The board report in one sentence
A cybersecurity board report should help directors understand material exposure, test management’s response and make decisions. It should not be a monthly export from security tools.
This template works for a vCISO reporting to a client board, an MSP preparing an executive pack or an internal CISO improving an established report. Adapt the depth and terminology to the organisation. A listed company, a regulated bank and a 100-person software firm will not need identical packs, but their directors still need a clear view of risk, accountability and progress.
The UK NCSC’s Cyber Security Toolkit for Boards frames cyber security as an essential business risk and provides questions boards can use with management. NIST Cybersecurity Framework 2.0 also places governance at the centre of cyber risk management. Use these references to shape the discussion, not to fill the report with control codes.
Recommended report structure
Keep the main pack concise. Five to eight pages is often enough for recurring reporting, with detailed control results and project records in an appendix. Put the most important decision first.
- Executive summary and decisions required
- Material cyber risk position
- Incidents and significant changes
- Security roadmap and investment
- Assurance, compliance and third-party exposure
- Measures and trends
- Decisions, actions and accountabilities
The following sections can be copied into a reporting document or board-pack template.
1. Executive summary
Use half a page. Write it last.
Overall position: [Improving / stable / deteriorating], with confidence [high / medium / low].
What changed since the last report:
- [Change in business, threat, control performance or evidence]
- [New or closed material risk]
- [Delivery milestone, delay or dependency]
Decisions required at this meeting:
- [Decision, recommended option, owner and decision date]
- [Risk acceptance or funding request]
Management attention: [One or two points that need oversight but not a formal decision today.]
Avoid a generic traffic-light status with no explanation. If the position is amber, state what is exposed, why it matters, whether it is getting better and what management is doing.
2. Material cyber risk position
Report risks as business scenarios. Directors need to understand the event and consequence before they see a score.
| Risk scenario | Business effect | Trend | Current response | Decision or next milestone |
|---|---|---|---|---|
| Compromise of privileged cloud identity | Disruption or unauthorised access to customer data | Improving | Administrator MFA coverage expanded; service-account review open | Approve replacement of legacy integration by [date] |
| Critical supplier outage | Customer service unavailable beyond recovery objective | Stable | Alternate process documented; supplier recovery evidence incomplete | Sponsor to accept interim exposure or fund resilience option |
| Ransomware affects core operations | Service interruption and recovery cost | Deteriorating | Backup tests pass; two unsupported servers remain | Confirm retirement date and accountable owner |
For each material risk, include:
- the accountable executive owner;
- current exposure and direction of travel;
- evidence supporting the assessment;
- the target position and expected date;
- treatment cost or dependency where relevant;
- any acceptance, deferral or escalation required.
Keep the scoring method stable enough to show change. If the method changes, explain why and avoid implying that a reclassified score reflects a real reduction in exposure.
3. Incidents and significant changes
Report events that affect the risk view, not every alert handled by the service desk.
Incidents
For each significant incident, cover:
- what happened and which business services were affected;
- customer, legal, regulatory or financial consequences;
- whether notification thresholds were considered or met;
- root cause or the current working view;
- containment and recovery status;
- lessons and tracked corrective actions.
State when facts are still being established. A confident but unsupported conclusion is less useful than a clear account of what is known, unknown and due next.
Material changes
Include acquisitions, new products, major suppliers, cloud migrations, regulatory deadlines, leadership changes and shifts in the threat picture. Explain how each change affects the target profile or roadmap.
4. Security roadmap and investment
Group the roadmap around outcomes rather than product names. A useful view contains:
| Outcome | Current milestone | Status | Benefit or risk reduction | Dependency |
|---|---|---|---|---|
| Stronger identity assurance | Privileged roles moved to phishing-resistant authentication | On track | Reduces likelihood of administrator takeover | Application compatibility testing |
| Recoverable core services | Tier-one service recovery exercise | At risk | Tests whether recovery objectives can be met | Business owner availability |
| Better supplier oversight | Critical supplier evidence review | Delayed | Identifies concentration and resilience gaps | Procurement contract records |
Explain material variance in time, scope or cost. Do not hide a delayed project by reporting that most individual tasks are green. The board needs the effect of the delay on risk.
Where investment is requested, present options:
- recommended response and expected effect;
- lower-cost or phased response and residual exposure;
- consequence of deferral.
This makes the decision explicit and records the trade-off.
5. Assurance, compliance and third parties
Summarise what independent or management assurance says about the programme.
Include:
- external audits, certification reviews and penetration tests;
- overdue high-priority findings;
- customer or regulator commitments at risk;
- control areas with weak or incomplete evidence;
- material suppliers that have not provided adequate assurance;
- changes to cyber insurance requirements or coverage.
Do not present certification as proof that the organisation is secure. State its scope, date and any important exclusions. The same applies to penetration testing: it provides evidence about a defined target at a point in time.
6. Measures and trends
Choose a small set of measures connected to material outcomes. Show at least three reporting periods where possible.
Useful measure categories
Exposure measures
- number and age of unresolved material risks;
- critical internet-facing vulnerabilities beyond the agreed deadline;
- critical services without a tested recovery result;
- privileged accounts outside the required authentication standard.
Delivery measures
- roadmap milestones completed, delayed and blocked;
- overdue risk-treatment actions by accountable owner;
- audit findings closed with verified evidence;
- policy or exercise schedule completed.
Response and resilience measures
- time to contain significant incidents;
- recovery test performance against agreed objectives;
- exercise actions completed by due date;
- coverage of critical services in response and continuity plans.
Add context to every metric. “99 per cent patched” may conceal the one unpatched system that supports the company’s main revenue service. “Zero incidents” may reflect weak detection rather than low exposure.
Avoid vanity measures such as total alerts, blocked emails, raw vulnerability counts or training completion without evidence of the business outcome they represent. These can support operational management but rarely help a board decide.
7. Decisions and action record
End with a visible record. This is often the most useful page in the next meeting.
| Date | Decision or action | Accountable owner | Due date | Status |
|---|---|---|---|---|
| [date] | [Approve, accept, fund, investigate or deliver] | [named role] | [date] | [open/closed] |
Distinguish decisions from actions. “Discussed ransomware” is neither. “The board accepted the residual recovery risk until the legacy platform is retired in June, with the COO accountable” is a decision that can be reviewed.
Questions the report should answer
Before sending the pack, check whether a director can answer:
- Which cyber risks could materially affect our objectives?
- Has exposure improved or deteriorated, and what evidence supports that view?
- Who is accountable for each material risk?
- Are agreed treatments on schedule and reducing exposure?
- Which assumptions or evidence gaps reduce confidence in the report?
- Have incidents or business changes altered our priorities?
- Are important suppliers creating unmanaged concentration or resilience risk?
- Which decisions or investments are required from the board?
- What happens if those decisions are deferred?
If the answer is buried in an appendix, move it into the main pack.
Reporting workflow for a vCISO or MSP
Ten working days before the meeting
- Ask risk and control owners for updates against existing actions.
- Collect material incident, project, assurance and supplier changes.
- Check the evidence behind any claimed reduction in risk.
- Confirm new business changes with the sponsor.
Five working days before the meeting
- Draft the risk position and recommended decisions.
- Challenge inconsistencies with the relevant owners.
- Reconcile roadmap status with the risk register.
- Ask the sponsor whether the board agenda changes the required emphasis.
Two working days before the meeting
- Issue the concise pack and supporting appendix.
- Confirm who will present each decision.
- Remove unexplained acronyms and technical detail that does not affect oversight.
After the meeting
- Record decisions, owners and due dates.
- Update accepted risks and the roadmap.
- Circulate actions through the agreed governance channel.
- Preserve the report and evidence according to the client’s record-retention rules.
Common reporting failures
Starting with tool activity. Boards oversee business risk. Put endpoint, firewall or vulnerability detail in an appendix unless it changes a material conclusion.
Reporting only good news. A board cannot provide oversight if uncertainty, delays and evidence gaps are hidden. State confidence and unresolved exposure plainly.
Changing the measures every quarter. Improve measures when needed, but preserve enough continuity to show direction of travel.
Presenting risk acceptance as silence. A missed deadline is not an accepted risk. Acceptance needs an authorised owner, rationale, review date and recorded decision.
Using colour without thresholds. Define what green, amber and red mean. A status should trigger a response, not decorate a slide.
Final quality check
- The first page states the overall position and decisions required.
- Material risks are written as business scenarios with named owners.
- Trends use consistent periods and explain material movement.
- Roadmap reporting shows outcome, delay and dependency.
- Assurance claims include scope and date.
- Metrics are tied to risk or delivery decisions.
- Unknowns and evidence gaps are visible.
- Board decisions and actions are recorded separately.
- Technical detail that does not affect oversight is in an appendix.
The test is simple: after reading the pack, directors should know what could materially go wrong, whether management’s response is working and what they are being asked to decide.