Risk Reporting Dashboard
Presents the risk position against appetite, movement since last cycle and treatment progress in a form suitable for an executive committee.
Available soon
- Format
- Excel
- Size
- 120 KB
- Length
- 12 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Register Data
- Action Data
- Metric Definitions
- Quarterly Report
- Trend
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Register Data sheet: in the Information Security Risk Register, copy the Register table's rows (columns A to AE, from row 4 down) and paste them here as values only (Paste Special → Values) into cell A4. Both sheets have the same columns in the same order. |
| 2 | Action Data sheet: in the Risk Treatment Plan, copy the Actions table's rows (columns A to AA, from row 4 down) and paste them as values into cell A4. |
| 3 | Delete the EXAMPLE rows on both data sheets before you paste, and check that dates are real dates (right-aligned), not text. |
| 4 | Quarterly Report sheet: enter the report date, normally the last day of the quarter. The EXAMPLE uses 2026-09-30; replace it with your quarter end. Owner reviews, overdue actions and acceptance reviews are recalculated at this date; positions and movement are as the register calculated them. |
| 5 | Enter the categories you report on (as named on the register's Appetite sheet). The Trend sheet holds last quarter's figures: type the three earlier quarters from the reports you kept. |
| 6 | Read the position sentence and the four headline measures. Each has its target, its direction since last quarter and a status in words; the colour only repeats the word. Add a line of commentary to every measure that missed its target or moved. |
| 7 | For each risk outside appetite, write the decision needed: what executive management or the board must decide, note or fund. A risk outside tolerance always needs a decision. |
| 8 | Complete 'What to tell executive management' and take the report to [[e.g. Executive Committee]] every quarter (RM-12). Carry the position and the decisions into the Board Cybersecurity Report Deck Template so both say the same. |
| 9 | Keep a copy of this workbook for each quarter as the record. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
The EXAMPLE is a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30: the same register as the Information Security Risk Register and the same actions as the Risk Treatment Plan. 2 of 12 risks are outside appetite (R-01, R-02), none past tolerance; R-04 moved from 9 to 4 and is back within appetite, so last quarter's figure was 3. The earlier quarters on the Trend sheet are EXAMPLE figures typed in.
Words shared with the board report: the position is one of "Within appetite", "Outside appetite, within tolerance", "Outside tolerance"; direction is Better, Same or Worse with last quarter's figure. Amounts in the examples are in euros (€); use your own currency.
Tailoring — small organisation: the report can be one page — the position sentence, the four measures, the risks outside appetite and the decisions. Take it to whoever runs the organisation, every quarter.
Tailoring — regulated entity (NIS2, DORA): take the report to the management body, which approves and oversees the risk-management measures (NIS2 Art 20(1), 21(1)). Show each category's approved tolerance next to its position, as the evidence of the approved risk tolerance level (Delegated Regulation (EU) 2024/1774 Art 3(a)); keep each quarter's copy.
Tailoring — IT run by a service provider: risks and actions in the provider's service are in the register and plan you paste; ask the provider to report its actions' status before your quarter end.
Register Data
Paste the Information Security Risk Register table here as values (columns A–AE, from row 4). Columns AF–AM are calculated at the report date. The 12 EXAMPLE rows are that register's example — delete them first.
| Example | Risk ID | Category | Appetite level | Risk scenario | Risk owner | Inherent impact (1–4) | Inherent likelihood (1–4) | Inherent score | Inherent band | Existing controls | Residual impact (1–4) | Residual likelihood (1–4) | Residual score | Residual band | Last quarter's residual score | Movement | Position against appetite | Treatment | Linked actions | Who may accept | Acceptance ref | Acceptance review date | Last owner review | Reviewed this quarter | Trigger since last assessment | Trigger date | Reassessed on | Trigger flag | Record check | Notes | Reviewed in the quarter (calc) | Acceptance status (calc) | Last quarter's band (calc) | Last quarter's position (calc) | Change in position (calc) | Outside no. (calc) | Moved no. (calc) | Accepted no. (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | R-01 | Service availability | Cautious | Ransomware takes online ordering offline for more than 2 days | Chief Operating Officer | 4 | 3 | 12 | Critical | Nightly backups of the ordering platform; endpoint detection on servers; recovery of the whole platform not yet proven within 2 days | 4 | 2 | 8 | High | 8 | Same | Outside appetite, within tolerance | Reduce | TA-01 | Accountable executive and Head of Information Security, and executive management as well | 10 Sep 2026 | Yes | OK | Treatment action TA-01 (€180,000) is the decision put to the board; see the Risk Treatment Plan | Yes | High | Outside appetite, within tolerance | No change | 1 | |||||||||
| EXAMPLE | R-02 | Financial fraud | Cautious | Payment fraud through a compromised supplier email account | Chief Financial Officer | 3 | 4 | 12 | Critical | Two-person approval of payments; accounts payable staff trained to spot changed bank details | 3 | 3 | 9 | High | 9 | Same | Outside appetite, within tolerance | Reduce | TA-02 | Accountable executive and Head of Information Security, and executive management as well | 8 Sep 2026 | Yes | OK | Yes | High | Outside appetite, within tolerance | No change | 2 | ||||||||||
| EXAMPLE | R-03 | Customer and personal data | Cautious | Customer data exposed through the ordering service | Chief Operating Officer | 4 | 2 | 8 | High | Web application firewall; yearly penetration test of the ordering service; customer data encrypted at rest | 4 | 1 | 4 | Medium | 4 | Same | Within appetite | Reduce | Risk owner and Head of Information Security | 22 Jul 2026 | Yes | OK | Yes | Medium | Within appetite | No change | ||||||||||||
| EXAMPLE | R-04 | Service availability | Cautious | Ransomware spreads from warehouse office PCs to warehouse systems | Head of Logistics | 3 | 3 | 9 | High | Warehouse networks separated from the office network at all three sites (last site 2026-09-09, tested 2026-09-11); endpoint protection on office PCs | 2 | 2 | 4 | Medium | 9 | Better | Within appetite | Reduce | TA-04 | Risk owner and Head of Information Security | 30 Sep 2026 | Yes | A major incident, or a near miss that shows a risk was underrated | 12 Aug 2026 | 20 Aug 2026 | Reassessed | OK | Reassessed on 2026-08-20 after the 12 Aug 2026 ransomware incident and kept at 9: two sites were still on the office network. The last site was separated on 2026-09-09 and tested on 2026-09-11 (TA-04); the quarter-end review scored it 4 | Yes | High | Outside appetite, within tolerance | Back within appetite | 1 | |||||
| EXAMPLE | R-05 | Service availability | Cautious | Critical weaknesses on internet-facing systems exploited before they are fixed | Head of IT | 3 | 3 | 9 | High | Monthly vulnerability scanning; patching deadlines by severity; internet-facing systems behind a web application firewall | 3 | 2 | 6 | Medium | 6 | Same | Within appetite | Reduce | TA-03 | Risk owner and Head of Information Security | 15 Sep 2026 | Yes | OK | Yes | Medium | Within appetite | No change | |||||||||||
| EXAMPLE | R-06 | Third-party dependency | Cautious | Managed IT provider fails or is compromised | Head of IT | 3 | 2 | 6 | Medium | Contract with security and service-level clauses; provider's yearly assurance report; insurance covering provider failure | 3 | 1 | 3 | Low | 3 | Same | Within appetite | Transfer | Risk owner | 14 Jul 2026 | Yes | OK | Transferred in part by contract and insurance; the Head of IT still owns the risk | Yes | Low | Within appetite | No change | |||||||||||
| EXAMPLE | R-07 | People and insider | Cautious | Administrator misuses privileged access | Head of IT | 3 | 2 | 6 | Medium | Separate administrator accounts with multi-factor authentication; administrator activity logged | 3 | 1 | 3 | Low | 3 | Same | Within appetite | Reduce | Risk owner | 14 Jul 2026 | Yes | OK | Yes | Low | Within appetite | No change | ||||||||||||
| EXAMPLE | R-08 | Regulatory compliance | Averse | Significant incident not reported to the authority on time (NIS2) | Head of Information Security | 2 | 2 | 4 | Medium | Incident response procedure with the notification steps and deadlines; on-call rota | 2 | 1 | 2 | Low | 2 | Same | Within appetite | Reduce | Risk owner | 5 Aug 2026 | Yes | OK | Yes | Low | Within appetite | No change | ||||||||||||
| EXAMPLE | R-09 | People and insider | Cautious | Staff account taken over through phishing | HR Director | 2 | 4 | 8 | High | Multi-factor authentication on email; phishing report button; awareness training every quarter | 2 | 3 | 6 | Medium | 6 | Same | Within appetite | Reduce | Risk owner and Head of Information Security | 27 Aug 2026 | Yes | OK | Yes | Medium | Within appetite | No change | ||||||||||||
| EXAMPLE | R-10 | Service availability | Cautious | Backups cannot restore a critical system | Head of IT | 4 | 2 | 8 | High | Daily backups with an offline copy; one critical system restored in a test each quarter | 4 | 1 | 4 | Medium | 4 | Same | Within appetite | Reduce | Risk owner and Head of Information Security | 14 Jul 2026 | Yes | OK | Yes | Medium | Within appetite | No change | ||||||||||||
| EXAMPLE | R-11 | Customer and personal data | Cautious | Cloud storage misconfigured and customer files exposed | Head of IT | 3 | 2 | 6 | Medium | Cloud configuration baseline; monthly configuration scan | 3 | 1 | 3 | Low | 3 | Same | Within appetite | Reduce | Risk owner | 14 Jul 2026 | Yes | OK | Yes | Low | Within appetite | No change | ||||||||||||
| EXAMPLE | R-12 | Customer and personal data | Cautious | Customer data on an unencrypted laptop at the smaller warehouse site is lost or stolen | Head of Logistics | 2 | 2 | 4 | Medium | Acceptance conditions: Laptops stay on site, are locked away overnight and are not used for customer data exports. | 2 | 2 | 4 | Medium | 4 | Same | Within appetite | Accept | Risk owner and Head of Information Security | RA-01 | 15 Jun 2027 | 1 Sep 2026 | Yes | OK | Accepted on 2026-06-15 by the Head of Logistics (risk owner) and Head of Information Security until the March 2027 laptop refresh (see RA-01) | Yes | Current | Medium | Within appetite | No change | 1 |
Action Data
Paste the Risk Treatment Plan Actions table here as values (columns A–AA, from row 4). Columns AB–AF are calculated at the report date. EXAMPLE: that plan's example.
| Example | Action ID | Risk ID | Risk | Appetite level | Treatment action | Action owner | Due date | Status | Completed on | One-off cost (€) | Running cost per year (€) | Dependencies | Current residual impact (1–4) | Current residual likelihood (1–4) | Current residual score | Current band | Current position | Expected residual impact (1–4) | Expected residual likelihood (1–4) | Expected residual score | Expected band | Expected position after | Days to due date | Overdue flag | Record check | Notes | Open (calc) | Days to due date (calc) | Overdue (calc) | Done in the quarter (calc) | Open no. (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | TA-01 | R-01 | Ransomware takes online ordering offline for more than 2 days | Cautious | Rebuild the ordering platform's recovery so it can be restored within 24 hours | Head of IT | 15 Dec 2026 | Awaiting board approval | €180,000 | €20,000 | Board approval of the funding at the 2026-10-29 meeting; work must start before the November peak season | 4 | 2 | 8 | High | Outside appetite, within tolerance | 4 | 1 | 4 | Medium | Within appetite | 76 | OK | The decision in the quarterly board report: option A, done by 15 Dec 2026. Brings R-01 back within appetite | Yes | 76 | 1 | ||||
| EXAMPLE | TA-02 | R-02 | Payment fraud through a compromised supplier email account | Cautious | Call-back verification of every change to supplier bank details, and a payment verification service | Chief Financial Officer | 30 Nov 2026 | In progress | €15,000 | Payment verification service chosen and contracted | 3 | 3 | 9 | High | Outside appetite, within tolerance | 3 | 2 | 6 | Medium | Within appetite | 61 | OK | Yes | 61 | 2 | ||||||
| EXAMPLE | TA-04 | R-04 | Ransomware spreads from warehouse office PCs to warehouse systems | Cautious | Separate the warehouse networks from the office network at all three sites | Head of IT | 11 Sep 2026 | Done | 11 Sep 2026 | €28,000 | None | 2 | 2 | 4 | Medium | Within appetite | 2 | 2 | 4 | Medium | Within appetite | OK | Done: the last site was separated on 2026-09-09 and the separation tested on 2026-09-11. R-04 back within appetite at the quarter-end review | Yes | |||||||
| EXAMPLE | TA-03 | R-05 | Critical weaknesses on internet-facing systems exploited before they are fixed | Cautious | Bring the ordering platform's patching back to 95% within deadline after two engineers left | Head of IT | 31 Oct 2026 | At risk | €0 | Two engineer vacancies on the ordering platform team filled, or cover arranged with the managed IT provider | 3 | 2 | 6 | Medium | Within appetite | 3 | 1 | 3 | Low | Within appetite | 31 | OK | Not overdue at the as-at date, but at risk of missing its due date while the team is short of two engineers | Yes | 31 | 3 |
Metric Definitions
Metric definitions
The four headline measures of the Risk Assessment Methodology & Scoring Model, defined once so every quarter is calculated the same way (RM-12).
| Measure | Definition | How this workbook calculates it | Target | How to read it |
|---|---|---|---|---|
| RMM-01 Risks outside appetite and past tolerance | Top risks whose residual band is above their category's appetite; and of those, above its tolerance. | Register rows whose Position against appetite is not Within appetite; and of those, Outside tolerance. The overall position applies the board's rule: Outside tolerance if any risk is; otherwise Outside appetite, within tolerance if any risk is; otherwise Within appetite. | Zero past tolerance; outside appetite each with a treatment decision | The same measure as the board report's first measure. Note the plan and date, or challenge them. Decide if the plan needs money or a change of priority. |
| RMM-02 Treatment actions overdue | Open treatment actions past their due date. | Action rows not Done or Cancelled whose due date is before the report date; and of those, more than 30 calendar days past it. Status At risk is shown separately: late is calculated, never typed. | Zero older than 30 days | Overdue actions keep a risk outside appetite longer than the plan said. Name each one older than the target with its owner. |
| RMM-03 Acceptances past review | Accepted risks whose acceptance review date has passed. | Register rows with Treatment Accept whose acceptance review date is before the report date. | Zero | An acceptance past review is a risk nobody has re-decided. Review it on the Risk Acceptance Form & Approval Record. |
| RMM-04 Risks not reviewed this quarter | Register entries with no owner review in the last quarter (RM-09). | Register rows with no owner review in the 3 months up to the report date. | Zero | A risk not reviewed is a score nobody has checked. Name the owners. |
Quarterly Report
Information security risk — quarterly report
Yellow cells are yours: the report date, the categories, the commentary and the decisions. Everything else is calculated. Every status is in words; the colour only repeats it.
Report settings
| Setting | Value | |
|---|---|---|
| Report date (the quarter end) | 30 Sep 2026 | EXAMPLE report date: replace with your quarter end. |
| Quarter | Q3 2026 |
Position
We are outside our cyber risk appetite on 2 of 12 top risks, both within tolerance.
| Overall position | Outside appetite, within tolerance | Note the plan and date, or challenge them. Decide if the plan needs money or a change of priority. | ||||||
Headline measures
| Measure | This quarter | Last quarter | Direction | Target | Status | Commentary — what changed, and why | ||
|---|---|---|---|---|---|---|---|---|
| RMM-01 Risks outside appetite | 2 | 3 | Better (was 3) | Each with a treatment decision | Outside appetite, within tolerance | [[EXAMPLE: Better overall: R-04 is back within appetite after TA-04 separated the last warehouse site; R-01 and R-02 remain outside, both within tolerance.]] | ||
| RMM-01 Of those, past tolerance | 0 | 0 | Same | 0 | On target | |||
| RMM-02 Treatment actions overdue | 0 | 0 | Same | — | ||||
| older than 30 days | 0 | 0 | Same | Zero older than 30 days | On target | |||
| RMM-03 Acceptances past review | 0 | 0 | Same | Zero | On target | |||
| RMM-04 Risks not reviewed this quarter | 0 | 0 | Same | Zero | On target | |||
Positions and movement are as the register calculated them; owner reviews, overdue actions and acceptance reviews are recalculated at the report date. Last quarter comes from the Trend sheet.
Position against appetite, by category
| Category | Appetite level | Risks | Outside appetite | Past tolerance | Outside appetite last quarter | Position | Direction | Appetite / tolerance (highest band) |
|---|---|---|---|---|---|---|---|---|
| Service availability | Cautious | 4 | 1 | 0 | 2 | Outside appetite, within tolerance | Better (was 2) | Medium / High |
| Customer and personal data | Cautious | 3 | 0 | 0 | 0 | Within appetite | Same | Medium / High |
| Financial fraud | Cautious | 1 | 1 | 0 | 1 | Outside appetite, within tolerance | Same | Medium / High |
| Regulatory compliance | Averse | 1 | 0 | 0 | 0 | Within appetite | Same | Low / Medium |
| Third-party dependency | Cautious | 1 | 0 | 0 | 0 | Within appetite | Same | Medium / High |
| People and insider | Cautious | 2 | 0 | 0 | 0 | Within appetite | Same | Medium / High |
Movement since last quarter
| Risk | Owner | Last quarter | Now | Movement | Position | What changed | ||
|---|---|---|---|---|---|---|---|---|
| R-04 Ransomware spreads from warehouse office PCs to warehouse systems | Head of Logistics | 9 (High) | 4 (Medium) | Better | Back within appetite | Reassessed on 2026-08-20 after the 12 Aug 2026 ransomware incident and kept at 9: two sites were still on the office network. The last site was separated on 2026-09-09 and tested on 2026-09-11 (TA-04); the quarter-end review scored it 4 | ||
All other risks: 11 the same as last quarter.
Risks outside appetite: treatment and decision needed
| Risk | Owner | Residual | Position | Treatment | Actions | Decision needed | ||
|---|---|---|---|---|---|---|---|---|
| R-01 Ransomware takes online ordering offline for more than 2 days | Chief Operating Officer | 8 (High) | Outside appetite, within tolerance | Reduce | TA-01 | [[EXAMPLE: Decide: Approve €180,000 to rebuild the ordering platform's recovery so it can be restored within 24 hours? (TA-01; recommended option A)]] | ||
| R-02 Payment fraud through a compromised supplier email account | Chief Financial Officer | 9 (High) | Outside appetite, within tolerance | Reduce | TA-02 | [[EXAMPLE: Note the plan and date, or challenge them: TA-02 due 2026-11-30.]] | ||
Outside appetite: note the plan and date, or challenge them. Decide if the plan needs money or a change of priority. Outside tolerance: decide: fund or order treatment, accept the risk explicitly and record why, or change the appetite. Reported out of cycle if it happens between meetings.
Treatment progress
| Measure | Actions | One-off cost |
|---|---|---|
| Open actions | 3 | €195,000 |
| awaiting approval | 1 | €180,000 |
| at risk | 1 | €0 |
| overdue | 0 | €0 |
| Done in the quarter | 1 | €28,000 |
| Open action | Risk | Owner | Due date | Status | Days to due date | Overdue | One-off cost | Expected position after |
|---|---|---|---|---|---|---|---|---|
| TA-01 Rebuild the ordering platform's recovery so it can be restored within 24 hours | R-01 | Head of IT | 15 Dec 2026 | Awaiting board approval | 76 | €180,000 | Within appetite | |
| TA-02 Call-back verification of every change to supplier bank details, and a payment verification service | R-02 | Chief Financial Officer | 30 Nov 2026 | In progress | 61 | €15,000 | Within appetite | |
| TA-03 Bring the ordering platform's patching back to 95% within deadline after two engineers left | R-05 | Head of IT | 31 Oct 2026 | At risk | 31 | "€0" | Within appetite |
Accepted risks and their review dates
| Accepted risk | Owner | Acceptance | Residual | Review by | Days to review | Status | ||
|---|---|---|---|---|---|---|---|---|
| R-12 Customer data on an unencrypted laptop at the smaller warehouse site is lost or stolen | Head of Logistics | RA-01 | 4 (Medium) | 15 Jun 2027 | 258 | Current | ||
Due soon: review within 90 calendar days of the report date. Past review counts in RMM-03; re-decide it on the Risk Acceptance Form & Approval Record.
What to tell executive management
| Point | What to say | |||||||
|---|---|---|---|---|---|---|---|---|
| Position (one sentence) | We are outside our cyber risk appetite on 2 of 12 top risks, both within tolerance. | |||||||
| Direction: better or worse, and why | [[EXAMPLE: Better overall: one risk returned within appetite after the warehouse network was separated from the office network. Worse on fixing critical weaknesses (81%, was 90%) because the ordering platform team lost two engineers.]] | |||||||
| What could hurt us most | [[EXAMPLE: R-01, ransomware takes online ordering offline for more than 2 days; R-02, payment fraud through a compromised supplier email account.]] | |||||||
| Decisions needed | [[EXAMPLE: Approve €180,000 to rebuild the ordering platform's recovery so it can be restored within 24 hours? A: approve now, done by 15 Dec 2026. B: approve half now for backup isolation only, and the rest in the next budget. C: do not approve; accept the risk. Recommended: A. It brings the ransomware risk back within appetite this year and is about 15% of one week's lost orders.]] | |||||||
| Prepared by (name, role) and date | [[Name, role, YYYY-MM-DD]] | |||||||
Trend
Trend — the last four quarters
The headline measures at each of the last four quarter ends. Type the three earlier quarters from the reports you kept; the last row comes from the Quarterly Report. Direction compares each quarter with the one before.
| Quarter end | Quarter | RMM-01 outside appetite | RMM-01 past tolerance | Position | RMM-02 overdue | RMM-02 over 30 days | RMM-03 past review | RMM-04 not reviewed | RMM-01 direction | Commentary |
|---|---|---|---|---|---|---|---|---|---|---|
| 31 Dec 2025 | Q4 2025 | 4 | 0 | Outside appetite, within tolerance | 2 | 1 | 0 | 3 | — | [[EXAMPLE figures: replace with your own]] |
| 31 Mar 2026 | Q1 2026 | 3 | 0 | Outside appetite, within tolerance | 1 | 0 | 0 | 1 | Better (was 4) | [[EXAMPLE figures: replace with your own]] |
| 30 Jun 2026 | Q2 2026 | 3 | 0 | Outside appetite, within tolerance | 0 | 0 | 0 | 0 | Same | [[EXAMPLE figures: replace with your own]] |
| 30 Sep 2026 | Q3 2026 | 2 | 0 | Outside appetite, within tolerance | 0 | 0 | 0 | 0 | Better (was 3) |
EXAMPLE: the three earlier quarters are typed in, as you would from the reports kept for them. 2026-06-30: 3 outside appetite, including R-04 before it moved.
Lists
| Level | Band | BandMinScore | AppetiteLevel | LevelAppetite | LevelTolerance | Position | PositionBoard | Treatment | ActionStatus |
|---|---|---|---|---|---|---|---|---|---|
| 1 | Low | 1 | Averse | Low | Medium | Within appetite | Note. No decision is needed on the position. | Reduce | Not started |
| 2 | Medium | 4 | Cautious | Medium | High | Outside appetite, within tolerance | Note the plan and date, or challenge them. Decide if the plan needs money or a change of priority. | Avoid | Awaiting board approval |
| 3 | High | 8 | Open | High | High | Outside tolerance | Decide: fund or order treatment, accept the risk explicitly and record why, or change the appetite. Reported out of cycle if it happens between meetings. | Transfer | In progress |
| 4 | Critical | 12 | Accept | At risk |
Done
Cancelled
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Report date | The quarter end the report is for. Owner reviews, overdue actions and acceptance reviews are calculated at this date. |
| Position | Within appetite: every top risk is assessed at or below the level of risk the board has said it is willing to accept. Outside appetite, within tolerance: at least one top risk is above appetite but below the tolerance limit, with a plan and a date to bring it back. Outside tolerance: at least one risk is above the tolerance limit: the point at which the board said it must act, not just be told. |
| Overall position | Outside tolerance if any risk is past its tolerance; otherwise Outside appetite, within tolerance if any risk is above appetite; otherwise Within appetite. The same rule as the board report. |
| Direction | Better, Same or Worse than last quarter, with last quarter's figure: for example Better (was 3). For every measure here, lower is better. |
| Movement | From the register: Better, Same or Worse against last quarter's residual score; New if it had none. Back within appetite: outside appetite last quarter, within it now. |
| Decision needed | What executive management or the board must decide, note or fund for a risk outside appetite: stated as a decision, with the action and its cost. |
| Open action | An action in the Risk Treatment Plan that is not Done or Cancelled. |
| Overdue | An open action past its due date at the report date. Overdue more than 30 days: more than 30 calendar days past it. |
| Acceptance status | For risks treated by Accept: Past review (review date before the report date), Due soon (within 90 calendar days), Current, or No review date. |
| RMM-01 Risks outside appetite and past tolerance | Top risks whose residual band is above their category's appetite; and of those, above its tolerance. Target: zero past tolerance; outside appetite each with a treatment decision. |
| RMM-02 Treatment actions overdue | Open treatment actions past their due date. Target: zero older than 30 days. |
| RMM-03 Acceptances past review | Accepted risks whose acceptance review date has passed. Target: zero. |
| RMM-04 Risks not reviewed this quarter | Register entries with no owner review in the last quarter (RM-09). Target: zero. |
| (calc) | A column the workbook calculates. Do not type or paste over it. |
| RM-nn, RMM-nn | Rule and measure numbers in the Risk Assessment Methodology & Scoring Model. |
| EXAMPLE | The example organisation's figures as at 2026-09-30 (R-12 is its accepted risk). Delete before approval. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 9.1 — Monitoring, measurement, analysis and evaluation | The workbook as a whole: four defined measures, calculated the same way each quarter, analysed and reported |
| ISO/IEC 27001:2022 | Clause 9.3 — Management review | What to tell executive management, and the decisions needed: input to management review |
| NIST CSF 2.0 | GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed” | Headline measures against targets, direction and Trend: risk management performance evaluated each quarter |
| NIST CSF 2.0 | GV.RM-02 — “Risk appetite and risk tolerance statements are established, communicated, and maintained” | Position against appetite, overall and by category, with each category's appetite and tolerance |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 3(a) — an indication of the approval of the risk tolerance level for ICT risk | Appetite and tolerance by category, and past-tolerance counts: the approved risk tolerance level in use |
| NIS2 — Directive (EU) 2022/2555 | Article 21(1) — appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems | The quarterly report as management's oversight of the measures that manage risk |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; Regulation (EU) 2016/679 (GDPR)