A common pattern in board reporting is a security update that is accurate, thorough and largely undiscussed. The information is there, but it does not give the people in the room anything they can act on.

Counts are not risk

Dashboards tend to report volume: findings open, patches applied, alerts triaged, training completed. These describe activity rather than exposure, and they lead to a predictable question that nobody can answer well - is that number good or bad?

A board is trying to establish three things: what could plausibly go wrong, how bad it would be, and whether the current investment is proportionate. Metrics that do not help answer those questions will be acknowledged and set aside.

Anchor discussion in scenarios

Scenarios translate technical detail into consequences without requiring technical background. A small number, specific to the organization, works better than an abstract risk register.

For example: a compromised administrator account leading to customer data exposure; a critical SaaS platform unavailable for two days; a supplier breach affecting data you are accountable for. For each, describe the plausible business impact, what currently reduces the likelihood, what would limit the damage, and what remains unaddressed.

This format invites a decision. A list of vulnerabilities does not.

Be honest about uncertainty

Precise-looking probabilities and financial estimates tend to attract scrutiny that the underlying data cannot support. It is more credible to say that an outcome is plausible, that the exposure would be material, and to explain the reasoning behind that judgement.

Equally, findings should not be inflated to secure attention. Overstatement works once. After that, subsequent reporting is discounted, including the parts that genuinely warrant concern.

Always attach a decision

Every item presented should make clear what is being asked: accept this risk, fund this work, accept a delay, or note that the position has improved. Risk that is reported repeatedly without a decision point becomes background noise.

Acceptance is a legitimate outcome. Recording it explicitly - with who accepted it and when it will be revisited - is more useful than leaving an unresolved finding open indefinitely.

Keep the trend visible

Boards are generally more interested in direction than in absolute state. Is exposure increasing or decreasing? Are the same issues recurring? Did the work funded last quarter change anything measurable?

A short, consistent report that answers those questions each time builds understanding over successive meetings. That accumulated context is what allows a board to engage with technology risk as a business matter rather than deferring to whoever is presenting it.

Related topics

Building a More Resilient Digital Environment · Cybersecurity Considerations for AI Adoption

← Back to Insights