Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Board Reporting Effectiveness Self-Check

Scores an existing board report against what governance bodies need, and identifies the specific content to add or remove.

Available soon

Format
Excel
Size
71 KB
Length
11 sheets
Version
1.1
Updated

What's inside

  • Instructions
  • Criteria
  • Remove Checklist
  • Results
  • Export
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Scope: the last cyber report that went to the board or committee [[e.g. Board, or its Audit & Risk Committee]], including its one-page summary and appendices. Score what the board actually received, not what you intended. Ideally two people score it separately — the reporter and the executive sponsor or a board member — then agree.
2On the Criteria sheet, read the three descriptions for each criterion (columns F to H). Enter 0, 1 or 2 in column J (Your score) for the one that matches the report. If you are between two, choose the lower.
3Use N/A only where a criterion cannot apply, for example ASK-04 when this was the first report to the board. N/A is left out of both the points scored and the points available.
4Note the evidence for each score in column O (for example 'slide 4: no targets'). It makes next year's check faster and shows why you chose the score.
5On the Remove Checklist sheet, answer Present or Absent in column G for each item: is it in the report?
6On the Results sheet, change cell D5 from 'Example report' to 'My report'. The points, levels and both lists now describe your report.
7Work down the list of content to add from the top, and take out every item on the remove list. Rebuild the next report, then score it again.
8Copy the Export table (paste as values) into your records. Repeat the check once a year (BR-10), before the board's deep dive.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

The worked EXAMPLE. Column I of the Criteria sheet and column F of the Remove Checklist hold scores for a typical technical-status report: twelve slides assembled from security tools for the fictional organisation used across this pack (a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders) before it adopted this pack — counts of blocked attacks, patching percentages with no targets, a red-amber-green project list, a slide of industry threat news, no statement on appetite and a closing slide marked 'for information'. While Results cell D5 says 'Example report', every result is calculated from those columns and labelled EXAMPLE. To clear it, set D5 to 'My report'; to remove it completely, also delete Criteria cells I4 to I27 and Remove Checklist cells F4 to F12.

Score scale. 0 Absent: The report does not do this, or does it so rarely a director would not notice. 1 Partly: The report does this for some items or some of the time, or does it in a way a director has to work to find. 2 Fully: The report does this every time, where a director expects to find it.

Priority. Essential: Without it the board cannot govern cyber risk from the report. Fix these first. Important: The board can govern, but with more effort, less confidence or a weaker record. Helpful: Makes a good report better. Fix once the essential and important criteria are in place. Priority orders the list of content to add; it does not change the points.

Levels, from the points scored against the points available. Not yet serving the board: fewer than a third of the available points. Partly serving the board: at least a third, but fewer than two thirds, of the available points. Largely serving the board: at least two thirds of the available points, but not all. Fully serving the board: every available point. If any Essential criterion scores 0, the overall level is no higher than 'Partly serving the board', however well the rest scores. Results are never shown as a percentage.

Tailoring — small organisation: the report may be two pages rather than a deck, and the board may meet less often. The criteria still apply; for EXP-03 fewer top risks is fine, and PRO-03 can be a single signed-off spreadsheet.

Tailoring — regulated entity (NIS2 or DORA): the management body must approve and oversee cybersecurity risk management (NIS2 Article 20; DORA Article 5). Treat POS-02, DIR-03 and ASK-04 as evidence of oversight: keep the completed self-check and the improvement actions with the board papers.

Tailoring — IT run by a service provider: score the report the board receives, not the provider's own service report. Where the provider's figures reach the board, MEA-01 and PRO-03 test whether they have been turned into board measures and checked before use.

Limitations: see the foot of the Results sheet.

Criteria

Enter 0, 1 or 2 (or N/A) in column J for each criterion. Column I is the worked EXAMPLE. Columns K, L and P calculate; do not type in them.

IDGroupCriterionRulePriority0 — Absent1 — Partly2 — FullyExample score (EXAMPLE)Your scoreScore used (calc)In words (calc)What to add or change if 0 or 1Document that helpsNotes or evidenceAdd ranking key (calc)
POS-01PositionDoes the report open with a one-sentence answer to 'are we within appetite?'BR-02EssentialNo such sentence; the report opens with activity, threats or a dashboard.A summary opens the report, but it does not say whether the organisation is within appetite, or says so only later.The first sentence states the position in the pack's words ('Within appetite', 'Outside appetite, within tolerance' or 'Outside tolerance') and why.00AbsentOpen with one sentence stating the position — 'Within appetite', 'Outside appetite, within tolerance' or 'Outside tolerance' — and the main reason for it.Board Reporting Narrative Model3224
POS-02PositionIs the position judged against a risk appetite and tolerance the board has actually set?BR-02EssentialNo appetite or tolerance is referred to; 'good' and 'bad' are the reporter's opinion.An appetite is mentioned, but it is not the board's approved statement, or the report does not measure against it.The report names the board's appetite and tolerance statement and measures the top risks against it (BM-01).00AbsentMeasure the position against the board's approved appetite and tolerance statement, using the count of risks outside appetite (BM-01). If there is no approved statement, make agreeing one your first ask.Board Reporting Narrative Model3223
POS-03PositionIs the position supported by a few board measures straight after the opening sentence?BR-03ImportantNo measures support the position, or the report opens with dozens of figures.Measures are there but too many, or not the ones that show the position.A handful of board measures, drawn from the Board Metric Selection Catalogue, follow the opening sentence and support it.11PartlyFollow the opening sentence with the few board measures that show the position, chosen from the Board Metric Selection Catalogue.Board Metric Selection Catalogue2122
DIR-01DirectionDoes each headline measure show its movement since the last report?BR-04EssentialNo comparison with the last report.Some measures show a trend, or trends are shown only as arrows or colours.Every headline measure states its direction in words ('Better', 'Same' or 'Worse') with the previous value.11PartlyShow every headline measure's direction since the last report in words ('Better', 'Same' or 'Worse'), with the previous value.Board Reporting Data Collection Workbook3121
DIR-02DirectionDoes the report explain why things moved, rather than list what the team did?BR-01ImportantA list of activity ('we deployed', 'we ran') with no link to the measures.Some causes are given, mixed with activity lists.Each significant movement has its cause, in a sentence or two; activity appears only where it explains a movement.00AbsentReplace the activity list with the cause of each significant movement: what changed, and what it did to the risk.Board Reporting Narrative Model2220
DIR-03DirectionIs bad news reported in the first report after it was known, with what is being done and by when?BR-07EssentialBad news is left out, softened into activity, or reported only when asked.Bad news is reported, but late, or without the action and date.Every significant problem appears in the first report after it was known, with the action, the owner and the date.11PartlyReport every significant problem in the first report after it is known, with what is being done, by whom and by when.Board Reporting Narrative Model3119
DIR-04DirectionDoes the report show whether the security programme the board funded is on plan?BR-03HelpfulNo view of programme delivery, or only a list of projects.Project statuses are shown, but not against the plan and budget the board approved.Delivery is shown against the approved plan (BM-07), with slippage explained and any decision needed stated.11PartlyShow delivery of the funded programme against the approved plan and budget (BM-07), and turn any slippage that needs a decision into an ask.Board Metric Selection Catalogue1118
EXP-01ExposureAre the top risks described in business terms: which service, what harm, what it would cost?BR-05EssentialRisks are described as technical weaknesses or threats (vulnerability names, attack types).Some risks name the service or the harm, but not the likely cost.Each top risk names the service affected, the harm to the organisation and a cost range.00AbsentRewrite each top risk as: the service affected, the harm, and a cost range. Move the technical description to the appendix.Board Reporting Narrative Model3217
EXP-02ExposureDoes each top risk say how likely it is now, and whether it is within appetite?BR-02ImportantNo likelihood, or 'high/medium/low' with no meaning given.Likelihood is given, but without agreed words, or without saying whether the risk is within appetite.Each top risk has a likelihood in the pack's agreed words and its position against appetite.00AbsentGive each top risk its likelihood in agreed words (Unlikely, Possible, Likely, Almost certain) and say whether it is within appetite.Board Reporting Narrative Model2216
EXP-03ExposureIs the list of top risks short enough for the board to discuss?BR-05HelpfulNo list of top risks, or the full risk register.A list is given but too long to discuss in the time.[[3 to 5]] top risks, with the rest available in the appendix or the risk register.11PartlyLimit the body to the [[3 to 5]] risks that matter most; put the rest in the appendix.Cyber Risk One-Page Board Summary1115
EXP-04ExposureCan the board see where risk has been knowingly accepted, and whether those acceptances are still under control?BR-03HelpfulAccepted risks and exceptions are not mentioned.Exceptions are mentioned, but not whether any have expired or are high risk.Expired and high-risk exceptions are reported (BM-03), with who accepted them and until when.00AbsentReport expired and high-risk exceptions (BM-03): what was accepted, by whom and until when.Board Metric Selection Catalogue1214
ASK-01AskIs each ask stated as a decision the board must take: decide, note or fund?BR-06EssentialNo ask, or the report is 'for information' only.An ask is implied or buried in the text.Each ask is stated plainly at the end of the report as a decision to decide, note or fund.00AbsentEnd the report with each ask stated as a decision: what the board is asked to decide, note or fund. If nothing is needed, say so.Board Cybersecurity Report Deck Template3213
ASK-02AskDoes each ask give the options and the one recommended?BR-06EssentialNo options: the board is asked to approve a single course.Options are listed, but no recommendation, or the recommendation is not explained.Each ask sets out the realistic options and the recommended one, with the reason.00AbsentFor each ask, set out the realistic options (including doing nothing) and the recommended one, with the reason.Board Reporting Narrative Model3212
ASK-03AskDoes each ask state the cost and the risk of not deciding?BR-06ImportantNeither is given.One is given, or the cost is given without a period.Each ask states its cost over a stated period and what happens to the risk if the board does not decide.00AbsentState each ask's cost over a stated period, and the risk of not deciding.Board Reporting Narrative Model2211
ASK-04AskAre the board's actions from previous meetings reported until they are closed? (N/A for a first report.)BR-09ImportantPrevious actions are not mentioned.Some are mentioned, or they drop out before they are closed.Every open action has its owner, date and status, and stays in the report until closed.11PartlyAdd a short list of the board's open actions, each with owner, date and status, kept until closed.Board Cybersecurity Report Deck Template2110
MEA-01MeasuresDoes every measure in the body answer a question the board asks?BR-03EssentialMost measures are operational (for example emails blocked, scans run).Some measures answer a board question; others are there because they are available.Every measure answers a board question from the Board Metric Selection Catalogue.11PartlyKeep only measures that answer a board question; take them from the Board Metric Selection Catalogue and move the rest to operational reporting.Board Metric Selection Catalogue3109
MEA-02MeasuresDoes every measure have a stated target or tolerance?BR-03EssentialNo targets.Some measures have targets.Every measure shows its target or tolerance, agreed in advance.00AbsentAgree a target or tolerance for every measure before it reaches the board; a measure without one shows 'No target set' and should be removed at the next report.Board Metric Selection Catalogue3208
MEA-03MeasuresDoes each measure show its value, target, direction and status together?BR-04ImportantValues only.Some of the four, or spread across different pages.Value, target, direction and status sit side by side for every measure, the status in the pack's words ('On target', 'Below target, within tolerance', 'Outside tolerance' or 'No target set').11PartlyShow value, target, direction and status side by side for every measure, with the status in words: 'On target', 'Below target, within tolerance', 'Outside tolerance' or 'No target set'.Cyber Risk One-Page Board Summary2107
MEA-04MeasuresIs status always written in words, never shown by colour alone?BR-04ImportantRed, amber and green with no words.Words for some items; colour alone for others.Every status is in words; colour, if used, only repeats the words.00AbsentWrite every status in words. Keep colour only as a repeat of the words, so the report works in black and white and in the minutes.Cyber Risk One-Page Board Summary2206
MEA-05MeasuresAre measures defined the same way from one report to the next, so periods compare?BR-08HelpfulDefinitions change, or are not written down.Definitions are written down but changes are not flagged.Definitions are fixed; any change is flagged and the previous figure restated.11PartlyFix each measure's definition, flag any change in the report, and restate the previous figure on the new basis.Board Reporting Data Collection Workbook1105
PRO-01ProcessDoes the report follow Position, Direction, Exposure and Ask, in that order?BR-01ImportantNo recognisable structure, or one per team or tool.Some of the four parts, or in a different order each time.The four parts, in that order, every time.00AbsentRestructure the report into the four parts: Position, Direction, Exposure, Ask, in that order.Board Cybersecurity Report Deck Template2204
PRO-02ProcessIs technical detail kept in an appendix, so the body speaks of services, harm and money?BR-05ImportantThe body is technical throughout.Mostly business language, with technical sections in the body.The body is in business language; the technical detail is in an appendix for those who want it.00AbsentMove technical detail to an appendix and rewrite the body in terms of services, harm and money.Board Reporting Narrative Model2203
PRO-03ProcessDo all figures come from one data collection workbook, checked and signed off before the report is built?BR-08ImportantFigures are pulled from tools as the report is written.One source exists, but figures are not checked or signed off before the report is built.Every figure comes from one workbook, reconciled with its source and signed off before the report is built.11PartlyCollect every figure in the Board Reporting Data Collection Workbook and have it checked and signed off before the report is built.Board Reporting Data Collection Workbook2102
PRO-04ProcessIs the reporting itself reviewed once a year, and are the improvements tracked?BR-10HelpfulNever reviewed.Reviewed occasionally, or improvements are not followed through.Reviewed once a year with this self-check, with improvements recorded and checked at the next review.00AbsentRepeat this self-check once a year, before the board's deep dive, and record the improvements. Schedule it in the Board & Executive Reporting Calendar.Board & Executive Reporting Calendar1201

Remove Checklist

Is each of these in the report? Answer Present or Absent in column G. Column F is the worked EXAMPLE. Anything present goes on the remove list on the Results sheet.

IDWhat to look forWhy it hurtsRuleInsteadExample answer (EXAMPLE)Your answerAnswer used (calc)Notes or evidenceRemove ranking key (calc)
REM-01Raw counts without a target or tolerance (for example 'phishing emails blocked')A number with no target cannot be judged good or bad, and moves the discussion to the number.BR-03Remove it, or replace it with a board measure that has a target.PresentPresent9
REM-02Status shown by colour alone (red, amber, green with no words)Colour fails for readers with colour-vision deficiency, disappears in print and cannot be minuted.BR-04Write the status in words: 'On target', 'Below target, within tolerance', 'Outside tolerance' or 'No target set'.PresentPresent8
REM-03Jargon and unexplained acronyms in the bodyDirectors cannot challenge what they cannot follow, and stop reading.BR-05Use plain words in the body; explain any term that must stay.PresentPresent7
REM-04Lists of activity in place of movement and causeActivity says the team is busy, not whether the risk changed.BR-01State the movement in each measure and its cause.PresentPresent6
REM-05Screenshots of security tools or dashboardsThey show what a tool can display, not what the board needs to decide, and are rarely readable.BR-05Put the one figure that matters in the board measure table; drop the screenshot.PresentPresent5
REM-06Technical detail in the body (vulnerability identifiers, product names, network details)It hides the business point and can itself be sensitive if the papers leak.BR-05Move it to the appendix, or leave it out.PresentPresent4
REM-07Measures that answer no question the board asksEach one takes attention from the measures that matter.BR-03Move them to operational reporting.PresentPresent3
REM-08Figures that disagree with each other, or with the last report, without explanationOne wrong figure makes the board doubt all of them.BR-08Take every figure from the one signed-off workbook; explain any restatement.AbsentAbsent0
REM-09General threat news or attacker statistics not linked to our own exposureIt raises alarm without telling the board what to do about its own risk.BR-05Keep only threats that change one of our top risks, and say how.PresentPresent1

Results

Results

Points are shown as 'x of y': points scored of the points available, leaving out criteria scored N/A. Each level is in words. The two lists are generated from your scores.

Results from:Example report← choose 'My report' once you have scored the Criteria and the Remove Checklist.

EXAMPLE: these results are for the worked example, a typical technical-status report, not your report. Choose 'My report' in D5 to see your own.

Overall result

Points10 of 48Points scored of the points available (2 for each criterion not scored N/A).
LevelNot yet serving the boardThe report tells the board what the security team did, not whether the organisation is within appetite or what the board must decide. Rebuild it on the four-part structure before refining anything.
Items to remove8 of 9 presentThings in the report that should not be there. They do not change the points; take them out.

Result by part of the report

No.PartPointsLevelWhat the part asksPoints scoredPoints available
1Position1 of 6Not yet serving the boardWhere do we stand against the risk appetite the board set?16
2Direction3 of 8Partly serving the boardIs it getting better or worse, and why?38
3Exposure1 of 8Not yet serving the boardWhat could hurt us most, and how likely is it now?18
4Ask1 of 8Not yet serving the boardWhat do you need the board to decide, note or fund?18
5Measures3 of 10Not yet serving the boardDoes every figure earn its place, and can a director judge it at a glance?310
6Process1 of 8Not yet serving the boardIs the report built, checked and improved in a way the board can rely on?18

Content to add — most important first

#CriterionPartWhat to add or changeRule and priorityScore nowDocument that helpsRanking keyRow
1POS-01PositionOpen with one sentence stating the position — 'Within appetite', 'Outside appetite, within tolerance' or 'Outside tolerance' — and the main reason for it.BR-02 · EssentialAbsentBoard Reporting Narrative Model32241
2POS-02PositionMeasure the position against the board's approved appetite and tolerance statement, using the count of risks outside appetite (BM-01). If there is no approved statement, make agreeing one your first ask.BR-02 · EssentialAbsentBoard Reporting Narrative Model32232
3EXP-01ExposureRewrite each top risk as: the service affected, the harm, and a cost range. Move the technical description to the appendix.BR-05 · EssentialAbsentBoard Reporting Narrative Model32178
4ASK-01AskEnd the report with each ask stated as a decision: what the board is asked to decide, note or fund. If nothing is needed, say so.BR-06 · EssentialAbsentBoard Cybersecurity Report Deck Template321312
5ASK-02AskFor each ask, set out the realistic options (including doing nothing) and the recommended one, with the reason.BR-06 · EssentialAbsentBoard Reporting Narrative Model321213
6MEA-02MeasuresAgree a target or tolerance for every measure before it reaches the board; a measure without one shows 'No target set' and should be removed at the next report.BR-03 · EssentialAbsentBoard Metric Selection Catalogue320817
7DIR-01DirectionShow every headline measure's direction since the last report in words ('Better', 'Same' or 'Worse'), with the previous value.BR-04 · EssentialPartlyBoard Reporting Data Collection Workbook31214
8DIR-03DirectionReport every significant problem in the first report after it is known, with what is being done, by whom and by when.BR-07 · EssentialPartlyBoard Reporting Narrative Model31196
9MEA-01MeasuresKeep only measures that answer a board question; take them from the Board Metric Selection Catalogue and move the rest to operational reporting.BR-03 · EssentialPartlyBoard Metric Selection Catalogue310916
10DIR-02DirectionReplace the activity list with the cause of each significant movement: what changed, and what it did to the risk.BR-01 · ImportantAbsentBoard Reporting Narrative Model22205
11EXP-02ExposureGive each top risk its likelihood in agreed words (Unlikely, Possible, Likely, Almost certain) and say whether it is within appetite.BR-02 · ImportantAbsentBoard Reporting Narrative Model22169
12ASK-03AskState each ask's cost over a stated period, and the risk of not deciding.BR-06 · ImportantAbsentBoard Reporting Narrative Model221114
13MEA-04MeasuresWrite every status in words. Keep colour only as a repeat of the words, so the report works in black and white and in the minutes.BR-04 · ImportantAbsentCyber Risk One-Page Board Summary220619
14PRO-01ProcessRestructure the report into the four parts: Position, Direction, Exposure, Ask, in that order.BR-01 · ImportantAbsentBoard Cybersecurity Report Deck Template220421
15PRO-02ProcessMove technical detail to an appendix and rewrite the body in terms of services, harm and money.BR-05 · ImportantAbsentBoard Reporting Narrative Model220322
16POS-03PositionFollow the opening sentence with the few board measures that show the position, chosen from the Board Metric Selection Catalogue.BR-03 · ImportantPartlyBoard Metric Selection Catalogue21223
17ASK-04AskAdd a short list of the board's open actions, each with owner, date and status, kept until closed.BR-09 · ImportantPartlyBoard Cybersecurity Report Deck Template211015
18MEA-03MeasuresShow value, target, direction and status side by side for every measure, with the status in words: 'On target', 'Below target, within tolerance', 'Outside tolerance' or 'No target set'.BR-04 · ImportantPartlyCyber Risk One-Page Board Summary210718
19PRO-03ProcessCollect every figure in the Board Reporting Data Collection Workbook and have it checked and signed off before the report is built.BR-08 · ImportantPartlyBoard Reporting Data Collection Workbook210223
20EXP-04ExposureReport expired and high-risk exceptions (BM-03): what was accepted, by whom and until when.BR-03 · HelpfulAbsentBoard Metric Selection Catalogue121411
21PRO-04ProcessRepeat this self-check once a year, before the board's deep dive, and record the improvements. Schedule it in the Board & Executive Reporting Calendar.BR-10 · HelpfulAbsentBoard & Executive Reporting Calendar120124
22DIR-04DirectionShow delivery of the funded programme against the approved plan and budget (BM-07), and turn any slippage that needs a decision into an ask.BR-03 · HelpfulPartlyBoard Metric Selection Catalogue11187
23EXP-03ExposureLimit the body to the [[3 to 5]] risks that matter most; put the rest in the appendix.BR-05 · HelpfulPartlyCyber Risk One-Page Board Summary111510
24MEA-05MeasuresFix each measure's definition, flag any change in the report, and restate the previous figure on the new basis.BR-08 · HelpfulPartlyBoard Reporting Data Collection Workbook110520

Content to remove

#ItemWhat to look forRuleInsteadRanking keyRow
1REM-01Raw counts without a target or tolerance (for example 'phishing emails blocked')BR-03Remove it, or replace it with a board measure that has a target.91
2REM-02Status shown by colour alone (red, amber, green with no words)BR-04Write the status in words: 'On target', 'Below target, within tolerance', 'Outside tolerance' or 'No target set'.82
3REM-03Jargon and unexplained acronyms in the bodyBR-05Use plain words in the body; explain any term that must stay.73
4REM-04Lists of activity in place of movement and causeBR-01State the movement in each measure and its cause.64
5REM-05Screenshots of security tools or dashboardsBR-05Put the one figure that matters in the board measure table; drop the screenshot.55
6REM-06Technical detail in the body (vulnerability identifiers, product names, network details)BR-05Move it to the appendix, or leave it out.46
7REM-07Measures that answer no question the board asksBR-03Move them to operational reporting.37
8REM-09General threat news or attacker statistics not linked to our own exposureBR-05Keep only threats that change one of our top risks, and say how.19

9

How the results are worked out

1. Points: each criterion scores 0, 1 or 2; N/A and blank are left out. Points available = 2 × the criteria scored. A part's points and the overall points are shown as 'x of y'.

2. Level: 'Not yet serving the board' for fewer than a third of the available points; 'Partly serving the board' for at least a third, but fewer than two thirds, of the available points; 'Largely serving the board' for at least two thirds of the available points, but not all; 'Fully serving the board' for every available point. Overall, if any Essential criterion scores 0 the level is held at or below 'Partly serving the board'.

3. Content to add: every criterion scored 0 or 1, ordered by priority (Essential, then Important, then Helpful), then by score (Absent before Partly), then by the order of the criteria. The ranking key on the Criteria sheet encodes this order.

4. Content to remove: every checklist item answered Present, in checklist order.

Limitations

This is a self-check of one report by the people who wrote it. It is only as honest as the scores; a second scorer, ideally a board member, is the best check.

It tests whether the report gives the board what it needs to govern, not whether the organisation's security is good. A well-written report can describe a poor position — that is its job.

The criteria follow the pack's reporting rules (BR-01 to BR-10). They are not a benchmark, and the level cannot be compared with other organisations or with any certification requirement.

It does not assess the meeting itself — how the board discussed the report or what it decided — beyond whether earlier actions are followed up (ASK-04).

Export

Every score and result in one table. Select the table, copy, and paste as values into your records. Everything here is calculated; do not type in it.

SectionRefPartItemScore or pointsIn wordsDetail
SourceScores usedExample reportEXAMPLE: these results are for the worked example, a typical technical-status report, not your report. Choose 'My report' in D5 to see your own.
CriterionPOS-01PositionDoes the report open with a one-sentence answer to 'are we within appetite?'0Absent
CriterionPOS-02PositionIs the position judged against a risk appetite and tolerance the board has actually set?0Absent
CriterionPOS-03PositionIs the position supported by a few board measures straight after the opening sentence?1Partly
CriterionDIR-01DirectionDoes each headline measure show its movement since the last report?1Partly
CriterionDIR-02DirectionDoes the report explain why things moved, rather than list what the team did?0Absent
CriterionDIR-03DirectionIs bad news reported in the first report after it was known, with what is being done and by when?1Partly
CriterionDIR-04DirectionDoes the report show whether the security programme the board funded is on plan?1Partly
CriterionEXP-01ExposureAre the top risks described in business terms: which service, what harm, what it would cost?0Absent
CriterionEXP-02ExposureDoes each top risk say how likely it is now, and whether it is within appetite?0Absent
CriterionEXP-03ExposureIs the list of top risks short enough for the board to discuss?1Partly
CriterionEXP-04ExposureCan the board see where risk has been knowingly accepted, and whether those acceptances are still under control?0Absent
CriterionASK-01AskIs each ask stated as a decision the board must take: decide, note or fund?0Absent
CriterionASK-02AskDoes each ask give the options and the one recommended?0Absent
CriterionASK-03AskDoes each ask state the cost and the risk of not deciding?0Absent
CriterionASK-04AskAre the board's actions from previous meetings reported until they are closed? (N/A for a first report.)1Partly
CriterionMEA-01MeasuresDoes every measure in the body answer a question the board asks?1Partly
CriterionMEA-02MeasuresDoes every measure have a stated target or tolerance?0Absent
CriterionMEA-03MeasuresDoes each measure show its value, target, direction and status together?1Partly
CriterionMEA-04MeasuresIs status always written in words, never shown by colour alone?0Absent
CriterionMEA-05MeasuresAre measures defined the same way from one report to the next, so periods compare?1Partly
CriterionPRO-01ProcessDoes the report follow Position, Direction, Exposure and Ask, in that order?0Absent
CriterionPRO-02ProcessIs technical detail kept in an appendix, so the body speaks of services, harm and money?0Absent
CriterionPRO-03ProcessDo all figures come from one data collection workbook, checked and signed off before the report is built?1Partly
CriterionPRO-04ProcessIs the reporting itself reviewed once a year, and are the improvements tracked?0Absent
Remove checklistREM-01Raw counts without a target or tolerance (for example 'phishing emails blocked')Present
Remove checklistREM-02Status shown by colour alone (red, amber, green with no words)Present
Remove checklistREM-03Jargon and unexplained acronyms in the bodyPresent
Remove checklistREM-04Lists of activity in place of movement and causePresent
Remove checklistREM-05Screenshots of security tools or dashboardsPresent
Remove checklistREM-06Technical detail in the body (vulnerability identifiers, product names, network details)Present
Remove checklistREM-07Measures that answer no question the board asksPresent
Remove checklistREM-08Figures that disagree with each other, or with the last report, without explanationAbsent
Remove checklistREM-09General threat news or attacker statistics not linked to our own exposurePresent
Part resultPositionPoints1 of 6Not yet serving the board
Part resultDirectionPoints3 of 8Partly serving the board
Part resultExposurePoints1 of 8Not yet serving the board
Part resultAskPoints1 of 8Not yet serving the board
Part resultMeasuresPoints3 of 10Not yet serving the board
Part resultProcessPoints1 of 8Not yet serving the board
Overall resultAll partsPoints10 of 48Not yet serving the board8 of 9 present
AddPOS-01PositionOpen with one sentence stating the position — 'Within appetite', 'Outside appetite, within tolerance' or 'Outside tolerance' — and the main reason for it.AbsentBR-02 · Essential
AddPOS-02PositionMeasure the position against the board's approved appetite and tolerance statement, using the count of risks outside appetite (BM-01). If there is no approved statement, make agreeing one your first ask.AbsentBR-02 · Essential
AddEXP-01ExposureRewrite each top risk as: the service affected, the harm, and a cost range. Move the technical description to the appendix.AbsentBR-05 · Essential
AddASK-01AskEnd the report with each ask stated as a decision: what the board is asked to decide, note or fund. If nothing is needed, say so.AbsentBR-06 · Essential
AddASK-02AskFor each ask, set out the realistic options (including doing nothing) and the recommended one, with the reason.AbsentBR-06 · Essential
AddMEA-02MeasuresAgree a target or tolerance for every measure before it reaches the board; a measure without one shows 'No target set' and should be removed at the next report.AbsentBR-03 · Essential
AddDIR-01DirectionShow every headline measure's direction since the last report in words ('Better', 'Same' or 'Worse'), with the previous value.PartlyBR-04 · Essential
AddDIR-03DirectionReport every significant problem in the first report after it is known, with what is being done, by whom and by when.PartlyBR-07 · Essential
AddMEA-01MeasuresKeep only measures that answer a board question; take them from the Board Metric Selection Catalogue and move the rest to operational reporting.PartlyBR-03 · Essential
AddDIR-02DirectionReplace the activity list with the cause of each significant movement: what changed, and what it did to the risk.AbsentBR-01 · Important
AddEXP-02ExposureGive each top risk its likelihood in agreed words (Unlikely, Possible, Likely, Almost certain) and say whether it is within appetite.AbsentBR-02 · Important
AddASK-03AskState each ask's cost over a stated period, and the risk of not deciding.AbsentBR-06 · Important
AddMEA-04MeasuresWrite every status in words. Keep colour only as a repeat of the words, so the report works in black and white and in the minutes.AbsentBR-04 · Important
AddPRO-01ProcessRestructure the report into the four parts: Position, Direction, Exposure, Ask, in that order.AbsentBR-01 · Important
AddPRO-02ProcessMove technical detail to an appendix and rewrite the body in terms of services, harm and money.AbsentBR-05 · Important
AddPOS-03PositionFollow the opening sentence with the few board measures that show the position, chosen from the Board Metric Selection Catalogue.PartlyBR-03 · Important
AddASK-04AskAdd a short list of the board's open actions, each with owner, date and status, kept until closed.PartlyBR-09 · Important
AddMEA-03MeasuresShow value, target, direction and status side by side for every measure, with the status in words: 'On target', 'Below target, within tolerance', 'Outside tolerance' or 'No target set'.PartlyBR-04 · Important
AddPRO-03ProcessCollect every figure in the Board Reporting Data Collection Workbook and have it checked and signed off before the report is built.PartlyBR-08 · Important
AddEXP-04ExposureReport expired and high-risk exceptions (BM-03): what was accepted, by whom and until when.AbsentBR-03 · Helpful
AddPRO-04ProcessRepeat this self-check once a year, before the board's deep dive, and record the improvements. Schedule it in the Board & Executive Reporting Calendar.AbsentBR-10 · Helpful
AddDIR-04DirectionShow delivery of the funded programme against the approved plan and budget (BM-07), and turn any slippage that needs a decision into an ask.PartlyBR-03 · Helpful
AddEXP-03ExposureLimit the body to the [[3 to 5]] risks that matter most; put the rest in the appendix.PartlyBR-05 · Helpful
AddMEA-05MeasuresFix each measure's definition, flag any change in the report, and restate the previous figure on the new basis.PartlyBR-08 · Helpful
RemoveREM-01Raw counts without a target or tolerance (for example 'phishing emails blocked')Remove it, or replace it with a board measure that has a target.
RemoveREM-02Status shown by colour alone (red, amber, green with no words)Write the status in words: 'On target', 'Below target, within tolerance', 'Outside tolerance' or 'No target set'.
RemoveREM-03Jargon and unexplained acronyms in the bodyUse plain words in the body; explain any term that must stay.
RemoveREM-04Lists of activity in place of movement and causeState the movement in each measure and its cause.
RemoveREM-05Screenshots of security tools or dashboardsPut the one figure that matters in the board measure table; drop the screenshot.
RemoveREM-06Technical detail in the body (vulnerability identifiers, product names, network details)Move it to the appendix, or leave it out.
RemoveREM-07Measures that answer no question the board asksMove them to operational reporting.
RemoveREM-09General threat news or attacker statistics not linked to our own exposureKeep only threats that change one of our top risks, and say how.

Remove

Lists

ScoreScoreNamePriorityNamePresentAbsentResultsModeLevelNameLevelMeaning
0AbsentEssentialPresentExample reportNot yet serving the boardThe report tells the board what the security team did, not whether the organisation is within appetite or what the board must decide. Rebuild it on the four-part structure before refining anything.
1PartlyImportantAbsentMy reportPartly serving the boardSome of what the board needs is there, but a director has to dig for it, and some essentials are missing. Work down the list of content to add.
2FullyHelpfulLargely serving the boardThe report supports governance. The remaining gaps are about consistency and follow-through.
N/AFully serving the boardThe report meets every criterion. Keep it that way: repeat the check each year (BR-10).

Definitions

Definitions

TermMeaning in this workbook
Board reportThe cyber risk paper the board or committee receives, with its one-page summary and appendices.
CriterionOne thing a board report should do, tied to a reporting rule (BR-nn) and scored 0, 1 or 2.
0 — AbsentThe report does not do this, or does it so rarely a director would not notice.
1 — PartlyThe report does this for some items or some of the time, or does it in a way a director has to work to find.
2 — FullyThe report does this every time, where a director expects to find it.
N/AThe criterion cannot apply to this report. Left out of the points scored and the points available.
Priority — EssentialWithout it the board cannot govern cyber risk from the report. Fix these first.
Priority — ImportantThe board can govern, but with more effort, less confidence or a weaker record.
Priority — HelpfulMakes a good report better. Fix once the essential and important criteria are in place.
PointsThe sum of the scores, shown as 'x of y': points scored of the points available.
Not yet serving the boardFewer than a third of the available points. The report tells the board what the security team did, not whether the organisation is within appetite or what the board must decide. Rebuild it on the four-part structure before refining anything.
Partly serving the boardAt least a third, but fewer than two thirds, of the available points. Some of what the board needs is there, but a director has to dig for it, and some essentials are missing. Work down the list of content to add.
Largely serving the boardAt least two thirds of the available points, but not all. The report supports governance. The remaining gaps are about consistency and follow-through.
Fully serving the boardEvery available point. The report meets every criterion. Keep it that way: repeat the check each year (BR-10).
PositionWhere the organisation stands against the risk appetite the board set, in one of three phrases: 'Within appetite', 'Outside appetite, within tolerance' or 'Outside tolerance'.
Measure statusA measure's status in words: On target — At or better than its target. Below target, within tolerance — Short of its target but inside the tolerance the board set; a plan and date are given. Outside tolerance — Beyond the limit at which the board said it must act, not just be told; an ask follows (BR-06). No target set — Reported without a target: it should not reach the board until one is set (BR-03).
DirectionMovement since the last report, in words: Better, Same or Worse.
Risk appetiteThe amount and type of cyber risk the board is willing to accept in pursuit of its objectives.
ToleranceThe limit beyond which the board must act, not just be told.
Remove checklistThings a board report should not carry. Anything answered Present goes on the list of content to remove.
Ranking keyA number the workbook uses to put the lists in order. Do not type over it.
BR-nnA reporting rule in the Board Reporting Narrative Model.
BM-nnA board measure in the Board Metric Selection Catalogue.
(calc)A column or cell the workbook calculates. Do not type or paste over it.
EXAMPLEThe worked example: scores for a typical technical-status report. Results show it until you choose 'My report'.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 9.3 — Management reviewThe whole self-check: the quality of the information that reaches management review
ISO/IEC 27001:2022Clause 10.1 — Continual improvementResults: content to add and content to remove; repeated once a year (BR-10)
NIST CSF 2.0ID.IM-01 — “Improvements are identified from evaluations”Results: improvements identified from this evaluation
NIST CSF 2.0GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed”Criteria POS-01 to POS-03, DIR-01 and the Measures group: performance reported so it can be evaluated
NIS2 — Directive (EU) 2022/2555Article 20(1) — management bodies approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringementsCriteria in the Position, Exposure and Ask groups: what the management body needs to approve and oversee
DORA — Regulation (EU) 2022/2554Article 5(2) — the management body defines, approves, oversees and is responsible for the ICT risk management framework, bears ultimate responsibility for ICT risk and sets the risk toleranceCriteria POS-02, EXP-02 and the Ask group: the management body's oversight against the risk tolerance it set

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA)