Board Reporting Effectiveness Self-Check
Scores an existing board report against what governance bodies need, and identifies the specific content to add or remove.
Available soon
- Format
- Excel
- Size
- 71 KB
- Length
- 11 sheets
- Version
- 1.1
- Updated
What's inside
- Instructions
- Criteria
- Remove Checklist
- Results
- Export
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Scope: the last cyber report that went to the board or committee [[e.g. Board, or its Audit & Risk Committee]], including its one-page summary and appendices. Score what the board actually received, not what you intended. Ideally two people score it separately — the reporter and the executive sponsor or a board member — then agree. |
| 2 | On the Criteria sheet, read the three descriptions for each criterion (columns F to H). Enter 0, 1 or 2 in column J (Your score) for the one that matches the report. If you are between two, choose the lower. |
| 3 | Use N/A only where a criterion cannot apply, for example ASK-04 when this was the first report to the board. N/A is left out of both the points scored and the points available. |
| 4 | Note the evidence for each score in column O (for example 'slide 4: no targets'). It makes next year's check faster and shows why you chose the score. |
| 5 | On the Remove Checklist sheet, answer Present or Absent in column G for each item: is it in the report? |
| 6 | On the Results sheet, change cell D5 from 'Example report' to 'My report'. The points, levels and both lists now describe your report. |
| 7 | Work down the list of content to add from the top, and take out every item on the remove list. Rebuild the next report, then score it again. |
| 8 | Copy the Export table (paste as values) into your records. Repeat the check once a year (BR-10), before the board's deep dive. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
The worked EXAMPLE. Column I of the Criteria sheet and column F of the Remove Checklist hold scores for a typical technical-status report: twelve slides assembled from security tools for the fictional organisation used across this pack (a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders) before it adopted this pack — counts of blocked attacks, patching percentages with no targets, a red-amber-green project list, a slide of industry threat news, no statement on appetite and a closing slide marked 'for information'. While Results cell D5 says 'Example report', every result is calculated from those columns and labelled EXAMPLE. To clear it, set D5 to 'My report'; to remove it completely, also delete Criteria cells I4 to I27 and Remove Checklist cells F4 to F12.
Score scale. 0 Absent: The report does not do this, or does it so rarely a director would not notice. 1 Partly: The report does this for some items or some of the time, or does it in a way a director has to work to find. 2 Fully: The report does this every time, where a director expects to find it.
Priority. Essential: Without it the board cannot govern cyber risk from the report. Fix these first. Important: The board can govern, but with more effort, less confidence or a weaker record. Helpful: Makes a good report better. Fix once the essential and important criteria are in place. Priority orders the list of content to add; it does not change the points.
Levels, from the points scored against the points available. Not yet serving the board: fewer than a third of the available points. Partly serving the board: at least a third, but fewer than two thirds, of the available points. Largely serving the board: at least two thirds of the available points, but not all. Fully serving the board: every available point. If any Essential criterion scores 0, the overall level is no higher than 'Partly serving the board', however well the rest scores. Results are never shown as a percentage.
Tailoring — small organisation: the report may be two pages rather than a deck, and the board may meet less often. The criteria still apply; for EXP-03 fewer top risks is fine, and PRO-03 can be a single signed-off spreadsheet.
Tailoring — regulated entity (NIS2 or DORA): the management body must approve and oversee cybersecurity risk management (NIS2 Article 20; DORA Article 5). Treat POS-02, DIR-03 and ASK-04 as evidence of oversight: keep the completed self-check and the improvement actions with the board papers.
Tailoring — IT run by a service provider: score the report the board receives, not the provider's own service report. Where the provider's figures reach the board, MEA-01 and PRO-03 test whether they have been turned into board measures and checked before use.
Limitations: see the foot of the Results sheet.
Criteria
Enter 0, 1 or 2 (or N/A) in column J for each criterion. Column I is the worked EXAMPLE. Columns K, L and P calculate; do not type in them.
| ID | Group | Criterion | Rule | Priority | 0 — Absent | 1 — Partly | 2 — Fully | Example score (EXAMPLE) | Your score | Score used (calc) | In words (calc) | What to add or change if 0 or 1 | Document that helps | Notes or evidence | Add ranking key (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| POS-01 | Position | Does the report open with a one-sentence answer to 'are we within appetite?' | BR-02 | Essential | No such sentence; the report opens with activity, threats or a dashboard. | A summary opens the report, but it does not say whether the organisation is within appetite, or says so only later. | The first sentence states the position in the pack's words ('Within appetite', 'Outside appetite, within tolerance' or 'Outside tolerance') and why. | 0 | 0 | Absent | Open with one sentence stating the position — 'Within appetite', 'Outside appetite, within tolerance' or 'Outside tolerance' — and the main reason for it. | Board Reporting Narrative Model | 3224 | ||
| POS-02 | Position | Is the position judged against a risk appetite and tolerance the board has actually set? | BR-02 | Essential | No appetite or tolerance is referred to; 'good' and 'bad' are the reporter's opinion. | An appetite is mentioned, but it is not the board's approved statement, or the report does not measure against it. | The report names the board's appetite and tolerance statement and measures the top risks against it (BM-01). | 0 | 0 | Absent | Measure the position against the board's approved appetite and tolerance statement, using the count of risks outside appetite (BM-01). If there is no approved statement, make agreeing one your first ask. | Board Reporting Narrative Model | 3223 | ||
| POS-03 | Position | Is the position supported by a few board measures straight after the opening sentence? | BR-03 | Important | No measures support the position, or the report opens with dozens of figures. | Measures are there but too many, or not the ones that show the position. | A handful of board measures, drawn from the Board Metric Selection Catalogue, follow the opening sentence and support it. | 1 | 1 | Partly | Follow the opening sentence with the few board measures that show the position, chosen from the Board Metric Selection Catalogue. | Board Metric Selection Catalogue | 2122 | ||
| DIR-01 | Direction | Does each headline measure show its movement since the last report? | BR-04 | Essential | No comparison with the last report. | Some measures show a trend, or trends are shown only as arrows or colours. | Every headline measure states its direction in words ('Better', 'Same' or 'Worse') with the previous value. | 1 | 1 | Partly | Show every headline measure's direction since the last report in words ('Better', 'Same' or 'Worse'), with the previous value. | Board Reporting Data Collection Workbook | 3121 | ||
| DIR-02 | Direction | Does the report explain why things moved, rather than list what the team did? | BR-01 | Important | A list of activity ('we deployed', 'we ran') with no link to the measures. | Some causes are given, mixed with activity lists. | Each significant movement has its cause, in a sentence or two; activity appears only where it explains a movement. | 0 | 0 | Absent | Replace the activity list with the cause of each significant movement: what changed, and what it did to the risk. | Board Reporting Narrative Model | 2220 | ||
| DIR-03 | Direction | Is bad news reported in the first report after it was known, with what is being done and by when? | BR-07 | Essential | Bad news is left out, softened into activity, or reported only when asked. | Bad news is reported, but late, or without the action and date. | Every significant problem appears in the first report after it was known, with the action, the owner and the date. | 1 | 1 | Partly | Report every significant problem in the first report after it is known, with what is being done, by whom and by when. | Board Reporting Narrative Model | 3119 | ||
| DIR-04 | Direction | Does the report show whether the security programme the board funded is on plan? | BR-03 | Helpful | No view of programme delivery, or only a list of projects. | Project statuses are shown, but not against the plan and budget the board approved. | Delivery is shown against the approved plan (BM-07), with slippage explained and any decision needed stated. | 1 | 1 | Partly | Show delivery of the funded programme against the approved plan and budget (BM-07), and turn any slippage that needs a decision into an ask. | Board Metric Selection Catalogue | 1118 | ||
| EXP-01 | Exposure | Are the top risks described in business terms: which service, what harm, what it would cost? | BR-05 | Essential | Risks are described as technical weaknesses or threats (vulnerability names, attack types). | Some risks name the service or the harm, but not the likely cost. | Each top risk names the service affected, the harm to the organisation and a cost range. | 0 | 0 | Absent | Rewrite each top risk as: the service affected, the harm, and a cost range. Move the technical description to the appendix. | Board Reporting Narrative Model | 3217 | ||
| EXP-02 | Exposure | Does each top risk say how likely it is now, and whether it is within appetite? | BR-02 | Important | No likelihood, or 'high/medium/low' with no meaning given. | Likelihood is given, but without agreed words, or without saying whether the risk is within appetite. | Each top risk has a likelihood in the pack's agreed words and its position against appetite. | 0 | 0 | Absent | Give each top risk its likelihood in agreed words (Unlikely, Possible, Likely, Almost certain) and say whether it is within appetite. | Board Reporting Narrative Model | 2216 | ||
| EXP-03 | Exposure | Is the list of top risks short enough for the board to discuss? | BR-05 | Helpful | No list of top risks, or the full risk register. | A list is given but too long to discuss in the time. | [[3 to 5]] top risks, with the rest available in the appendix or the risk register. | 1 | 1 | Partly | Limit the body to the [[3 to 5]] risks that matter most; put the rest in the appendix. | Cyber Risk One-Page Board Summary | 1115 | ||
| EXP-04 | Exposure | Can the board see where risk has been knowingly accepted, and whether those acceptances are still under control? | BR-03 | Helpful | Accepted risks and exceptions are not mentioned. | Exceptions are mentioned, but not whether any have expired or are high risk. | Expired and high-risk exceptions are reported (BM-03), with who accepted them and until when. | 0 | 0 | Absent | Report expired and high-risk exceptions (BM-03): what was accepted, by whom and until when. | Board Metric Selection Catalogue | 1214 | ||
| ASK-01 | Ask | Is each ask stated as a decision the board must take: decide, note or fund? | BR-06 | Essential | No ask, or the report is 'for information' only. | An ask is implied or buried in the text. | Each ask is stated plainly at the end of the report as a decision to decide, note or fund. | 0 | 0 | Absent | End the report with each ask stated as a decision: what the board is asked to decide, note or fund. If nothing is needed, say so. | Board Cybersecurity Report Deck Template | 3213 | ||
| ASK-02 | Ask | Does each ask give the options and the one recommended? | BR-06 | Essential | No options: the board is asked to approve a single course. | Options are listed, but no recommendation, or the recommendation is not explained. | Each ask sets out the realistic options and the recommended one, with the reason. | 0 | 0 | Absent | For each ask, set out the realistic options (including doing nothing) and the recommended one, with the reason. | Board Reporting Narrative Model | 3212 | ||
| ASK-03 | Ask | Does each ask state the cost and the risk of not deciding? | BR-06 | Important | Neither is given. | One is given, or the cost is given without a period. | Each ask states its cost over a stated period and what happens to the risk if the board does not decide. | 0 | 0 | Absent | State each ask's cost over a stated period, and the risk of not deciding. | Board Reporting Narrative Model | 2211 | ||
| ASK-04 | Ask | Are the board's actions from previous meetings reported until they are closed? (N/A for a first report.) | BR-09 | Important | Previous actions are not mentioned. | Some are mentioned, or they drop out before they are closed. | Every open action has its owner, date and status, and stays in the report until closed. | 1 | 1 | Partly | Add a short list of the board's open actions, each with owner, date and status, kept until closed. | Board Cybersecurity Report Deck Template | 2110 | ||
| MEA-01 | Measures | Does every measure in the body answer a question the board asks? | BR-03 | Essential | Most measures are operational (for example emails blocked, scans run). | Some measures answer a board question; others are there because they are available. | Every measure answers a board question from the Board Metric Selection Catalogue. | 1 | 1 | Partly | Keep only measures that answer a board question; take them from the Board Metric Selection Catalogue and move the rest to operational reporting. | Board Metric Selection Catalogue | 3109 | ||
| MEA-02 | Measures | Does every measure have a stated target or tolerance? | BR-03 | Essential | No targets. | Some measures have targets. | Every measure shows its target or tolerance, agreed in advance. | 0 | 0 | Absent | Agree a target or tolerance for every measure before it reaches the board; a measure without one shows 'No target set' and should be removed at the next report. | Board Metric Selection Catalogue | 3208 | ||
| MEA-03 | Measures | Does each measure show its value, target, direction and status together? | BR-04 | Important | Values only. | Some of the four, or spread across different pages. | Value, target, direction and status sit side by side for every measure, the status in the pack's words ('On target', 'Below target, within tolerance', 'Outside tolerance' or 'No target set'). | 1 | 1 | Partly | Show value, target, direction and status side by side for every measure, with the status in words: 'On target', 'Below target, within tolerance', 'Outside tolerance' or 'No target set'. | Cyber Risk One-Page Board Summary | 2107 | ||
| MEA-04 | Measures | Is status always written in words, never shown by colour alone? | BR-04 | Important | Red, amber and green with no words. | Words for some items; colour alone for others. | Every status is in words; colour, if used, only repeats the words. | 0 | 0 | Absent | Write every status in words. Keep colour only as a repeat of the words, so the report works in black and white and in the minutes. | Cyber Risk One-Page Board Summary | 2206 | ||
| MEA-05 | Measures | Are measures defined the same way from one report to the next, so periods compare? | BR-08 | Helpful | Definitions change, or are not written down. | Definitions are written down but changes are not flagged. | Definitions are fixed; any change is flagged and the previous figure restated. | 1 | 1 | Partly | Fix each measure's definition, flag any change in the report, and restate the previous figure on the new basis. | Board Reporting Data Collection Workbook | 1105 | ||
| PRO-01 | Process | Does the report follow Position, Direction, Exposure and Ask, in that order? | BR-01 | Important | No recognisable structure, or one per team or tool. | Some of the four parts, or in a different order each time. | The four parts, in that order, every time. | 0 | 0 | Absent | Restructure the report into the four parts: Position, Direction, Exposure, Ask, in that order. | Board Cybersecurity Report Deck Template | 2204 | ||
| PRO-02 | Process | Is technical detail kept in an appendix, so the body speaks of services, harm and money? | BR-05 | Important | The body is technical throughout. | Mostly business language, with technical sections in the body. | The body is in business language; the technical detail is in an appendix for those who want it. | 0 | 0 | Absent | Move technical detail to an appendix and rewrite the body in terms of services, harm and money. | Board Reporting Narrative Model | 2203 | ||
| PRO-03 | Process | Do all figures come from one data collection workbook, checked and signed off before the report is built? | BR-08 | Important | Figures are pulled from tools as the report is written. | One source exists, but figures are not checked or signed off before the report is built. | Every figure comes from one workbook, reconciled with its source and signed off before the report is built. | 1 | 1 | Partly | Collect every figure in the Board Reporting Data Collection Workbook and have it checked and signed off before the report is built. | Board Reporting Data Collection Workbook | 2102 | ||
| PRO-04 | Process | Is the reporting itself reviewed once a year, and are the improvements tracked? | BR-10 | Helpful | Never reviewed. | Reviewed occasionally, or improvements are not followed through. | Reviewed once a year with this self-check, with improvements recorded and checked at the next review. | 0 | 0 | Absent | Repeat this self-check once a year, before the board's deep dive, and record the improvements. Schedule it in the Board & Executive Reporting Calendar. | Board & Executive Reporting Calendar | 1201 |
Remove Checklist
Is each of these in the report? Answer Present or Absent in column G. Column F is the worked EXAMPLE. Anything present goes on the remove list on the Results sheet.
| ID | What to look for | Why it hurts | Rule | Instead | Example answer (EXAMPLE) | Your answer | Answer used (calc) | Notes or evidence | Remove ranking key (calc) |
|---|---|---|---|---|---|---|---|---|---|
| REM-01 | Raw counts without a target or tolerance (for example 'phishing emails blocked') | A number with no target cannot be judged good or bad, and moves the discussion to the number. | BR-03 | Remove it, or replace it with a board measure that has a target. | Present | Present | 9 | ||
| REM-02 | Status shown by colour alone (red, amber, green with no words) | Colour fails for readers with colour-vision deficiency, disappears in print and cannot be minuted. | BR-04 | Write the status in words: 'On target', 'Below target, within tolerance', 'Outside tolerance' or 'No target set'. | Present | Present | 8 | ||
| REM-03 | Jargon and unexplained acronyms in the body | Directors cannot challenge what they cannot follow, and stop reading. | BR-05 | Use plain words in the body; explain any term that must stay. | Present | Present | 7 | ||
| REM-04 | Lists of activity in place of movement and cause | Activity says the team is busy, not whether the risk changed. | BR-01 | State the movement in each measure and its cause. | Present | Present | 6 | ||
| REM-05 | Screenshots of security tools or dashboards | They show what a tool can display, not what the board needs to decide, and are rarely readable. | BR-05 | Put the one figure that matters in the board measure table; drop the screenshot. | Present | Present | 5 | ||
| REM-06 | Technical detail in the body (vulnerability identifiers, product names, network details) | It hides the business point and can itself be sensitive if the papers leak. | BR-05 | Move it to the appendix, or leave it out. | Present | Present | 4 | ||
| REM-07 | Measures that answer no question the board asks | Each one takes attention from the measures that matter. | BR-03 | Move them to operational reporting. | Present | Present | 3 | ||
| REM-08 | Figures that disagree with each other, or with the last report, without explanation | One wrong figure makes the board doubt all of them. | BR-08 | Take every figure from the one signed-off workbook; explain any restatement. | Absent | Absent | 0 | ||
| REM-09 | General threat news or attacker statistics not linked to our own exposure | It raises alarm without telling the board what to do about its own risk. | BR-05 | Keep only threats that change one of our top risks, and say how. | Present | Present | 1 |
Results
Results
Points are shown as 'x of y': points scored of the points available, leaving out criteria scored N/A. Each level is in words. The two lists are generated from your scores.
| Results from: | Example report | ← choose 'My report' once you have scored the Criteria and the Remove Checklist. | |
EXAMPLE: these results are for the worked example, a typical technical-status report, not your report. Choose 'My report' in D5 to see your own.
Overall result
| Points | 10 of 48 | Points scored of the points available (2 for each criterion not scored N/A). | |||||
| Level | Not yet serving the board | The report tells the board what the security team did, not whether the organisation is within appetite or what the board must decide. Rebuild it on the four-part structure before refining anything. | |||||
| Items to remove | 8 of 9 present | Things in the report that should not be there. They do not change the points; take them out. | |||||
Result by part of the report
| No. | Part | Points | Level | What the part asks | Points scored | Points available | |||
|---|---|---|---|---|---|---|---|---|---|
| 1 | Position | 1 of 6 | Not yet serving the board | Where do we stand against the risk appetite the board set? | 1 | 6 | |||
| 2 | Direction | 3 of 8 | Partly serving the board | Is it getting better or worse, and why? | 3 | 8 | |||
| 3 | Exposure | 1 of 8 | Not yet serving the board | What could hurt us most, and how likely is it now? | 1 | 8 | |||
| 4 | Ask | 1 of 8 | Not yet serving the board | What do you need the board to decide, note or fund? | 1 | 8 | |||
| 5 | Measures | 3 of 10 | Not yet serving the board | Does every figure earn its place, and can a director judge it at a glance? | 3 | 10 | |||
| 6 | Process | 1 of 8 | Not yet serving the board | Is the report built, checked and improved in a way the board can rely on? | 1 | 8 | |||
Content to add — most important first
| # | Criterion | Part | What to add or change | Rule and priority | Score now | Document that helps | Ranking key | Row |
|---|---|---|---|---|---|---|---|---|
| 1 | POS-01 | Position | Open with one sentence stating the position — 'Within appetite', 'Outside appetite, within tolerance' or 'Outside tolerance' — and the main reason for it. | BR-02 · Essential | Absent | Board Reporting Narrative Model | 3224 | 1 |
| 2 | POS-02 | Position | Measure the position against the board's approved appetite and tolerance statement, using the count of risks outside appetite (BM-01). If there is no approved statement, make agreeing one your first ask. | BR-02 · Essential | Absent | Board Reporting Narrative Model | 3223 | 2 |
| 3 | EXP-01 | Exposure | Rewrite each top risk as: the service affected, the harm, and a cost range. Move the technical description to the appendix. | BR-05 · Essential | Absent | Board Reporting Narrative Model | 3217 | 8 |
| 4 | ASK-01 | Ask | End the report with each ask stated as a decision: what the board is asked to decide, note or fund. If nothing is needed, say so. | BR-06 · Essential | Absent | Board Cybersecurity Report Deck Template | 3213 | 12 |
| 5 | ASK-02 | Ask | For each ask, set out the realistic options (including doing nothing) and the recommended one, with the reason. | BR-06 · Essential | Absent | Board Reporting Narrative Model | 3212 | 13 |
| 6 | MEA-02 | Measures | Agree a target or tolerance for every measure before it reaches the board; a measure without one shows 'No target set' and should be removed at the next report. | BR-03 · Essential | Absent | Board Metric Selection Catalogue | 3208 | 17 |
| 7 | DIR-01 | Direction | Show every headline measure's direction since the last report in words ('Better', 'Same' or 'Worse'), with the previous value. | BR-04 · Essential | Partly | Board Reporting Data Collection Workbook | 3121 | 4 |
| 8 | DIR-03 | Direction | Report every significant problem in the first report after it is known, with what is being done, by whom and by when. | BR-07 · Essential | Partly | Board Reporting Narrative Model | 3119 | 6 |
| 9 | MEA-01 | Measures | Keep only measures that answer a board question; take them from the Board Metric Selection Catalogue and move the rest to operational reporting. | BR-03 · Essential | Partly | Board Metric Selection Catalogue | 3109 | 16 |
| 10 | DIR-02 | Direction | Replace the activity list with the cause of each significant movement: what changed, and what it did to the risk. | BR-01 · Important | Absent | Board Reporting Narrative Model | 2220 | 5 |
| 11 | EXP-02 | Exposure | Give each top risk its likelihood in agreed words (Unlikely, Possible, Likely, Almost certain) and say whether it is within appetite. | BR-02 · Important | Absent | Board Reporting Narrative Model | 2216 | 9 |
| 12 | ASK-03 | Ask | State each ask's cost over a stated period, and the risk of not deciding. | BR-06 · Important | Absent | Board Reporting Narrative Model | 2211 | 14 |
| 13 | MEA-04 | Measures | Write every status in words. Keep colour only as a repeat of the words, so the report works in black and white and in the minutes. | BR-04 · Important | Absent | Cyber Risk One-Page Board Summary | 2206 | 19 |
| 14 | PRO-01 | Process | Restructure the report into the four parts: Position, Direction, Exposure, Ask, in that order. | BR-01 · Important | Absent | Board Cybersecurity Report Deck Template | 2204 | 21 |
| 15 | PRO-02 | Process | Move technical detail to an appendix and rewrite the body in terms of services, harm and money. | BR-05 · Important | Absent | Board Reporting Narrative Model | 2203 | 22 |
| 16 | POS-03 | Position | Follow the opening sentence with the few board measures that show the position, chosen from the Board Metric Selection Catalogue. | BR-03 · Important | Partly | Board Metric Selection Catalogue | 2122 | 3 |
| 17 | ASK-04 | Ask | Add a short list of the board's open actions, each with owner, date and status, kept until closed. | BR-09 · Important | Partly | Board Cybersecurity Report Deck Template | 2110 | 15 |
| 18 | MEA-03 | Measures | Show value, target, direction and status side by side for every measure, with the status in words: 'On target', 'Below target, within tolerance', 'Outside tolerance' or 'No target set'. | BR-04 · Important | Partly | Cyber Risk One-Page Board Summary | 2107 | 18 |
| 19 | PRO-03 | Process | Collect every figure in the Board Reporting Data Collection Workbook and have it checked and signed off before the report is built. | BR-08 · Important | Partly | Board Reporting Data Collection Workbook | 2102 | 23 |
| 20 | EXP-04 | Exposure | Report expired and high-risk exceptions (BM-03): what was accepted, by whom and until when. | BR-03 · Helpful | Absent | Board Metric Selection Catalogue | 1214 | 11 |
| 21 | PRO-04 | Process | Repeat this self-check once a year, before the board's deep dive, and record the improvements. Schedule it in the Board & Executive Reporting Calendar. | BR-10 · Helpful | Absent | Board & Executive Reporting Calendar | 1201 | 24 |
| 22 | DIR-04 | Direction | Show delivery of the funded programme against the approved plan and budget (BM-07), and turn any slippage that needs a decision into an ask. | BR-03 · Helpful | Partly | Board Metric Selection Catalogue | 1118 | 7 |
| 23 | EXP-03 | Exposure | Limit the body to the [[3 to 5]] risks that matter most; put the rest in the appendix. | BR-05 · Helpful | Partly | Cyber Risk One-Page Board Summary | 1115 | 10 |
| 24 | MEA-05 | Measures | Fix each measure's definition, flag any change in the report, and restate the previous figure on the new basis. | BR-08 · Helpful | Partly | Board Reporting Data Collection Workbook | 1105 | 20 |
Content to remove
| # | Item | What to look for | Rule | Instead | Ranking key | Row | ||
|---|---|---|---|---|---|---|---|---|
| 1 | REM-01 | Raw counts without a target or tolerance (for example 'phishing emails blocked') | BR-03 | Remove it, or replace it with a board measure that has a target. | 9 | 1 | ||
| 2 | REM-02 | Status shown by colour alone (red, amber, green with no words) | BR-04 | Write the status in words: 'On target', 'Below target, within tolerance', 'Outside tolerance' or 'No target set'. | 8 | 2 | ||
| 3 | REM-03 | Jargon and unexplained acronyms in the body | BR-05 | Use plain words in the body; explain any term that must stay. | 7 | 3 | ||
| 4 | REM-04 | Lists of activity in place of movement and cause | BR-01 | State the movement in each measure and its cause. | 6 | 4 | ||
| 5 | REM-05 | Screenshots of security tools or dashboards | BR-05 | Put the one figure that matters in the board measure table; drop the screenshot. | 5 | 5 | ||
| 6 | REM-06 | Technical detail in the body (vulnerability identifiers, product names, network details) | BR-05 | Move it to the appendix, or leave it out. | 4 | 6 | ||
| 7 | REM-07 | Measures that answer no question the board asks | BR-03 | Move them to operational reporting. | 3 | 7 | ||
| 8 | REM-09 | General threat news or attacker statistics not linked to our own exposure | BR-05 | Keep only threats that change one of our top risks, and say how. | 1 | 9 | ||
9
How the results are worked out
1. Points: each criterion scores 0, 1 or 2; N/A and blank are left out. Points available = 2 × the criteria scored. A part's points and the overall points are shown as 'x of y'.
2. Level: 'Not yet serving the board' for fewer than a third of the available points; 'Partly serving the board' for at least a third, but fewer than two thirds, of the available points; 'Largely serving the board' for at least two thirds of the available points, but not all; 'Fully serving the board' for every available point. Overall, if any Essential criterion scores 0 the level is held at or below 'Partly serving the board'.
3. Content to add: every criterion scored 0 or 1, ordered by priority (Essential, then Important, then Helpful), then by score (Absent before Partly), then by the order of the criteria. The ranking key on the Criteria sheet encodes this order.
4. Content to remove: every checklist item answered Present, in checklist order.
Limitations
This is a self-check of one report by the people who wrote it. It is only as honest as the scores; a second scorer, ideally a board member, is the best check.
It tests whether the report gives the board what it needs to govern, not whether the organisation's security is good. A well-written report can describe a poor position — that is its job.
The criteria follow the pack's reporting rules (BR-01 to BR-10). They are not a benchmark, and the level cannot be compared with other organisations or with any certification requirement.
It does not assess the meeting itself — how the board discussed the report or what it decided — beyond whether earlier actions are followed up (ASK-04).
Export
Every score and result in one table. Select the table, copy, and paste as values into your records. Everything here is calculated; do not type in it.
| Section | Ref | Part | Item | Score or points | In words | Detail |
|---|---|---|---|---|---|---|
| Source | Scores used | Example report | EXAMPLE: these results are for the worked example, a typical technical-status report, not your report. Choose 'My report' in D5 to see your own. | |||
| Criterion | POS-01 | Position | Does the report open with a one-sentence answer to 'are we within appetite?' | 0 | Absent | |
| Criterion | POS-02 | Position | Is the position judged against a risk appetite and tolerance the board has actually set? | 0 | Absent | |
| Criterion | POS-03 | Position | Is the position supported by a few board measures straight after the opening sentence? | 1 | Partly | |
| Criterion | DIR-01 | Direction | Does each headline measure show its movement since the last report? | 1 | Partly | |
| Criterion | DIR-02 | Direction | Does the report explain why things moved, rather than list what the team did? | 0 | Absent | |
| Criterion | DIR-03 | Direction | Is bad news reported in the first report after it was known, with what is being done and by when? | 1 | Partly | |
| Criterion | DIR-04 | Direction | Does the report show whether the security programme the board funded is on plan? | 1 | Partly | |
| Criterion | EXP-01 | Exposure | Are the top risks described in business terms: which service, what harm, what it would cost? | 0 | Absent | |
| Criterion | EXP-02 | Exposure | Does each top risk say how likely it is now, and whether it is within appetite? | 0 | Absent | |
| Criterion | EXP-03 | Exposure | Is the list of top risks short enough for the board to discuss? | 1 | Partly | |
| Criterion | EXP-04 | Exposure | Can the board see where risk has been knowingly accepted, and whether those acceptances are still under control? | 0 | Absent | |
| Criterion | ASK-01 | Ask | Is each ask stated as a decision the board must take: decide, note or fund? | 0 | Absent | |
| Criterion | ASK-02 | Ask | Does each ask give the options and the one recommended? | 0 | Absent | |
| Criterion | ASK-03 | Ask | Does each ask state the cost and the risk of not deciding? | 0 | Absent | |
| Criterion | ASK-04 | Ask | Are the board's actions from previous meetings reported until they are closed? (N/A for a first report.) | 1 | Partly | |
| Criterion | MEA-01 | Measures | Does every measure in the body answer a question the board asks? | 1 | Partly | |
| Criterion | MEA-02 | Measures | Does every measure have a stated target or tolerance? | 0 | Absent | |
| Criterion | MEA-03 | Measures | Does each measure show its value, target, direction and status together? | 1 | Partly | |
| Criterion | MEA-04 | Measures | Is status always written in words, never shown by colour alone? | 0 | Absent | |
| Criterion | MEA-05 | Measures | Are measures defined the same way from one report to the next, so periods compare? | 1 | Partly | |
| Criterion | PRO-01 | Process | Does the report follow Position, Direction, Exposure and Ask, in that order? | 0 | Absent | |
| Criterion | PRO-02 | Process | Is technical detail kept in an appendix, so the body speaks of services, harm and money? | 0 | Absent | |
| Criterion | PRO-03 | Process | Do all figures come from one data collection workbook, checked and signed off before the report is built? | 1 | Partly | |
| Criterion | PRO-04 | Process | Is the reporting itself reviewed once a year, and are the improvements tracked? | 0 | Absent | |
| Remove checklist | REM-01 | Raw counts without a target or tolerance (for example 'phishing emails blocked') | Present | |||
| Remove checklist | REM-02 | Status shown by colour alone (red, amber, green with no words) | Present | |||
| Remove checklist | REM-03 | Jargon and unexplained acronyms in the body | Present | |||
| Remove checklist | REM-04 | Lists of activity in place of movement and cause | Present | |||
| Remove checklist | REM-05 | Screenshots of security tools or dashboards | Present | |||
| Remove checklist | REM-06 | Technical detail in the body (vulnerability identifiers, product names, network details) | Present | |||
| Remove checklist | REM-07 | Measures that answer no question the board asks | Present | |||
| Remove checklist | REM-08 | Figures that disagree with each other, or with the last report, without explanation | Absent | |||
| Remove checklist | REM-09 | General threat news or attacker statistics not linked to our own exposure | Present | |||
| Part result | Position | Points | 1 of 6 | Not yet serving the board | ||
| Part result | Direction | Points | 3 of 8 | Partly serving the board | ||
| Part result | Exposure | Points | 1 of 8 | Not yet serving the board | ||
| Part result | Ask | Points | 1 of 8 | Not yet serving the board | ||
| Part result | Measures | Points | 3 of 10 | Not yet serving the board | ||
| Part result | Process | Points | 1 of 8 | Not yet serving the board | ||
| Overall result | All parts | Points | 10 of 48 | Not yet serving the board | 8 of 9 present | |
| Add | POS-01 | Position | Open with one sentence stating the position — 'Within appetite', 'Outside appetite, within tolerance' or 'Outside tolerance' — and the main reason for it. | Absent | BR-02 · Essential | |
| Add | POS-02 | Position | Measure the position against the board's approved appetite and tolerance statement, using the count of risks outside appetite (BM-01). If there is no approved statement, make agreeing one your first ask. | Absent | BR-02 · Essential | |
| Add | EXP-01 | Exposure | Rewrite each top risk as: the service affected, the harm, and a cost range. Move the technical description to the appendix. | Absent | BR-05 · Essential | |
| Add | ASK-01 | Ask | End the report with each ask stated as a decision: what the board is asked to decide, note or fund. If nothing is needed, say so. | Absent | BR-06 · Essential | |
| Add | ASK-02 | Ask | For each ask, set out the realistic options (including doing nothing) and the recommended one, with the reason. | Absent | BR-06 · Essential | |
| Add | MEA-02 | Measures | Agree a target or tolerance for every measure before it reaches the board; a measure without one shows 'No target set' and should be removed at the next report. | Absent | BR-03 · Essential | |
| Add | DIR-01 | Direction | Show every headline measure's direction since the last report in words ('Better', 'Same' or 'Worse'), with the previous value. | Partly | BR-04 · Essential | |
| Add | DIR-03 | Direction | Report every significant problem in the first report after it is known, with what is being done, by whom and by when. | Partly | BR-07 · Essential | |
| Add | MEA-01 | Measures | Keep only measures that answer a board question; take them from the Board Metric Selection Catalogue and move the rest to operational reporting. | Partly | BR-03 · Essential | |
| Add | DIR-02 | Direction | Replace the activity list with the cause of each significant movement: what changed, and what it did to the risk. | Absent | BR-01 · Important | |
| Add | EXP-02 | Exposure | Give each top risk its likelihood in agreed words (Unlikely, Possible, Likely, Almost certain) and say whether it is within appetite. | Absent | BR-02 · Important | |
| Add | ASK-03 | Ask | State each ask's cost over a stated period, and the risk of not deciding. | Absent | BR-06 · Important | |
| Add | MEA-04 | Measures | Write every status in words. Keep colour only as a repeat of the words, so the report works in black and white and in the minutes. | Absent | BR-04 · Important | |
| Add | PRO-01 | Process | Restructure the report into the four parts: Position, Direction, Exposure, Ask, in that order. | Absent | BR-01 · Important | |
| Add | PRO-02 | Process | Move technical detail to an appendix and rewrite the body in terms of services, harm and money. | Absent | BR-05 · Important | |
| Add | POS-03 | Position | Follow the opening sentence with the few board measures that show the position, chosen from the Board Metric Selection Catalogue. | Partly | BR-03 · Important | |
| Add | ASK-04 | Ask | Add a short list of the board's open actions, each with owner, date and status, kept until closed. | Partly | BR-09 · Important | |
| Add | MEA-03 | Measures | Show value, target, direction and status side by side for every measure, with the status in words: 'On target', 'Below target, within tolerance', 'Outside tolerance' or 'No target set'. | Partly | BR-04 · Important | |
| Add | PRO-03 | Process | Collect every figure in the Board Reporting Data Collection Workbook and have it checked and signed off before the report is built. | Partly | BR-08 · Important | |
| Add | EXP-04 | Exposure | Report expired and high-risk exceptions (BM-03): what was accepted, by whom and until when. | Absent | BR-03 · Helpful | |
| Add | PRO-04 | Process | Repeat this self-check once a year, before the board's deep dive, and record the improvements. Schedule it in the Board & Executive Reporting Calendar. | Absent | BR-10 · Helpful | |
| Add | DIR-04 | Direction | Show delivery of the funded programme against the approved plan and budget (BM-07), and turn any slippage that needs a decision into an ask. | Partly | BR-03 · Helpful | |
| Add | EXP-03 | Exposure | Limit the body to the [[3 to 5]] risks that matter most; put the rest in the appendix. | Partly | BR-05 · Helpful | |
| Add | MEA-05 | Measures | Fix each measure's definition, flag any change in the report, and restate the previous figure on the new basis. | Partly | BR-08 · Helpful | |
| Remove | REM-01 | Raw counts without a target or tolerance (for example 'phishing emails blocked') | Remove it, or replace it with a board measure that has a target. | |||
| Remove | REM-02 | Status shown by colour alone (red, amber, green with no words) | Write the status in words: 'On target', 'Below target, within tolerance', 'Outside tolerance' or 'No target set'. | |||
| Remove | REM-03 | Jargon and unexplained acronyms in the body | Use plain words in the body; explain any term that must stay. | |||
| Remove | REM-04 | Lists of activity in place of movement and cause | State the movement in each measure and its cause. | |||
| Remove | REM-05 | Screenshots of security tools or dashboards | Put the one figure that matters in the board measure table; drop the screenshot. | |||
| Remove | REM-06 | Technical detail in the body (vulnerability identifiers, product names, network details) | Move it to the appendix, or leave it out. | |||
| Remove | REM-07 | Measures that answer no question the board asks | Move them to operational reporting. | |||
| Remove | REM-09 | General threat news or attacker statistics not linked to our own exposure | Keep only threats that change one of our top risks, and say how. |
Remove
Lists
| Score | ScoreName | PriorityName | PresentAbsent | ResultsMode | LevelName | LevelMeaning |
|---|---|---|---|---|---|---|
| 0 | Absent | Essential | Present | Example report | Not yet serving the board | The report tells the board what the security team did, not whether the organisation is within appetite or what the board must decide. Rebuild it on the four-part structure before refining anything. |
| 1 | Partly | Important | Absent | My report | Partly serving the board | Some of what the board needs is there, but a director has to dig for it, and some essentials are missing. Work down the list of content to add. |
| 2 | Fully | Helpful | Largely serving the board | The report supports governance. The remaining gaps are about consistency and follow-through. | ||
| N/A | Fully serving the board | The report meets every criterion. Keep it that way: repeat the check each year (BR-10). |
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Board report | The cyber risk paper the board or committee receives, with its one-page summary and appendices. |
| Criterion | One thing a board report should do, tied to a reporting rule (BR-nn) and scored 0, 1 or 2. |
| 0 — Absent | The report does not do this, or does it so rarely a director would not notice. |
| 1 — Partly | The report does this for some items or some of the time, or does it in a way a director has to work to find. |
| 2 — Fully | The report does this every time, where a director expects to find it. |
| N/A | The criterion cannot apply to this report. Left out of the points scored and the points available. |
| Priority — Essential | Without it the board cannot govern cyber risk from the report. Fix these first. |
| Priority — Important | The board can govern, but with more effort, less confidence or a weaker record. |
| Priority — Helpful | Makes a good report better. Fix once the essential and important criteria are in place. |
| Points | The sum of the scores, shown as 'x of y': points scored of the points available. |
| Not yet serving the board | Fewer than a third of the available points. The report tells the board what the security team did, not whether the organisation is within appetite or what the board must decide. Rebuild it on the four-part structure before refining anything. |
| Partly serving the board | At least a third, but fewer than two thirds, of the available points. Some of what the board needs is there, but a director has to dig for it, and some essentials are missing. Work down the list of content to add. |
| Largely serving the board | At least two thirds of the available points, but not all. The report supports governance. The remaining gaps are about consistency and follow-through. |
| Fully serving the board | Every available point. The report meets every criterion. Keep it that way: repeat the check each year (BR-10). |
| Position | Where the organisation stands against the risk appetite the board set, in one of three phrases: 'Within appetite', 'Outside appetite, within tolerance' or 'Outside tolerance'. |
| Measure status | A measure's status in words: On target — At or better than its target. Below target, within tolerance — Short of its target but inside the tolerance the board set; a plan and date are given. Outside tolerance — Beyond the limit at which the board said it must act, not just be told; an ask follows (BR-06). No target set — Reported without a target: it should not reach the board until one is set (BR-03). |
| Direction | Movement since the last report, in words: Better, Same or Worse. |
| Risk appetite | The amount and type of cyber risk the board is willing to accept in pursuit of its objectives. |
| Tolerance | The limit beyond which the board must act, not just be told. |
| Remove checklist | Things a board report should not carry. Anything answered Present goes on the list of content to remove. |
| Ranking key | A number the workbook uses to put the lists in order. Do not type over it. |
| BR-nn | A reporting rule in the Board Reporting Narrative Model. |
| BM-nn | A board measure in the Board Metric Selection Catalogue. |
| (calc) | A column or cell the workbook calculates. Do not type or paste over it. |
| EXAMPLE | The worked example: scores for a typical technical-status report. Results show it until you choose 'My report'. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 9.3 — Management review | The whole self-check: the quality of the information that reaches management review |
| ISO/IEC 27001:2022 | Clause 10.1 — Continual improvement | Results: content to add and content to remove; repeated once a year (BR-10) |
| NIST CSF 2.0 | ID.IM-01 — “Improvements are identified from evaluations” | Results: improvements identified from this evaluation |
| NIST CSF 2.0 | GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed” | Criteria POS-01 to POS-03, DIR-01 and the Measures group: performance reported so it can be evaluated |
| NIS2 — Directive (EU) 2022/2555 | Article 20(1) — management bodies approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements | Criteria in the Position, Exposure and Ask groups: what the management body needs to approve and oversee |
| DORA — Regulation (EU) 2022/2554 | Article 5(2) — the management body defines, approves, oversees and is responsible for the ICT risk management framework, bears ultimate responsibility for ICT risk and sets the risk tolerance | Criteria POS-02, EXP-02 and the Ask group: the management body's oversight against the risk tolerance it set |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA)