Cyber security board reporting

How to Write a Cyber Security Board Report

A cyber security board report is the document that translates technical security activity into the handful of decisions, risks, and assurances a board actually needs. Most are written for the wrong audience: dense with controls, alerts, and patch counts that mean nothing to a non-executive director, and silent on the one question the board is accountable for, namely whether cyber risk is being managed within the appetite they set. This guide gives you a four-component structure, a complete template you can reuse, and the metrics that belong in front of a board.

Book a conversation

What a Cyber Security Board Report Is For

A board does not need to understand your firewall configuration. It needs to discharge its governance duty: confirm that material cyber risks are identified, that they are being treated to a level the board has agreed, and that the investment and decisions required are on the table. A good report serves four purposes.

  • It shows the board where the organisation stands against a defined target, not in absolute technical terms.
  • It frames cyber as business risk: what could happen, how likely, what it would cost, and how it compares to the board’s stated risk appetite.
  • It surfaces the decisions the board must make, usually about investment, acceptance of residual risk, or response to a material incident.
  • It creates a documented trail that the board exercised oversight, which matters to regulators, insurers, and acquirers.

Why Most Cyber Security Board Reports Fail

The recurring failures are predictable, and every one of them costs the board’s attention.

  • Written for engineers, not directors. Vulnerability counts, alert volumes, and tool names belong in an operational review, not a board pack.
  • Vanity metrics. Reporting that you blocked four million emails tells the board nothing about whether the organisation is safe. It rewards activity, not outcome.
  • No business framing. Risk is reported in technical severity, never in pounds, downtime, or regulatory exposure.
  • No trend. A single snapshot cannot show whether the position is improving or deteriorating.
  • No decision asked. A report that requests nothing leaves the board as passive readers rather than accountable governors.

The Four-Component Structure

Every cyber security board report should answer four questions, in this order. Keep each component to a single page or less.

# Component The question it answers
1 Posture Where do we stand today against the target we agreed?
2 Risk What are our top cyber risks, and are they inside the board’s appetite?
3 Incidents and threats What happened since the last report, and what is changing around us?
4 Decisions and investment What does the board need to decide, approve, or accept?

1. Posture. Report maturity against a recognised framework such as NIST CSF, ISO 27001, or Cyber Essentials, expressed as a simple current versus target score with a direction of travel. A board can act on a statement that you are at 2.8 against a target of 3.5 and improving far more readily than on a list of open findings.

2. Risk. Present the three to five most material cyber risks. For each, state the business impact in plain terms, the likelihood, the current treatment status, and whether the residual risk sits inside or outside the appetite the board has set. This is the component non-executives engage with most, because it is the one they are accountable for.

3. Incidents and threats. Summarise any incidents since the last report, what was learned, and what changed as a result. Add a short, honest read on the external threat landscape relevant to your sector, so the board understands the context they are governing.

4. Decisions and investment. End with what you are asking for. Every report should make a clear request: approve this investment, accept this residual risk, or note this position. A report that asks for nothing is an update, not governance.

Cyber Security Board Report Template

Use this as a one-page summary followed by four short sections. Copy it, populate it, and keep it to about four pages plus appendices.

Section What to include
Executive summary Three sentences: overall posture and direction, the single most important risk, and the decision being requested.
1. Posture Current versus target maturity score, framework used, trend since last report, and the two or three drivers behind any change.
2. Risk register extract Top three to five risks: impact in business terms, likelihood, owner, treatment status, residual versus appetite.
3. Incidents and threat landscape Incidents this period, lessons applied, and sector-relevant threat changes.
4. Decisions requested Each decision stated as approve, accept, or note, with the cost and the consequence of inaction.
Appendix Supporting detail, metrics, and programme status for directors who want to go deeper.

Metrics That Belong in a Board Report

The test for any metric is simple: does it help the board make a decision or judge whether risk is within appetite? If not, it belongs in an operational report. These earn their place.

  • Maturity score against framework, current versus target, with trend
  • Number of risks outside the agreed appetite, and the plan to close them
  • Time to detect and time to respond to incidents
  • Percentage of critical systems covered by tested backups and recovery
  • Status of the agreed improvement programme against plan and budget
  • Third-party and supply-chain risks rated material

Leave these out of the board pack. They are operational, not governance.

  • Raw counts of blocked emails, malware samples, or firewall hits
  • Total number of vulnerabilities without business context
  • Tool names, dashboards, and configuration detail
  • Patch percentages with no link to risk or critical systems

What the ICO Penalises, and Why Board Oversight Matters

Cyber security is a board accountability, not a delegated technical function, and UK regulators treat it that way. The Information Commissioner’s Office has issued substantial penalties where security failures harmed people’s data, and the board is where responsibility ultimately sits.

  • British Airways, 20 million pounds (2020). A 2018 attack compromised the personal and payment data of more than 400,000 customers. The ICO found that security measures which should have been in place were not.
  • Marriott International, 18.4 million pounds (2020). A breach of the Starwood reservation system exposed an estimated 339 million guest records worldwide, and went undetected for years.
  • Interserve, 4.4 million pounds (2022). A phishing email led to a ransomware attack affecting the data of 113,000 employees. The ICO criticised the company for failing to act on an earlier alert, a governance failure as much as a technical one.

In each case the controls and the response were management’s job, but the accountability was the board’s. A clear board report is the mechanism by which directors discharge that duty, and the evidence that they did.

How Often Should You Report Cyber Security to the Board?

Cyber security should appear on the full board agenda at least quarterly. A risk or audit committee should see a fuller version more often, typically monthly or every two months, with the headlines rolled up to the board. Material incidents and any risk that moves outside appetite should be reported as they happen, not held for the next scheduled meeting. The cadence matters less than the consistency: the same structure every time, so the board can read the trend at a glance.

Frequently Asked Questions

What should a cyber security board report include?

Four components: posture against a target, the top three to five risks measured against the board’s appetite, incidents and threat changes since the last report, and the decisions the board is being asked to make. Lead with a three-sentence executive summary and keep the whole report to about four pages plus appendices.

How long should a cyber security board report be?

Four pages or fewer for the report itself, with one page per component and a short executive summary on top. Detail belongs in an appendix for directors who want it. A board report that runs to twenty pages of technical metrics will not be read, and it is not serving its governance purpose.

Who should present cyber security to the board?

Whoever owns security accountability, usually a CISO, CIO, or a fractional or virtual equivalent. The presenter must be able to translate technical posture into business risk and answer questions in the board’s language rather than retreat into jargon. Where an organisation has no full-time security leader, a virtual CISO often fills this role.

How do you present cyber risk to a non-technical board?

Frame every risk in business terms: what could happen, how likely it is, what it would cost in money, downtime, or regulatory exposure, and whether it sits inside the appetite the board agreed. Use a single maturity score with a trend rather than technical detail, and always end with a clear decision the board can take.

How often should cyber security be on the board agenda?

At least quarterly for the full board, more frequently for a risk or audit committee, and immediately for any material incident or any risk that moves outside appetite. Consistency of structure matters as much as frequency, so the board can track the direction of travel from one report to the next.

Board-level technology leadership

Turn cyber risk into decisions your board can act on

Starkhorn provides board-ready cyber security reporting and the fractional CIO and CISO leadership behind it: posture, risk, and the decisions that follow, in language the board understands.
Book a conversation

Leave a Reply

Your email address will not be published. Required fields are marked *