Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Board Reporting Narrative Model

Provides the reporting structure that turns metrics into a decision-oriented narrative: position, direction, exposure, ask.

Available soon

Format
Word
Size
68 KB
Length
21 pages
Version
1.1
Updated

What's inside

  • Purpose
  • Principles
  • Inputs
  • The four parts
  • The reporting rules
  • Scales and criteria
  • Decision logic
  • Worked examples
  • Common failure modes
  • How to defend the method to an auditor
  • Limitations
  • Calibration and review
  • Related documents
  • Adapting this template
  • Framework references
  • Definitions

Preview

The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.

Purpose

This model sets out how [[Organisation Name]] reports cyber risk to its [[board or committee]]. It turns measures and events into a short narrative the board can govern with: where we stand against the risk appetite the board set, which way it is moving, what could hurt us most, and what the board needs to decide.

Why a board needs governance, not status

Most cyber reports that reach a board are status reports: what the security team did, how many alerts it handled, which projects are green. They answer the question 'is the security team busy?' The board is asking a different one: 'are we exposed to more risk than we agreed to carry, and what must we decide about it?'

A board cannot manage the security team's work, and should not try. What it can do is set the level of risk the organisation will accept, check that the organisation stays within it, and decide when it does not — to fund, to change priority, or to accept a risk openly. A report that does not help it do those three things uses its time without informing its judgement.

In many organisations the directors also carry personal accountability for cyber risk. Under NIS2 and DORA, the management body approves the risk-management measures, oversees them, and can be held responsible for failures. A director who received a year of status reports and no clear statement of exposure has little to show that they exercised oversight.

This model is used by every other document in the Board Cybersecurity Reporting pack. The Board Cybersecurity Report Deck Template and the Cyber Risk One-Page Board Summary follow its structure; the Board Metric Selection Catalogue supplies its measures; the Board Reporting Data Collection Workbook holds its figures; the Board Question Bank & Preparation Brief prepares the reporter to defend it.

Guidance — delete before approval

Approve this model once, then use it unchanged for at least four reports. A structure that changes every quarter cannot show direction, and the board will not learn where to look.

If the board has never agreed a cyber risk appetite, the first report under this model should say so in its Position and make agreeing one its first Ask. See 'Stating the position against appetite and tolerance'.

Principles

Six principles sit under the four parts and the ten rules. Most questions about why a report is written the way it is are answered by one of them.

  1. Answer the board's questions, not the team's. The board asks whether the organisation is within appetite, whether that is changing, what could hurt it and what it must decide. Everything in the body of the report answers one of those four.
  2. Judgement first, evidence second. Each part opens with the conclusion in a sentence, then the few facts that support it. A director who reads only the first sentence of each part should still know the position.
  3. Business terms in the body; technical terms in the appendix. Services, harm, money and likelihood — not systems, vulnerabilities and tools.
  4. Every number has a target and a direction. A number the board cannot judge is noise.
  5. Bad news travels fastest. The board hears it from the reporter, early, with what is being done about it.
  6. The same shape every time. A board that sees the same four parts each quarter learns to read them in minutes, and notices at once when something has moved.

Inputs

The narrative is written from a small set of inputs, collected in the Board Reporting Data Collection Workbook and checked and signed off 15 working days before the board meeting (BR-08). A report is not drafted from memory or from figures collected separately.

Input

What the narrative uses it for

Where it comes from

The board's risk appetite statement

The yardstick for Position. Without it there is no Position to report.

[[Board-approved risk appetite statement, with date]]

BM-01 Risks outside appetite

Are we within the risk appetite we set?

Risk register

BM-02 Critical exposure fixed on time

Are the weaknesses attackers use being closed fast enough?

Vulnerability remediation tracker (P01)

BM-03 Expired or high-risk exceptions

Where have we knowingly accepted risk, and is it still under control?

Security exception register (P02)

BM-04 Significant incidents and time to contain

Have we been hurt, and how quickly did we recover?

Incident log

BM-05 Critical suppliers assessed

Are the suppliers we depend on held to our standard?

Third-party register

BM-06 Critical services restored in tests

Could we recover our most important services, and have we proved it?

Recovery test records

BM-07 Security programme delivery

Is the plan the board funded being delivered?

Programme plan

BM-08 Board and staff security training

Do we, and our people, know enough to judge and act on cyber risk?

Training records

The previous report and its action log

Direction, and the actions the board is owed an update on (BR-09).

Board papers and minutes

Events since the last report

Anything the board should hear about first: incidents, supplier failures, regulator contact, audit findings (BR-07).

Incident log; [[compliance and legal]]

The measures are the Board Metric Selection Catalogue's. A report uses the ones that answer a question this board asks and have a target (BR-03); it does not have to use all eight, and it should not add others without the same test.

Guidance — delete before approval

If a figure is not available in time for the sign-off, report it as 'not available', say why and when it will be. Never estimate a figure in the body of a board report without labelling it as an estimate.

The four parts

Every report — the deck, the one-page summary, a written paper, an out-of-cycle note — has four parts, in this order (BR-01).

Part

The question it answers

What it contains

Position

Where do we stand against the risk appetite the board set?

One sentence, then the few measures that show it.

Direction

Is it getting better or worse, and why?

Movement since the last report, with the cause — not a list of activity.

Exposure

What could hurt us most, and how likely is it now?

The top risks in business terms: which service, what harm, what it would cost.

Ask

What do you need the board to decide, note or fund?

Each ask stated as a decision, with its options and the recommended one.

The four parts are short. In a quarterly report the body is typically [[four to six]] slides or [[two]] pages of text; everything else goes in an appendix (BR-05).

Position

Answers: Where do we stand against the risk appetite the board set? Opens with the one-sentence answer that BR-02 requires, using one of the three position statements (see 'Stating the position against appetite and tolerance'). Then the measures that support it, each with its value, target, direction and status in words (BR-04). BM-01 Risks outside appetite is always one of them.

Weak

Strong (EXAMPLE)

"Overall security posture remains amber, with good progress across most workstreams."

"We are outside our cyber risk appetite on 2 of 12 top risks, both within tolerance, and we expect to be back within appetite by the end of Q4 2026 if the board approves today's decision."

A dashboard of 20 coloured tiles, with no targets.

A few measures, each with value, target, direction and a status word — for example: "Critical exposure fixed on time: 81% against a target of 95% within 14 calendar days; worse (was 90%); below target, within tolerance."

A measure's status is always one of four words (BR-04). Colour may sit beside the word, never replace it.

Status

Means

On target

At or better than its target.

Below target, within tolerance

Short of its target but inside the tolerance the board set; a plan and date are given.

Outside tolerance

Beyond the limit at which the board said it must act, not just be told; an ask follows (BR-06).

No target set

Reported without a target: it should not reach the board until one is set (BR-03).

Direction

Answers: Is it getting better or worse, and why? Contains what has moved since the last report and why it moved. A cause, not a list of activity: "worse because a supplier's delay left 40 servers unpatched for six weeks", not "we have continued to progress remediation".

Weak

Strong (EXAMPLE)

"This quarter we completed the network segmentation project, deployed a new endpoint tool and ran two phishing exercises."

"Better overall: one risk returned within appetite after the warehouse network was separated from the office network."

"Metrics are broadly stable."

"Worse on fixing critical weaknesses (81%, was 90%) because the ordering platform team lost two engineers."

Exposure

Answers: What could hurt us most, and how likely is it now? Contains the [[three to five]] top risks, each stated in business terms: which service, what harm, what it would cost, how likely it is now (see 'Expressing risk in business terms'), and where it stands against appetite. Show movement since last time. A risk that has left the list says so, with the reason.

Weak

Strong (EXAMPLE)

"Top risks: ransomware; phishing; third-party risk; insider threat; cloud misconfiguration."

"Online ordering unavailable for more than 2 days after ransomware. Loss of about €1.2m of orders per week; customer contracts breached. Likelihood: Possible. Outside appetite, within tolerance."

"Third-party risk remains elevated."

"Payment fraud through a compromised supplier email account. Single losses of €50k to €400k; not recoverable once paid. Likelihood: Likely. Outside appetite, within tolerance."

Ask

Answers: What do you need the board to decide, note or fund? Contains each decision the board is asked to take, written as BR-06 requires: the options, the recommended one, the cost and the risk of not deciding. Then anything the board is asked to note, kept separate from what it must decide. If there is nothing to decide, the report says "No decision is needed this quarter" — it does not invent one.

Weak

Strong (EXAMPLE)

"We need more investment in security."

"Approve €180,000 to rebuild the ordering platform's recovery so it can be restored within 24 hours?

A: approve now, done by 15 Dec 2026.

B: approve half now for backup isolation only, and the rest in the next budget.

C: do not approve; accept the risk.

Recommended: A. It brings the ransomware risk back within appetite this year and is about 15% of one week's lost orders.

Cost: €180,000 one-off, plus about €20,000 a year to run.

If we do not decide: The ransomware risk stays outside appetite into 2027. A 2-day outage would cost about €1.2m per week of orders lost, plus contract penalties."

"The board is asked to note the report."

"The board is asked to decide one matter (above) and to note the incident reported to the chair during the quarter."

A status update rewritten as a governance narrative

The same EXAMPLE quarter, reported two ways. The left column is typical of a first board report. The right column uses the same facts, and nothing else.

Technical status update

Governance narrative (EXAMPLE)

Security update Q3

• 1,243 vulnerabilities patched

• Endpoint detection on 94% of devices

• 2.1 million phishing emails blocked

• Ransomware on 14 office PCs, cleaned up

• Warehouse network segmentation project complete

• Two vacancies in the ordering platform team

• Overall status: AMBER

Position. We are outside our cyber risk appetite on 2 of 12 top risks, both within tolerance, and we expect to be back within appetite by the end of Q4 2026 if the board approves today's decision.

Direction. Better overall: one risk returned within appetite after the warehouse network was separated from the office network. Worse on fixing critical weaknesses (81%, was 90%) because the ordering platform team lost two engineers.

Exposure. Online ordering unavailable for more than 2 days after ransomware. Loss of about €1.2m of orders per week; customer contracts breached. Likelihood: Possible. Outside appetite, within tolerance.

Ask. Approve €180,000 to rebuild the ordering platform's recovery so it can be restored within 24 hours? Recommended: A. It brings the ransomware risk back within appetite this year and is about 15% of one week's lost orders.

What changed: the counts of activity went to the appendix; the segmentation project became a risk returned within appetite; the two vacancies became the cause of slower fixing; the ransomware on office PCs became a reason to fund the recovery of the ordering platform; 'amber' became a position against appetite in words; and the report ends with a decision instead of a colour.

The reporting rules

Ten rules apply to every board report and every document in the pack. Each is followed by the reason for it: a rule applied without its reason is soon applied badly.

BR-01 Every report follows Position, Direction, Exposure, Ask, in that order.

Why: A fixed order teaches the board where to look, and it makes every report answer the same four questions, so two quarters can be compared. The order runs from judgement to decision: by the time the ask arrives, the board already knows the position, the trend and the exposure it is being asked to act on.

BR-02 Every report opens with a one-sentence answer to 'are we within appetite?'.

Why: The board set the risk appetite, so whether the organisation is within it is the one question only the board owns. Many directors read the first line closely and skim the rest. A reporter who cannot answer the question in one sentence does not yet know the answer, and the report is not ready.

BR-03 A measure reaches the board only if it answers a question the board asks and has a stated target or tolerance (see the Board Metric Selection Catalogue).

Why: Every extra number competes for the same few minutes of attention. A measure with no target cannot be judged good or bad, so it invites 'so what?' and moves the discussion to the measure instead of the risk. The Board Metric Selection Catalogue lists the measures that pass this test.

BR-04 Each measure shows its value, its target, its direction since last time and a status in words — never colour alone.

Why: A value means nothing without its target, and a single value hides whether things are improving. Status is written in words because colour fails for readers with colour-vision deficiency, disappears when papers are printed in black and white, and cannot be recorded in the minutes.

BR-05 Technical detail goes in an appendix; the body speaks of services, harm and money.

Why: Directors are accountable for outcomes: whether customers are served, whether the organisation stays within the law, what it costs. Technical detail moves the discussion to things they cannot judge and hides the business point. The appendix keeps the detail for the director who wants it and for the auditor.

BR-06 Every ask is a decision with options, a recommendation, cost and the risk of not deciding.

Why: A board acts by deciding. An ask with no options is a request to approve, and an ask with no cost cannot be weighed against other uses of the money. Stating the risk of not deciding makes a deferral a visible choice, recorded as such, rather than a quiet default.

BR-07 Bad news is reported in the first report after it is known, with what is being done and by when.

Why: Boards lose trust through surprise, not through bad news. A problem the board hears about late, or from someone else, makes every later report less credible. Directors of regulated entities also have duties that depend on being told in time.

BR-08 All figures come from one data collection workbook, checked and signed off before the deck is built.

Why: Figures that change between meetings, or disagree between the deck and the one-page summary, destroy confidence in all of them. One checked source makes every figure reproducible, which is also what an auditor tests first.

BR-09 Actions the board agrees are recorded, owned and reported on at the next meeting until closed.

Why: A decision that is never followed up teaches the board that its decisions do not matter. The action log is also the evidence that the board oversees cyber risk rather than simply hearing about it.

BR-10 The reporting itself is reviewed once a year against the Board Reporting Effectiveness Self-Check.

Why: Reporting is a control like any other and decays the same way: measures stop answering the questions the board now asks, and reports grow. A yearly check catches the drift before the board stops reading.

Guidance — delete before approval

BR-08 names one workbook as the source of every figure. That is the Board Reporting Data Collection Workbook. BR-10 names the Board Reporting Effectiveness Self-Check. If you use your own equivalents, change the document names here, not the rules.

Scales and criteria

Expressing risk in business terms

Every risk in the body of the report is stated in four elements. A risk that cannot be written this way is not yet understood well enough to put in front of the board.

Element

The question

Write it as

Not as

Service

What would stop or be damaged?

A service a customer, regulator or board member recognises: online ordering, payroll, patient records, the payment run.

A system name, a server, a network segment.

Harm

To whom, and how?

What happens to customers, operations, legal position or reputation: cannot ship, personal data exposed, regulatory notification, breach of contract.

"Confidentiality, integrity and availability impact: high."

Money

Roughly what would it cost?

A range, with its basis: "€[[1–3]] million: orders lost at about €[[x]] a day for [[3–7]] days, plus recovery and contract penalties."

A precise figure with no basis, or no figure at all.

Likelihood

How likely, now?

One of the likelihood words below, with its movement since last time.

"Medium", "elevated", "significant" — words with no agreed meaning.

The likelihood words below give each word a stated meaning. Use the scale in your risk register if it has one; the words here are for organisations that do not.

Word

Means

Typical of

Unlikely

less than [[20]]% in the next 12 months

Not seen at organisations like ours in recent years, or only with rare skill or access.

Possible

[[20]]% to [[50]]% in the next 12 months

Happens regularly to organisations like ours; our controls make it harder but not rare.

Likely

[[50]]% to [[90]]% in the next 12 months

Happening now to organisations like ours, or has happened to us, and the gap is still open.

Almost certain

more than [[90]]% in the next 12 months, or already happening

Being attempted against us now, with little in the way.

Money is a range, never a point. State the low and the high, and how they were reached: lost revenue or margin per day of outage multiplied by a credible number of days; the cost of recovery and outside help; contractual penalties; likely regulatory fines where the law sets them. Agree the per-day figures with [[the finance function]] once a year so the board is not surprised by them. Where the organisation cannot reasonably put a figure on the harm — patient safety, for example — say so and describe the harm instead.

Guidance — delete before approval

Keep one sentence per risk in the body. The four elements fit into it: 'If [[event]] stopped [[service]], [[harm]], costing about [[range]]. Likelihood: [[word]] ([[movement]]).'

Do not multiply likelihood by money to get a single 'expected loss'. The board needs to see a rare, severe risk and a likely, small one as different things.

Stating the position against appetite and tolerance

Risk appetite is the amount and kind of risk the board is willing to accept in pursuit of its objectives. Risk tolerance is the limit around it: the point beyond which the board has said it must act, not merely be told. Each top risk has its own tolerance limit. BM-01 (Risks outside appetite) records two counts: the top risks above appetite, and the top risks past their tolerance limit.

The position rule. Outside tolerance if any top risk is past its own tolerance limit; otherwise Outside appetite, within tolerance if any top risk is above appetite; otherwise Within appetite. The Position opens with the statement the rule gives:

Statement

When it applies

What the board does

Within appetite

Every top risk is assessed at or below the level of risk the board has said it is willing to accept.

Note. No decision is needed on the position.

Outside appetite, within tolerance

At least one top risk is above appetite but below the tolerance limit, with a plan and a date to bring it back.

Note the plan and date, or challenge them. Decide if the plan needs money or a change of priority.

Outside tolerance

At least one risk is above the tolerance limit: the point at which the board said it must act, not just be told.

Decide: fund or order treatment, accept the risk explicitly and record why, or change the appetite. Reported out of cycle if it happens between meetings.

The opening sentence then names the count and the movement:

"[[Organisation Name]] is [[within appetite / outside appetite, within tolerance / outside tolerance]]: [[n]] of our [[N]] top risks [[is / are]] above appetite ([[m]] last [[quarter]]), and [[none is / n are]] above tolerance."

Guidance — delete before approval

The statement is chosen from the risk register by the rule above, not from a feeling. One top risk past its tolerance limit makes the position 'Outside tolerance', however many others are within appetite and whatever the other measures say.

An appetite statement for cyber risk is usually a few sentences, for example: 'We accept no risk of losing customers' personal data through a known and unfixed weakness. We accept a risk of up to [[2]] days' loss of any critical service a year. We accept higher risk in trials of new services, if they hold no customer data.' Each sentence should allow a risk to be judged inside or outside it.

If there is no appetite statement, the Position says: 'The board has not yet set a cyber risk appetite, so we cannot say whether our exposure is acceptable.' The first Ask is then to agree one.

Decision logic

Writing an ask as a decision

An ask is complete when it has six parts (BR-06). A board member should be able to decide from the ask alone, without the rest of the report.

Part

What it states

The decision

One sentence, beginning with a verb the board can do: decide, approve, accept, set, choose.

Why now

The risk it addresses, in business terms, and why this meeting rather than the next.

Options

At least two real options, one of which may be to do nothing. For each: what it achieves, what it costs (once, and per year), and when it takes effect.

Recommendation

The option the reporter recommends, and the reason in a sentence.

Risk of not deciding

What stays true if the board defers: which risk stays where, for how long, and whether that is inside appetite.

Who has agreed

Who has seen the ask before the meeting: the executive sponsor, [[the finance function]] for costs, [[legal]] where the law is involved.

Things the board is asked to note are not asks. Keep them in a separate short list after the decisions, so the board spends its time on what it must decide.

Do not ask the board to decide what management should. Choosing a product, a supplier or a project plan is management's decision. The board decides appetite, priority, money above management's authority, and risk acceptance above tolerance.

Reporting bad news

Bad news is reported in the first report after it is known, with what is being done and by when. Bad news includes a significant incident, a risk moving outside tolerance, a failed recovery test, a supplier failure, a missed commitment to the board, a regulator's enquiry, and a serious audit finding.

  1. Tell the chair first, and soon. Between meetings, an out-of-cycle note goes within [[5]] working days of a major incident or of any top risk moving outside its tolerance limit, to the chair (a move outside appetite but within tolerance waits for the next report). The executive sponsor agrees the note before it goes.
  2. Put it first. In the next full report, the bad news opens the Position, before any good news. It is not placed in the appendix or on the last slide.
  3. State it plainly. What happened, which service and whom it affected, what it cost or may cost, in the four elements of 'Expressing risk in business terms'.
  4. Say what is being done and by when. The actions, their owners and their dates, and how the board will know they have worked.
  5. Say what you do not yet know. And when you will know it. Never fill a gap with a guess (see the Board Question Bank & Preparation Brief).
  6. Take a decision if one is needed. If fixing it needs money, a change of priority or an acceptance of risk, put an Ask in the same report.

Guidance — delete before approval

A reporter who delivers bad news early and plainly is usually trusted more afterwards, not less. What damages trust is the board learning of a problem from the press, a regulator, a customer or an auditor.

Worked examples

The organisation, figures, costs and dates below are fictional EXAMPLE values, chosen to show the method. They are the same EXAMPLE quarter shown in the Board Cybersecurity Report Deck Template, the Cyber Risk One-Page Board Summary and the Board Reporting Data Collection Workbook. Amounts in the examples are in euros (€); use your own currency.

Example 1 — a full quarterly narrative (EXAMPLE)

The EXAMPLE firm is a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. Its board meets quarterly and has an Audit & Risk Committee. This is the body of its Q3 2026 report: figures as at 30 September 2026, for the meeting on 29 October 2026.

Position

EXAMPLE — We are outside our cyber risk appetite on 2 of 12 top risks, both within tolerance, and we expect to be back within appetite by the end of Q4 2026 if the board approves today's decision.

Measure

Value

Target

Direction

Status

BM-01 Risks outside appetite

2 of 12 top risks

0

Better (was 3)

Outside appetite, within tolerance

BM-02 Critical exposure fixed on time

81%

95% within 14 calendar days

Worse (was 90%)

Below target, within tolerance

BM-03 Expired or high-risk exceptions

4 open; 1 expired

0 expired

Worse (was 0 expired)

Below target, within tolerance

BM-04 Significant incidents and time to contain

1 significant incident; contained in 6 hours

Contained within 24 hours

Same (1 last quarter)

On target

BM-05 Critical suppliers assessed

9 of 14 critical suppliers

14 of 14 by year end

Better (was 6)

On target

BM-06 Critical services restored in tests

2 of 4 critical services

4 of 4 each year

Better (was 1)

On target

BM-07 Security programme delivery

7 of 9 milestones

9 of 9 by quarter end

Same (78% last quarter)

Below target, within tolerance

BM-08 Board and staff security training

Board 6 of 7; staff 92%

All board; staff 95%

Better (staff was 88%)

Below target, within tolerance

Figures as at 30 September 2026, signed off from the Board Reporting Data Collection Workbook (BR-08). Definitions in the appendix.

Incident this quarter (BR-07). 12 Aug 2026: Ransomware on 14 office PCs at one warehouse; ordering and dispatch not affected. About 1.5 days of lost office work; no data taken, as far as we know. Contained in 6 hours. Reported to the chair: yes, within 24 hours. What we are doing: Remove local admin rights from all office PCs by 31 Oct 2026.

Direction
  • Better overall: one risk returned within appetite after the warehouse network was separated from the office network.
  • Worse: on fixing critical weaknesses (81%, was 90%) because the ordering platform team lost two engineers.
  • Recovery tested: critical services restored in tests — 2 of 4 critical services (better (was 1)); target 4 of 4 each year.
Exposure

Risk

Harm (EXAMPLE)

Likelihood

Position

Online ordering unavailable for more than 2 days after ransomware

Loss of about €1.2m of orders per week; customer contracts breached

Possible

Outside appetite, within tolerance

Payment fraud through a compromised supplier email account

Single losses of €50k to €400k; not recoverable once paid

Likely

Outside appetite, within tolerance

Customer data exposed through the ordering service

Regulatory fine, notification cost and lost trade; about €0.8m

Unlikely

Within appetite

Ask

Decision (EXAMPLE). Approve €180,000 to rebuild the ordering platform's recovery so it can be restored within 24 hours?

Part

EXAMPLE

Options

A: approve now, done by 15 Dec 2026.

B: approve half now for backup isolation only, and the rest in the next budget.

C: do not approve; accept the risk.

Recommendation

A. It brings the ransomware risk back within appetite this year and is about 15% of one week's lost orders.

Cost

€180,000 one-off, plus about €20,000 a year to run.

Risk of not deciding

The ransomware risk stays outside appetite into 2027. A 2-day outage would cost about €1.2m per week of orders lost, plus contract penalties.

Decide by

This meeting, so work starts before the peak season in November.

To note: board and staff security training — Board 6 of 7; staff 92% against a target of all board; staff 95%; the remaining director's training is booked for [[date]].

Guidance — delete before approval

Read Example 1 against the rules: it opens with the position (BR-02), follows the four parts in order (BR-01), shows measures that each have a target (BR-03) with value, direction and status in words (BR-04), keeps technology out of the body (BR-05), states the ask as a decision (BR-06), reports the incident in the first report after it was known (BR-07) and cites the signed-off workbook (BR-08).

The position follows the rule in 'Stating the position against appetite and tolerance': 2 top risks are above appetite and none is past its tolerance limit, so the position is 'Outside appetite, within tolerance'.

Example 2 — bad news between meetings (EXAMPLE)

Three weeks after the meeting on 29 October 2026, the same firm pays a fraudulent invoice. This moves a top risk past its tolerance limit, which is a trigger for an out-of-cycle note: within [[5]] working days of a major incident or of any top risk moving outside its tolerance limit, to the chair (a move outside appetite but within tolerance waits for the next report). The note keeps the four parts. The event and its figures are EXAMPLE values for this note only.

Part

EXAMPLE note to the chair

Position

We are now outside tolerance on one top risk: payment fraud through a compromised supplier email account. On [[date]] we paid €[[120,000]] to a fraudster after a supplier's email account was taken over and used to change its bank details. Operations are not affected.

Direction

Worse since the meeting on 29 October 2026, where this risk was reported as Likely and outside appetite, within tolerance. It has now happened, at a cost above the limit the board set for it.

Exposure

Single losses of €50k to €400k; not recoverable once paid. Our bank has asked the receiving bank to freeze the funds; we will know by [[date]] whether any can be recovered. We do not yet know whether other suppliers' accounts are affected; we are checking every change of bank details in the last [[90]] days and will report by [[date]].

Ask

Because the risk is outside tolerance, the committee must decide, not just note: fund or order treatment, accept the risk explicitly and record why, or change the appetite. We propose a short call on [[date]] to decide between (A) a call-back to a known number before any change of supplier bank details is paid, from [[date]], at no cost beyond staff time; and (B) option A plus a payment-verification service at about €[[15,000]] a year. Recommended: B.

Common failure modes

Most weak board reports fail in the same few ways. Use this list to review a draft before the executive sponsor sees it.

Failure

What it looks like

What to do instead

Activity report

Counts of things done: patches, alerts, emails blocked, trainings completed.

Report outcomes against appetite. Move activity counts to the appendix or drop them.

Traffic-light soup

Twenty coloured tiles, few targets, no words.

Five to eight measures with targets (BR-03), status in words (BR-04).

Always green

Every measure on target, quarter after quarter, while incidents happen elsewhere.

Check the targets. A report that never shows a problem is usually measuring the wrong thing.

Fear, uncertainty and doubt

Headline breaches and threat statistics with no link to this organisation's exposure.

State the risk to our services, with likelihood and cost. Use a headline only to answer 'could this happen to us?'.

The open-ended ask

"We need more budget" or "the board should be aware".

An ask with options, a recommendation, cost and the risk of not deciding (BR-06).

Compliance as security

"We are certified, so we are secure."

Report certification as one fact. Certification shows a management system works; it does not show a risk is within appetite.

Moving measures

New measures each quarter; old ones dropped when they look bad.

Keep the set for at least a year. Change it only at the yearly review (BR-10), and say what changed.

Late bad news

A problem known for weeks reported at the end of the deck.

First report after it is known, first in the Position (BR-07).

Too long

A 40-slide deck, or a paper the board cannot read in the time it has.

Four to six slides and the Cyber Risk One-Page Board Summary; the rest in the appendix.

No follow-up

The board agrees actions that are never mentioned again.

An action log in every report until each action is closed (BR-09).

Operational asks

The board asked to choose a product or approve a project plan.

Ask the board only what the board decides: appetite, priority, money, risk acceptance.

How to defend the method to an auditor

An auditor or supervisor looking at how the board oversees cyber risk will usually test three things: that top management reviews the security of the organisation at planned intervals and records its decisions (ISO/IEC 27001 clause 9.3); that leadership is visibly engaged and sets direction (clause 5.1); and, for entities under NIS2 or DORA, that the management body approves and oversees the risk-management measures and is kept informed. This model is designed to produce the evidence for all three.

Evidence to have ready

  • The approved risk appetite statement, and the minute of the meeting that approved it.
  • Each quarterly report, following the four parts, with its one-page summary.
  • The signed-off Board Reporting Data Collection Workbook for each report (BR-08).
  • The minutes, showing the decisions taken on each Ask, and the action log showing each action followed to closure (BR-09).
  • Out-of-cycle notes to the chair, with the date the event was known and the date the note was sent (BR-07).
  • The yearly result of the Board Reporting Effectiveness Self-Check and what changed because of it (BR-10).

Questions auditors commonly ask

Question

Answer the model gives

How does the board know whether cyber risk is acceptable?

Every report opens with the position against the appetite the board approved (BR-02), measured by BM-01.

What did the board decide, and was it followed through?

Each Ask is recorded as a decision in the minutes; the action log carries every agreed action until it is closed (BR-09).

How do you know the figures are right?

They come from one workbook, checked and signed off before the report is written (BR-08). Any figure can be traced to its source.

How quickly does the board hear about a serious incident?

An out-of-cycle note goes within [[5]] working days of a major incident or of any top risk moving outside its tolerance limit, to the chair (a move outside appetite but within tolerance waits for the next report). The event then opens the next report (BR-07).

Is the reporting itself reviewed?

Once a year against the Board Reporting Effectiveness Self-Check (BR-10).

Limitations

Limitation

Effect

How it is managed

The reporter chooses the top risks.

A narrative can hide as well as reveal: an awkward risk can be left out.

BM-01 counts from the whole risk register, not from the report. The risk function checks the list at sign-off.

Money figures are estimates.

A wide range may be dismissed, a narrow one may be wrong.

Ranges with their basis; per-day figures agreed with finance once a year.

Likelihood is a judgement.

Two reporters may choose different words.

Stated ranges for each word; movement explained by a cause (Direction).

The model depends on an appetite statement.

Without one, Position cannot be stated.

Report that it is missing and ask the board to set one.

A fixed shape can feel repetitive.

Directors may ask for 'something new'.

The repetition is the point: movement stands out. Offer a yearly deep dive for new material.

Business terms simplify.

Some technical nuance is lost in the body.

The appendix keeps it; the reporter offers detail on request.

Calibration and review

After every board meeting

  1. Within [[2]] working days, the reporter and the executive sponsor spend [[15]] minutes on three questions: which questions did the board ask that the report did not answer; which parts did it skip; which figure was challenged.
  2. Add each unexpected question to your copy of the Board Question Bank & Preparation Brief, with a good answer.
  3. Record decisions and actions in the action log (BR-09).

Every year

Review the reporting against the Board Reporting Effectiveness Self-Check (BR-10), with the chair or a member of the committee. Test whether a director can state the position after reading only the first page. Confirm the measures still answer the board's questions and their targets still fit the appetite. Review this model itself at least every 12 months, and when the board's appetite statement, membership or regulatory status changes.

Review record

Date

Reviewed by

Finding

Change made

Approved by

[[YYYY-MM-DD]]

[[Name]]

[[e.g. board asked twice about suppliers]]

[[e.g. BM-05 added to the Position]]

[[Name]]

Related documents

Document

Relationship

Board Cybersecurity Report Deck Template

The deck built on the four parts

Board Metric Selection Catalogue

The measures (BM-01 to BM-08) and how to choose them (BR-03)

Board Reporting Data Collection Workbook

The single source of every figure (BR-08)

Board Question Bank & Preparation Brief

Preparation for the meeting and the questions the board is likely to ask

Cyber Risk One-Page Board Summary

The four parts on one page

Board & Executive Reporting Calendar

The reporting cycle, from data request to actions recorded (quarterly by default)

Board Reporting Effectiveness Self-Check

The yearly review of the reporting itself (BR-10)

[[Risk appetite statement]]

The yardstick for Position

[[Risk register]]

The source of BM-01 and the top risks

Adapting this template

Guidance — delete before approval

Small organisation with no board committee: the 'board' may be the owners, the partners or the directors meeting monthly. Keep the four parts and the ten rules; shrink everything else. Report [[twice a year]] or quarterly on [[two]] pages. The reporter may be the IT manager or an external adviser, and the executive sponsor the managing director. If the appetite has never been written down, write one paragraph from what the owners say they will not tolerate, and make approving it the first Ask. Use three or four measures, not eight.

Regulated entity (NIS2, DORA): the management body is required to approve and oversee the cybersecurity risk-management measures and can be held liable (NIS2 Article 20(1)); under DORA it defines, approves and oversees the ICT risk management framework, bears ultimate responsibility and sets the risk tolerance (Article 5(2)), and must have reporting channels that keep it informed, including of major ICT-related incidents (Article 5(2)(i)). So: state the position against the tolerance the management body set, in the terms of your ICT risk framework; record every approval and decision in the minutes; make the out-of-cycle route to the chair your documented reporting channel for major incidents; and report board training through BM-08. Keep the minutes and action log as the evidence of oversight.

IT run by a service provider: the provider supplies the figures for measures such as BM-02, BM-04 and BM-06 into the Board Reporting Data Collection Workbook by the date in the reporting cycle, as the contract requires. The reporter is someone in your organisation who interprets them; the provider does not write or present the board report. Report the provider itself as a critical supplier under BM-05, and its failures as bad news under BR-07.

Delete this section before approval.

Framework references

These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA).

Framework

Reference

Supported by

ISO/IEC 27001:2022

Clause 5.1 — Leadership and commitment

Purpose; stating the position; writing an ask as a decision

ISO/IEC 27001:2022

Clause 7.4 — Communication

The four parts; the reporting rules (what is communicated, to whom and when)

ISO/IEC 27001:2022

Clause 9.3 — Management review

Whole model: the board's periodic review, its decisions and follow-up (BR-09)

NIST CSF 2.0

GV.OV-01 — “Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction”

Direction; Ask: outcomes reviewed to adjust strategy

NIST CSF 2.0

GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed”

Position and measures (BR-03, BR-04)

NIST CSF 2.0

GV.RM-02 — “Risk appetite and risk tolerance statements are established, communicated, and maintained”

Stating the position against appetite and tolerance

NIST CSF 2.0

GV.RR-01 — “Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving”

Purpose; reporting bad news (BR-07)

NIS2 — Directive (EU) 2022/2555

Article 20(1) — management bodies approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements

Purpose; adapting this template: regulated entity

DORA — Regulation (EU) 2022/2554

Article 5(2) — the management body defines, approves, oversees and is responsible for the ICT risk management framework, bears ultimate responsibility for ICT risk and sets the risk tolerance

Stating the position against tolerance; adapting this template: regulated entity

DORA — Regulation (EU) 2022/2554

Article 5(2)(i) — reporting channels that keep the management body informed, including of at least major ICT-related incidents and their impact

Reporting bad news; out-of-cycle reporting to the chair

Definitions

Term

Meaning in this model

Appendix

The part of a report after the four parts, holding technical detail, definitions and supporting data (BR-05).

Ask

The fourth part of a report: each decision the board is asked to take, with options, a recommendation, cost and the risk of not deciding (BR-06).

Board

The body the report is written for: [[e.g. Board, or its Audit & Risk Committee]]. In a small organisation, the owners or directors.

Direction

The second part of a report: what has moved since last time, and why.

Executive sponsor

The executive who reviews the report before it goes to the board and supports its asks: [[e.g. Chief Operating Officer or CFO]].

Exposure

The third part of a report: the top risks in business terms.

Management body

The term NIS2 and DORA use for the board of directors or equivalent body that directs the organisation.

Measure

A figure reported to the board with a target, one of BM-01 to BM-08.

Out-of-cycle report

A note sent between meetings within [[5]] working days of a major incident or of any top risk moving outside its tolerance limit, to the chair (a move outside appetite but within tolerance waits for the next report).

Position

The first part of a report: where the organisation stands against the risk appetite, stated in one sentence (BR-02).

Reporter

The person who writes and presents the report: [[e.g. Head of Information Security or CISO]].

Risk appetite

The amount and kind of risk the board is willing to accept in pursuit of its objectives.

Risk tolerance

The limit around the appetite beyond which the board must act, not merely be told.

Top risks

The [[ten to fifteen]] risks in the risk register that the board follows by name.