Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Risk Reporting Dashboard

Presents the risk position against appetite, movement since last cycle and treatment progress in a form suitable for an executive committee.

Available soon

Format
Excel
Size
120 KB
Length
12 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Register Data
  • Action Data
  • Metric Definitions
  • Quarterly Report
  • Trend
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Register Data sheet: in the Information Security Risk Register, copy the Register table's rows (columns A to AE, from row 4 down) and paste them here as values only (Paste Special → Values) into cell A4. Both sheets have the same columns in the same order.
2Action Data sheet: in the Risk Treatment Plan, copy the Actions table's rows (columns A to AA, from row 4 down) and paste them as values into cell A4.
3Delete the EXAMPLE rows on both data sheets before you paste, and check that dates are real dates (right-aligned), not text.
4Quarterly Report sheet: enter the report date, normally the last day of the quarter. The EXAMPLE uses 2026-09-30; replace it with your quarter end. Owner reviews, overdue actions and acceptance reviews are recalculated at this date; positions and movement are as the register calculated them.
5Enter the categories you report on (as named on the register's Appetite sheet). The Trend sheet holds last quarter's figures: type the three earlier quarters from the reports you kept.
6Read the position sentence and the four headline measures. Each has its target, its direction since last quarter and a status in words; the colour only repeats the word. Add a line of commentary to every measure that missed its target or moved.
7For each risk outside appetite, write the decision needed: what executive management or the board must decide, note or fund. A risk outside tolerance always needs a decision.
8Complete 'What to tell executive management' and take the report to [[e.g. Executive Committee]] every quarter (RM-12). Carry the position and the decisions into the Board Cybersecurity Report Deck Template so both say the same.
9Keep a copy of this workbook for each quarter as the record.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

The EXAMPLE is a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30: the same register as the Information Security Risk Register and the same actions as the Risk Treatment Plan. 2 of 12 risks are outside appetite (R-01, R-02), none past tolerance; R-04 moved from 9 to 4 and is back within appetite, so last quarter's figure was 3. The earlier quarters on the Trend sheet are EXAMPLE figures typed in.

Words shared with the board report: the position is one of "Within appetite", "Outside appetite, within tolerance", "Outside tolerance"; direction is Better, Same or Worse with last quarter's figure. Amounts in the examples are in euros (€); use your own currency.

Tailoring — small organisation: the report can be one page — the position sentence, the four measures, the risks outside appetite and the decisions. Take it to whoever runs the organisation, every quarter.

Tailoring — regulated entity (NIS2, DORA): take the report to the management body, which approves and oversees the risk-management measures (NIS2 Art 20(1), 21(1)). Show each category's approved tolerance next to its position, as the evidence of the approved risk tolerance level (Delegated Regulation (EU) 2024/1774 Art 3(a)); keep each quarter's copy.

Tailoring — IT run by a service provider: risks and actions in the provider's service are in the register and plan you paste; ask the provider to report its actions' status before your quarter end.

Register Data

Paste the Information Security Risk Register table here as values (columns A–AE, from row 4). Columns AF–AM are calculated at the report date. The 12 EXAMPLE rows are that register's example — delete them first.

ExampleRisk IDCategoryAppetite levelRisk scenarioRisk ownerInherent impact (1–4)Inherent likelihood (1–4)Inherent scoreInherent bandExisting controlsResidual impact (1–4)Residual likelihood (1–4)Residual scoreResidual bandLast quarter's residual scoreMovementPosition against appetiteTreatmentLinked actionsWho may acceptAcceptance refAcceptance review dateLast owner reviewReviewed this quarterTrigger since last assessmentTrigger dateReassessed onTrigger flagRecord checkNotesReviewed in the quarter (calc)Acceptance status (calc)Last quarter's band (calc)Last quarter's position (calc)Change in position (calc)Outside no. (calc)Moved no. (calc)Accepted no. (calc)
EXAMPLER-01Service availabilityCautiousRansomware takes online ordering offline for more than 2 daysChief Operating Officer4312CriticalNightly backups of the ordering platform; endpoint detection on servers; recovery of the whole platform not yet proven within 2 days428High8SameOutside appetite, within toleranceReduceTA-01Accountable executive and Head of Information Security, and executive management as well10 Sep 2026YesOKTreatment action TA-01 (€180,000) is the decision put to the board; see the Risk Treatment PlanYesHighOutside appetite, within toleranceNo change1
EXAMPLER-02Financial fraudCautiousPayment fraud through a compromised supplier email accountChief Financial Officer3412CriticalTwo-person approval of payments; accounts payable staff trained to spot changed bank details339High9SameOutside appetite, within toleranceReduceTA-02Accountable executive and Head of Information Security, and executive management as well8 Sep 2026YesOKYesHighOutside appetite, within toleranceNo change2
EXAMPLER-03Customer and personal dataCautiousCustomer data exposed through the ordering serviceChief Operating Officer428HighWeb application firewall; yearly penetration test of the ordering service; customer data encrypted at rest414Medium4SameWithin appetiteReduceRisk owner and Head of Information Security22 Jul 2026YesOKYesMediumWithin appetiteNo change
EXAMPLER-04Service availabilityCautiousRansomware spreads from warehouse office PCs to warehouse systemsHead of Logistics339HighWarehouse networks separated from the office network at all three sites (last site 2026-09-09, tested 2026-09-11); endpoint protection on office PCs224Medium9BetterWithin appetiteReduceTA-04Risk owner and Head of Information Security30 Sep 2026YesA major incident, or a near miss that shows a risk was underrated12 Aug 202620 Aug 2026ReassessedOKReassessed on 2026-08-20 after the 12 Aug 2026 ransomware incident and kept at 9: two sites were still on the office network. The last site was separated on 2026-09-09 and tested on 2026-09-11 (TA-04); the quarter-end review scored it 4YesHighOutside appetite, within toleranceBack within appetite1
EXAMPLER-05Service availabilityCautiousCritical weaknesses on internet-facing systems exploited before they are fixedHead of IT339HighMonthly vulnerability scanning; patching deadlines by severity; internet-facing systems behind a web application firewall326Medium6SameWithin appetiteReduceTA-03Risk owner and Head of Information Security15 Sep 2026YesOKYesMediumWithin appetiteNo change
EXAMPLER-06Third-party dependencyCautiousManaged IT provider fails or is compromisedHead of IT326MediumContract with security and service-level clauses; provider's yearly assurance report; insurance covering provider failure313Low3SameWithin appetiteTransferRisk owner14 Jul 2026YesOKTransferred in part by contract and insurance; the Head of IT still owns the riskYesLowWithin appetiteNo change
EXAMPLER-07People and insiderCautiousAdministrator misuses privileged accessHead of IT326MediumSeparate administrator accounts with multi-factor authentication; administrator activity logged313Low3SameWithin appetiteReduceRisk owner14 Jul 2026YesOKYesLowWithin appetiteNo change
EXAMPLER-08Regulatory complianceAverseSignificant incident not reported to the authority on time (NIS2)Head of Information Security224MediumIncident response procedure with the notification steps and deadlines; on-call rota212Low2SameWithin appetiteReduceRisk owner5 Aug 2026YesOKYesLowWithin appetiteNo change
EXAMPLER-09People and insiderCautiousStaff account taken over through phishingHR Director248HighMulti-factor authentication on email; phishing report button; awareness training every quarter236Medium6SameWithin appetiteReduceRisk owner and Head of Information Security27 Aug 2026YesOKYesMediumWithin appetiteNo change
EXAMPLER-10Service availabilityCautiousBackups cannot restore a critical systemHead of IT428HighDaily backups with an offline copy; one critical system restored in a test each quarter414Medium4SameWithin appetiteReduceRisk owner and Head of Information Security14 Jul 2026YesOKYesMediumWithin appetiteNo change
EXAMPLER-11Customer and personal dataCautiousCloud storage misconfigured and customer files exposedHead of IT326MediumCloud configuration baseline; monthly configuration scan313Low3SameWithin appetiteReduceRisk owner14 Jul 2026YesOKYesLowWithin appetiteNo change
EXAMPLER-12Customer and personal dataCautiousCustomer data on an unencrypted laptop at the smaller warehouse site is lost or stolenHead of Logistics224MediumAcceptance conditions: Laptops stay on site, are locked away overnight and are not used for customer data exports.224Medium4SameWithin appetiteAcceptRisk owner and Head of Information SecurityRA-0115 Jun 20271 Sep 2026YesOKAccepted on 2026-06-15 by the Head of Logistics (risk owner) and Head of Information Security until the March 2027 laptop refresh (see RA-01)YesCurrentMediumWithin appetiteNo change1

Action Data

Paste the Risk Treatment Plan Actions table here as values (columns A–AA, from row 4). Columns AB–AF are calculated at the report date. EXAMPLE: that plan's example.

ExampleAction IDRisk IDRiskAppetite levelTreatment actionAction ownerDue dateStatusCompleted onOne-off cost (€)Running cost per year (€)DependenciesCurrent residual impact (1–4)Current residual likelihood (1–4)Current residual scoreCurrent bandCurrent positionExpected residual impact (1–4)Expected residual likelihood (1–4)Expected residual scoreExpected bandExpected position afterDays to due dateOverdue flagRecord checkNotesOpen (calc)Days to due date (calc)Overdue (calc)Done in the quarter (calc)Open no. (calc)
EXAMPLETA-01R-01Ransomware takes online ordering offline for more than 2 daysCautiousRebuild the ordering platform's recovery so it can be restored within 24 hoursHead of IT15 Dec 2026Awaiting board approval€180,000€20,000Board approval of the funding at the 2026-10-29 meeting; work must start before the November peak season428HighOutside appetite, within tolerance414MediumWithin appetite76OKThe decision in the quarterly board report: option A, done by 15 Dec 2026. Brings R-01 back within appetiteYes761
EXAMPLETA-02R-02Payment fraud through a compromised supplier email accountCautiousCall-back verification of every change to supplier bank details, and a payment verification serviceChief Financial Officer30 Nov 2026In progress€15,000Payment verification service chosen and contracted339HighOutside appetite, within tolerance326MediumWithin appetite61OKYes612
EXAMPLETA-04R-04Ransomware spreads from warehouse office PCs to warehouse systemsCautiousSeparate the warehouse networks from the office network at all three sitesHead of IT11 Sep 2026Done11 Sep 2026€28,000None224MediumWithin appetite224MediumWithin appetiteOKDone: the last site was separated on 2026-09-09 and the separation tested on 2026-09-11. R-04 back within appetite at the quarter-end reviewYes
EXAMPLETA-03R-05Critical weaknesses on internet-facing systems exploited before they are fixedCautiousBring the ordering platform's patching back to 95% within deadline after two engineers leftHead of IT31 Oct 2026At risk€0Two engineer vacancies on the ordering platform team filled, or cover arranged with the managed IT provider326MediumWithin appetite313LowWithin appetite31OKNot overdue at the as-at date, but at risk of missing its due date while the team is short of two engineersYes313

Metric Definitions

Metric definitions

The four headline measures of the Risk Assessment Methodology & Scoring Model, defined once so every quarter is calculated the same way (RM-12).

MeasureDefinitionHow this workbook calculates itTargetHow to read it
RMM-01 Risks outside appetite and past toleranceTop risks whose residual band is above their category's appetite; and of those, above its tolerance.Register rows whose Position against appetite is not Within appetite; and of those, Outside tolerance. The overall position applies the board's rule: Outside tolerance if any risk is; otherwise Outside appetite, within tolerance if any risk is; otherwise Within appetite.Zero past tolerance; outside appetite each with a treatment decisionThe same measure as the board report's first measure. Note the plan and date, or challenge them. Decide if the plan needs money or a change of priority.
RMM-02 Treatment actions overdueOpen treatment actions past their due date.Action rows not Done or Cancelled whose due date is before the report date; and of those, more than 30 calendar days past it. Status At risk is shown separately: late is calculated, never typed.Zero older than 30 daysOverdue actions keep a risk outside appetite longer than the plan said. Name each one older than the target with its owner.
RMM-03 Acceptances past reviewAccepted risks whose acceptance review date has passed.Register rows with Treatment Accept whose acceptance review date is before the report date.ZeroAn acceptance past review is a risk nobody has re-decided. Review it on the Risk Acceptance Form & Approval Record.
RMM-04 Risks not reviewed this quarterRegister entries with no owner review in the last quarter (RM-09).Register rows with no owner review in the 3 months up to the report date.ZeroA risk not reviewed is a score nobody has checked. Name the owners.

Quarterly Report

Information security risk — quarterly report

Yellow cells are yours: the report date, the categories, the commentary and the decisions. Everything else is calculated. Every status is in words; the colour only repeats it.

Report settings

SettingValue
Report date (the quarter end)30 Sep 2026EXAMPLE report date: replace with your quarter end.
QuarterQ3 2026

Position

We are outside our cyber risk appetite on 2 of 12 top risks, both within tolerance.

Overall positionOutside appetite, within toleranceNote the plan and date, or challenge them. Decide if the plan needs money or a change of priority.

Headline measures

MeasureThis quarterLast quarterDirectionTargetStatusCommentary — what changed, and why
RMM-01 Risks outside appetite23Better (was 3)Each with a treatment decisionOutside appetite, within tolerance[[EXAMPLE: Better overall: R-04 is back within appetite after TA-04 separated the last warehouse site; R-01 and R-02 remain outside, both within tolerance.]]
RMM-01 Of those, past tolerance00Same0On target
RMM-02 Treatment actions overdue00Same—
older than 30 days00SameZero older than 30 daysOn target
RMM-03 Acceptances past review00SameZeroOn target
RMM-04 Risks not reviewed this quarter00SameZeroOn target

Positions and movement are as the register calculated them; owner reviews, overdue actions and acceptance reviews are recalculated at the report date. Last quarter comes from the Trend sheet.

Position against appetite, by category

CategoryAppetite levelRisksOutside appetitePast toleranceOutside appetite last quarterPositionDirectionAppetite / tolerance (highest band)
Service availabilityCautious4102Outside appetite, within toleranceBetter (was 2)Medium / High
Customer and personal dataCautious3000Within appetiteSameMedium / High
Financial fraudCautious1101Outside appetite, within toleranceSameMedium / High
Regulatory complianceAverse1000Within appetiteSameLow / Medium
Third-party dependencyCautious1000Within appetiteSameMedium / High
People and insiderCautious2000Within appetiteSameMedium / High

Movement since last quarter

RiskOwnerLast quarterNowMovementPositionWhat changed
R-04 Ransomware spreads from warehouse office PCs to warehouse systemsHead of Logistics9 (High)4 (Medium)BetterBack within appetiteReassessed on 2026-08-20 after the 12 Aug 2026 ransomware incident and kept at 9: two sites were still on the office network. The last site was separated on 2026-09-09 and tested on 2026-09-11 (TA-04); the quarter-end review scored it 4

All other risks: 11 the same as last quarter.

Risks outside appetite: treatment and decision needed

RiskOwnerResidualPositionTreatmentActionsDecision needed
R-01 Ransomware takes online ordering offline for more than 2 daysChief Operating Officer8 (High)Outside appetite, within toleranceReduceTA-01[[EXAMPLE: Decide: Approve €180,000 to rebuild the ordering platform's recovery so it can be restored within 24 hours? (TA-01; recommended option A)]]
R-02 Payment fraud through a compromised supplier email accountChief Financial Officer9 (High)Outside appetite, within toleranceReduceTA-02[[EXAMPLE: Note the plan and date, or challenge them: TA-02 due 2026-11-30.]]

Outside appetite: note the plan and date, or challenge them. Decide if the plan needs money or a change of priority. Outside tolerance: decide: fund or order treatment, accept the risk explicitly and record why, or change the appetite. Reported out of cycle if it happens between meetings.

Treatment progress

MeasureActionsOne-off cost
Open actions3€195,000
awaiting approval1€180,000
at risk1€0
overdue0€0
Done in the quarter1€28,000
Open actionRiskOwnerDue dateStatusDays to due dateOverdueOne-off costExpected position after
TA-01 Rebuild the ordering platform's recovery so it can be restored within 24 hoursR-01Head of IT15 Dec 2026Awaiting board approval76€180,000Within appetite
TA-02 Call-back verification of every change to supplier bank details, and a payment verification serviceR-02Chief Financial Officer30 Nov 2026In progress61€15,000Within appetite
TA-03 Bring the ordering platform's patching back to 95% within deadline after two engineers leftR-05Head of IT31 Oct 2026At risk31"€0"Within appetite

Accepted risks and their review dates

Accepted riskOwnerAcceptanceResidualReview byDays to reviewStatus
R-12 Customer data on an unencrypted laptop at the smaller warehouse site is lost or stolenHead of LogisticsRA-014 (Medium)15 Jun 2027258Current

Due soon: review within 90 calendar days of the report date. Past review counts in RMM-03; re-decide it on the Risk Acceptance Form & Approval Record.

What to tell executive management

PointWhat to say
Position (one sentence)We are outside our cyber risk appetite on 2 of 12 top risks, both within tolerance.
Direction: better or worse, and why[[EXAMPLE: Better overall: one risk returned within appetite after the warehouse network was separated from the office network. Worse on fixing critical weaknesses (81%, was 90%) because the ordering platform team lost two engineers.]]
What could hurt us most[[EXAMPLE: R-01, ransomware takes online ordering offline for more than 2 days; R-02, payment fraud through a compromised supplier email account.]]
Decisions needed[[EXAMPLE: Approve €180,000 to rebuild the ordering platform's recovery so it can be restored within 24 hours? A: approve now, done by 15 Dec 2026. B: approve half now for backup isolation only, and the rest in the next budget. C: do not approve; accept the risk. Recommended: A. It brings the ransomware risk back within appetite this year and is about 15% of one week's lost orders.]]
Prepared by (name, role) and date[[Name, role, YYYY-MM-DD]]

Trend

Trend — the last four quarters

The headline measures at each of the last four quarter ends. Type the three earlier quarters from the reports you kept; the last row comes from the Quarterly Report. Direction compares each quarter with the one before.

Quarter endQuarterRMM-01 outside appetiteRMM-01 past tolerancePositionRMM-02 overdueRMM-02 over 30 daysRMM-03 past reviewRMM-04 not reviewedRMM-01 directionCommentary
31 Dec 2025Q4 202540Outside appetite, within tolerance2103—[[EXAMPLE figures: replace with your own]]
31 Mar 2026Q1 202630Outside appetite, within tolerance1001Better (was 4)[[EXAMPLE figures: replace with your own]]
30 Jun 2026Q2 202630Outside appetite, within tolerance0000Same[[EXAMPLE figures: replace with your own]]
30 Sep 2026Q3 202620Outside appetite, within tolerance0000Better (was 3)

EXAMPLE: the three earlier quarters are typed in, as you would from the reports kept for them. 2026-06-30: 3 outside appetite, including R-04 before it moved.

Lists

LevelBandBandMinScoreAppetiteLevelLevelAppetiteLevelTolerancePositionPositionBoardTreatmentActionStatus
1Low1AverseLowMediumWithin appetiteNote. No decision is needed on the position.ReduceNot started
2Medium4CautiousMediumHighOutside appetite, within toleranceNote the plan and date, or challenge them. Decide if the plan needs money or a change of priority.AvoidAwaiting board approval
3High8OpenHighHighOutside toleranceDecide: fund or order treatment, accept the risk explicitly and record why, or change the appetite. Reported out of cycle if it happens between meetings.TransferIn progress
4Critical12AcceptAt risk

Done

Cancelled

Definitions

Definitions

TermMeaning in this workbook
Report dateThe quarter end the report is for. Owner reviews, overdue actions and acceptance reviews are calculated at this date.
PositionWithin appetite: every top risk is assessed at or below the level of risk the board has said it is willing to accept. Outside appetite, within tolerance: at least one top risk is above appetite but below the tolerance limit, with a plan and a date to bring it back. Outside tolerance: at least one risk is above the tolerance limit: the point at which the board said it must act, not just be told.
Overall positionOutside tolerance if any risk is past its tolerance; otherwise Outside appetite, within tolerance if any risk is above appetite; otherwise Within appetite. The same rule as the board report.
DirectionBetter, Same or Worse than last quarter, with last quarter's figure: for example Better (was 3). For every measure here, lower is better.
MovementFrom the register: Better, Same or Worse against last quarter's residual score; New if it had none. Back within appetite: outside appetite last quarter, within it now.
Decision neededWhat executive management or the board must decide, note or fund for a risk outside appetite: stated as a decision, with the action and its cost.
Open actionAn action in the Risk Treatment Plan that is not Done or Cancelled.
OverdueAn open action past its due date at the report date. Overdue more than 30 days: more than 30 calendar days past it.
Acceptance statusFor risks treated by Accept: Past review (review date before the report date), Due soon (within 90 calendar days), Current, or No review date.
RMM-01 Risks outside appetite and past toleranceTop risks whose residual band is above their category's appetite; and of those, above its tolerance. Target: zero past tolerance; outside appetite each with a treatment decision.
RMM-02 Treatment actions overdueOpen treatment actions past their due date. Target: zero older than 30 days.
RMM-03 Acceptances past reviewAccepted risks whose acceptance review date has passed. Target: zero.
RMM-04 Risks not reviewed this quarterRegister entries with no owner review in the last quarter (RM-09). Target: zero.
(calc)A column the workbook calculates. Do not type or paste over it.
RM-nn, RMM-nnRule and measure numbers in the Risk Assessment Methodology & Scoring Model.
EXAMPLEThe example organisation's figures as at 2026-09-30 (R-12 is its accepted risk). Delete before approval.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 9.1 — Monitoring, measurement, analysis and evaluationThe workbook as a whole: four defined measures, calculated the same way each quarter, analysed and reported
ISO/IEC 27001:2022Clause 9.3 — Management reviewWhat to tell executive management, and the decisions needed: input to management review
NIST CSF 2.0GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed”Headline measures against targets, direction and Trend: risk management performance evaluated each quarter
NIST CSF 2.0GV.RM-02 — “Risk appetite and risk tolerance statements are established, communicated, and maintained”Position against appetite, overall and by category, with each category's appetite and tolerance
DORA — Delegated Regulation (EU) 2024/1774Article 3(a) — an indication of the approval of the risk tolerance level for ICT riskAppetite and tolerance by category, and past-tolerance counts: the approved risk tolerance level in use
NIS2 — Directive (EU) 2022/2555Article 21(1) — appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systemsThe quarterly report as management's oversight of the measures that manage risk

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; Regulation (EU) 2016/679 (GDPR)