Board reporting,
a number you can defend.
A letter grade is what your audit committee wants to see. A list of CVEs is not. Translate security posture into a trend the board can read, where every number traces back to a dated scan result.
Board Reporting, step by step
Slides built by hand
A week of screenshots and spreadsheets, and numbers nobody in the room can trace back to a source.
One trend, one scale
Score movement over time, per company and across the portfolio, generated from the same evidence the security team uses.
Questions get answers
When someone asks why the number moved, you click into the finding rather than promising to follow up.

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out
Security reporting that a board cannot use
Most cyber reporting to a board fails in one of two directions. Either it is technical (CVE counts, patch percentages, an unexplained heat map) in which case the board nods and moves on having learned nothing. Or it is reassuring, a green traffic light and a paragraph about ongoing vigilance, in which case they learn less than nothing, because they now believe something they should not.
The underlying difficulty is real. A board is accountable for cyber risk but is not equipped to evaluate technical detail, and the honest answer to most of their questions is heavily qualified. So reporting drifts toward whichever failure the reporter finds less uncomfortable.
What a board can actually use is small: is our posture getting better or worse, how do we compare to peers, where is the concentrated risk, and what are we doing about it. Four questions, none of which require anybody to understand a CVSS score.
Why a direction beats a number
Open findings is a bad metric and it is the one most commonly reported. The number mostly measures how hard you looked. Deploy better tooling and it goes up, which reads to a board as posture getting worse at the precise moment it got better, so the incentive is not to look harder.
A rating trended over quarters avoids that. It is normalised, so it does not move because you changed scanner. It is directional, so the question becomes whether the line is going the right way. And it is comparable, so a board can ask how it sits against the sector without anybody constructing an argument.
It also survives the question boards actually ask, which is whether the security budget is working. A flat line after two years of increased spend is a legitimate and uncomfortable question, and a reporting model that can raise it is more valuable than one that cannot.
The part boards understand immediately
Directors who find infrastructure detail impenetrable understand supplier concentration instantly, because it is the same reasoning they already apply to counterparty and single-source risk elsewhere in the business.
A slide showing that eleven of forty critical suppliers share one cloud region, or that five sit behind one email provider, produces a governance conversation without any technical translation. It maps onto continuity planning, which boards are already comfortable governing.
This is usually the most productive item in the pack, and it is one that vendor-by-vendor review can never produce, because concentration is a property of the portfolio rather than of any supplier in it.
What to put in front of them, and what to leave out
One page of executive summary: the trend, the peer comparison, the two or three things that changed materially this quarter, and what is being done. If a director reads only this page they should still be able to govern.
Then the module breakdown for anybody who wants it, supply chain concentration, and an action plan with named owners and dates. The named owner matters more than it sounds: an action item without one is a statement of intent, and boards have learned to discount those.
Leave out raw finding lists, CVE identifiers and anything requiring the reader to know what a CVSS vector is. Those belong in the technical appendix, where the people who need them will find them and nobody else has to pretend to have read them.
What to report, and what to stop reporting
| Metric | Board-useful? | Why |
|---|---|---|
| Open finding count | No | Measures how hard you looked; rises when tooling improves |
| Patch compliance % | Rarely | Depends entirely on the denominator, which nobody checks |
| Rating trend over quarters | Yes | Normalised, directional, survives a change of tooling |
| Peer comparison | Yes | Answers 'are we where we should be' without argument |
| Supplier concentration | Yes | Maps onto continuity risk boards already govern |
| Actions with named owners | Yes | An action without an owner is an intention |
“For the first time our board pack and our security team were looking at the same number.”
Board Reporting | common questions
What should we actually report to the board?
Four things: is posture improving or degrading, how do we compare to peers, where is risk concentrated, and what is being done with named owners. Everything else belongs in an appendix.
Why is open finding count a bad metric?
Because it mostly measures how hard you looked. Better tooling raises it, which reads to a board as posture worsening at the moment it improved, so it quietly discourages looking harder.
How do we compare ourselves to peers?
Ratings are normalised, so a sector comparison is a direct read rather than a constructed argument. That is the question boards ask most often and the one internal metrics answer worst.
How often should we report?
Quarterly suits most boards, with the rating trended across quarters rather than presented as a point-in-time number. Material changes should not wait for the cycle.
Can we export this rather than rebuild it each quarter?
Yes. Reports are audience-tailored, so the board version is an executive summary and trend rather than the technical detail engineering needs, generated from the same underlying evidence.
What if the trend is flat after significant investment?
Then that is the conversation worth having, and a reporting model that can surface it is more useful than one that cannot. Boards tend to respect the question more than a green light they suspect is decorative.
Where this connects
Board pack template →
The quarterly report structure, ready to adapt.
Supply chain monitoring →
Where the concentration slide comes from.
Reports →
Audience-tailored exports for board, audit and engineering.
Put your vendors on the board
Start with ten vendors. Expand when the first alert pays for the year.