BOARD REPORTING
What Should a CISO Report to the Board?
Boards are now accountable for cyber risk, but most security reporting is written for engineers, not directors. This page sets out what a CISO should actually put in front of a board, what to leave out, and how to translate technical risk into decisions.
Book a conversationWhere security leadership succeeds or fails
A CISO can run an excellent programme and still lose the board, because the board does not experience the programme, it experiences the report. If the reporting is a wall of technical metrics, directors cannot govern the risk they are accountable for, and security becomes a cost they cannot interrogate. Board reporting is not an afterthought to the security job; it is where the job is judged.
What a board actually needs
A board does not need to know how many patches were applied or which tool blocked what. It needs to know whether the organisation’s cyber risk is within the level it is willing to accept, what has changed, whether the plan is working, and whether it can trust that the controls are real. Everything in a good report serves one of those four questions.
The four things to report
- Current risk posture against the board’s stated risk appetite, in business terms
- Material changes and incidents since the last report, and what they mean
- Progress against the agreed security plan, so investment can be judged
- Assurance that the controls work, from testing, audit or independent review
What to leave out
Vanity metrics erode a board’s confidence rather than building it. Patch counts, blocked-email totals, tool inventories and colour-coded dashboards with no narrative tell a director nothing they can act on. Strip them out. If a number does not change a decision the board might make, it does not belong in the board report, however satisfying it is to present.
How often, and in what form
Quarterly is the right rhythm for most boards, with immediate escalation for anything material in between. Keep it short, ideally a page or two, and show trend rather than a single snapshot, because the direction of travel matters more than any one figure. This is the discipline behind our work on board cyber governance and it sits alongside broader board IT strategy.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
Daniel has reported cyber risk to boards and investment committees under real scrutiny, and can translate a technical security posture into the handful of things a director actually needs to decide on.
Frequently asked questions
What should a CISO report to the board?
Four things: the current risk posture against the board’s risk appetite in business terms, material changes and incidents since the last report, progress against the security plan, and assurance that the controls actually work. Everything else is detail the board does not need.
How often should a CISO report to the board?
Quarterly suits most boards, with immediate escalation for anything material in between. The cadence should let the board govern the risk without drowning in updates it cannot act on.
What security metrics matter to a board?
Metrics that change a decision: risk against appetite, the business impact of incidents, and evidence that controls work. Patch counts, blocked-email totals and tool inventories do not help a director govern and should be left out.
What should a CISO not report to the board?
Vanity metrics and raw technical detail. If a number does not inform a decision the board might make, it does not belong in the board report. Colour-coded dashboards with no narrative are a common example that adds noise, not assurance.
How do you translate technical risk into business terms?
Frame each risk by what it could cost the business, how likely it is, and whether it sits inside or outside the board’s stated appetite. Directors can govern that; they cannot govern a list of vulnerabilities.
NEXT STEP
Can your board answer for its cyber position?
The free Board Cyber Governance check shows where the reporting and accountability gaps sit, from the board’s point of view. When you want to talk it through, a conversation is the next step.
Board Cyber Governance check Book a conversation