Board pack template.
A board-ready quarterly cyber posture report: cover, executive summary, six-module breakdown, supply-chain hotspots and an action plan. Use it as scaffolding, the in-product board pack auto-fills every section.
Cover and executive summary
One page. Three numbers. The board reads no further than this unless something is on fire.
| 01: Company rating | Letter grade and numeric score, with the delta against last quarter. |
| 02: Critical findings open | Count, ageing, and a named owner for each. |
| 03: Supply-chain hotspots | Top three vendors by risk contribution. |
| 04: One paragraph | What changed, why, and what we are doing about it. |
Six-module breakdown
One page per module: score, trend line, top three open findings and remediation status. Designed to be read in four minutes by a non-technical director.
- Page 2: Brand protection
- Page 3: Domain security
- Page 4: Application security
- Page 5: Network security
- Page 6: Cloud security
- Page 7: Compliance posture
Supply-chain hotspots
Two pages. The top ten vendors by risk contribution to your aggregate posture, highlighting those trending downward, those that breached remediation SLA, and any with a public security incident in the quarter. Columns: vendor, rating, delta, contract value, action.
Action plan
One page, five rows. Each row is a specific action with a named owner, a due date and a measurable expected impact on the rating. No vague “continue to improve” verbs.
| Retire 7 unused legacy subdomains | Platform team · end Q3 · +4 rating points |
| Enforce DMARC reject policy | IT ops · end Q2 · +3 rating points |
| Off-board 2 D-rated vendors | Procurement · at renewal · removes 8% of aggregate risk |
One page a director can act on, then everything else
The discipline that makes a cyber board pack work is deciding what happens if the reader gets no further than page one. If a director reads only the executive summary, they should still be able to govern, which means the summary carries the direction of travel, the peer comparison, the two or three things that changed materially, and what is being done about them.
Everything after that page exists for the directors who want it and the audit committee who will read it properly. Module breakdown, supply-chain concentration, the action plan, and a technical appendix nobody is obliged to open.
The most common structural mistake is leading with detail and burying direction. A pack that opens with a findings table has already lost the reader it was written for.
What to include, and what to stop including
Drop open finding count. It measures how hard you looked, and it rises when tooling improves, which reads to a board as posture worsening at the moment it got better. Reporting it creates a quiet incentive not to look harder.
Include the rating trended across quarters, because it is normalised and directional and survives a change of tooling. Include peer comparison, because it answers the question boards ask most often and internal metrics answer worst. Include supplier concentration, because directors understand it immediately: it is the same reasoning they already apply to counterparty and single-source risk.
Include actions with named owners and dates. An action item without an owner is a statement of intent, and boards have learned to discount those.
Usually the most productive item in the pack
Directors who find infrastructure detail impenetrable understand concentration risk instantly. A slide showing that eleven of forty critical suppliers share one cloud region, or five sit behind one email provider, needs no technical translation at all.
It also lands in territory boards are already comfortable governing: continuity planning, single-source dependency, and whether the assumption that failures are independent actually holds. Most continuity plans quietly assume independence, and this is the slide that tests it.
It is a portfolio property rather than a vendor property, which is why vendor-by-vendor review never produces it however thorough that review is.
Adapt it rather than adopting it
This is the structure we would use ourselves, not a format that will fit your board unchanged. Reporting conventions differ, committee structures differ, and a pack that ignores an organisation's existing conventions gets rewritten by whoever presents it.
The parts worth keeping regardless: the single-page summary discipline, trend rather than count, peer comparison, and named owners. The parts to adjust: depth of the module breakdown, how much technical appendix your audit committee expects, and the reporting cadence.
If a quarterly cadence is what your board runs on, material changes should still not wait for the cycle. The pack is the routine; alerting is what covers the gap between packs.
Common questions
What should the first page contain?
Direction of travel, peer comparison, the two or three material changes this quarter, and what is being done with named owners. If a director reads only that page they should still be able to govern.
Why drop open finding count?
It measures how hard you looked. Better tooling raises it, which reads as posture worsening at the moment it improved, so it quietly discourages looking harder.
Why does the supply chain slide work so well?
Because concentration risk maps onto counterparty and single-source thinking directors already do. It needs no technical translation, and it tests the assumption in most continuity plans that supplier failures are independent.
How often should we report?
Quarterly suits most boards, with the rating trended across quarters. Material changes should not wait for the cycle: that is what alerting is for.
Can we use this template unchanged?
Adapt it. Reporting conventions and committee structures differ, and a pack that ignores your existing conventions gets rewritten by whoever presents it.
See your own pack
The template is scaffolding; the rating is what fills it in.
Your external rating becomes the seed for the first board pack.