tolerance if any top risk is above appetite; otherwise Within appetite. |
| Direction | Better, Same, Worse: this period's value against last period's, read with 'Higher is better', with last period's value in brackets. 'No previous value' when there is none. |
| Status — On target | At or better than its target. |
| Status — Below target, within tolerance | Short of its target but inside the tolerance the board set; a plan and date are given. |
| Status — Outside tolerance | Beyond the limit at which the board said it must act, not just be told; an ask follows (BR-06). |
| Status — No target set | Reported without a target: it should not reach the board until one is set (BR-03). |
| Position — Within appetite | Every top risk is assessed at or below the level of risk the board has said it is willing to accept. Used as the status of the Position measure (BM-01) and in the position statement (BR-02). |
| Position — Outside appetite, within tolerance | At least one top risk is above appetite but below the tolerance limit, with a plan and a date to bring it back. Used as the status of the Position measure (BM-01) and in the position statement (BR-02). |
| Position — Outside tolerance | At least one risk is above the tolerance limit: the point at which the board said it must act, not just be told. Used as the status of the Position measure (BM-01) and in the position statement (BR-02). |
| Awaiting value | Status before this period's value is entered. |
| Supporting figure | The value in words the board recognises, such as '2 of 12 top risks'. |
| Evidence reference | Where the figure can be checked: a report, export or record, with its date. |
| Checked by | Someone other than the data owner who compared the figure with its evidence. |
| Signed off | The reporter's confirmation, with the risk function, that the figure may go to the board (BR-08). |
| Timeliness | On time or Late: when the figure arrived against the date due. Overdue: not yet arrived and past due. |
| Deck feed | The figures in the order of the report (BR-01), for building the Board Cybersecurity Report Deck Template and the Cyber Risk One-Page Board Summary. |
| BR-nn, BM-nn | Reporting rules and board measures defined in the Board Reporting Narrative Model; the measures are explained in the Board Metric Selection Catalogue. |
| (calc) | A column or cell the workbook calculates. Do not type or paste over it. |
| EXAMPLE row | A worked example showing one quarter for a fictional distributor. Delete before use. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 9.1 — Monitoring, measurement, analysis and evaluation | Metric Data: what is measured, when, by whom, and the evidence; Direction and Status |
| ISO/IEC 27001:2022 | Clause 9.3 — Management review | Deck Feed: the figures as an input to management review by the board |
| NIST CSF 2.0 | GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed” | Metric Data and Deck Feed: performance reviewed against target and tolerance |
| DORA — Regulation (EU) 2022/2554 | Article 5(2)(i) — reporting channels that keep the management body informed, including of at least major ICT-related incidents and their impact | Cycle Control and Deck Feed: a regular reporting channel to the management body, incidents included (BM-04) |
| NIS2 — Directive (EU) 2022/2555 | Article 20(1) — management bodies approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements | The signed-off figures through which the management body oversees implementation |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA)