Use case · Enterprise

Board reporting,
a number you can defend.

A letter grade is what your audit committee wants to see. A list of CVEs is not. Translate security posture into a trend the board can read, where every number traces back to a dated scan result.

How it works

Board Reporting, step by step

Before

Slides built by hand

A week of screenshots and spreadsheets, and numbers nobody in the room can trace back to a source.

With GuardianGaze

One trend, one scale

Score movement over time, per company and across the portfolio, generated from the same evidence the security team uses.

Result

Questions get answers

When someone asks why the number moved, you click into the finding rather than promising to follow up.

Third-party vendor inventory scored by security rating, tier and risk category

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out

The problem

Security reporting that a board cannot use

Most cyber reporting to a board fails in one of two directions. Either it is technical (CVE counts, patch percentages, an unexplained heat map) in which case the board nods and moves on having learned nothing. Or it is reassuring, a green traffic light and a paragraph about ongoing vigilance, in which case they learn less than nothing, because they now believe something they should not.

The underlying difficulty is real. A board is accountable for cyber risk but is not equipped to evaluate technical detail, and the honest answer to most of their questions is heavily qualified. So reporting drifts toward whichever failure the reporter finds less uncomfortable.

What a board can actually use is small: is our posture getting better or worse, how do we compare to peers, where is the concentrated risk, and what are we doing about it. Four questions, none of which require anybody to understand a CVSS score.

Trend over count

Why a direction beats a number

Open findings is a bad metric and it is the one most commonly reported. The number mostly measures how hard you looked. Deploy better tooling and it goes up, which reads to a board as posture getting worse at the precise moment it got better, so the incentive is not to look harder.

A rating trended over quarters avoids that. It is normalised, so it does not move because you changed scanner. It is directional, so the question becomes whether the line is going the right way. And it is comparable, so a board can ask how it sits against the sector without anybody constructing an argument.

It also survives the question boards actually ask, which is whether the security budget is working. A flat line after two years of increased spend is a legitimate and uncomfortable question, and a reporting model that can raise it is more valuable than one that cannot.

The supply chain slide

The part boards understand immediately

Directors who find infrastructure detail impenetrable understand supplier concentration instantly, because it is the same reasoning they already apply to counterparty and single-source risk elsewhere in the business.

A slide showing that eleven of forty critical suppliers share one cloud region, or that five sit behind one email provider, produces a governance conversation without any technical translation. It maps onto continuity planning, which boards are already comfortable governing.

This is usually the most productive item in the pack, and it is one that vendor-by-vendor review can never produce, because concentration is a property of the portfolio rather than of any supplier in it.

The pack

What to put in front of them, and what to leave out

One page of executive summary: the trend, the peer comparison, the two or three things that changed materially this quarter, and what is being done. If a director reads only this page they should still be able to govern.

Then the module breakdown for anybody who wants it, supply chain concentration, and an action plan with named owners and dates. The named owner matters more than it sounds: an action item without one is a statement of intent, and boards have learned to discount those.

Leave out raw finding lists, CVE identifiers and anything requiring the reader to know what a CVSS vector is. Those belong in the technical appendix, where the people who need them will find them and nobody else has to pretend to have read them.

Metrics

What to report, and what to stop reporting

MetricBoard-useful?Why
Open finding countNoMeasures how hard you looked; rises when tooling improves
Patch compliance %RarelyDepends entirely on the denominator, which nobody checks
Rating trend over quartersYesNormalised, directional, survives a change of tooling
Peer comparisonYesAnswers 'are we where we should be' without argument
Supplier concentrationYesMaps onto continuity risk boards already govern
Actions with named ownersYesAn action without an owner is an intention
“For the first time our board pack and our security team were looking at the same number.”
CISO · Mid-market financial services group
FAQ

Board Reporting | common questions

What should we actually report to the board?

Four things: is posture improving or degrading, how do we compare to peers, where is risk concentrated, and what is being done with named owners. Everything else belongs in an appendix.

Why is open finding count a bad metric?

Because it mostly measures how hard you looked. Better tooling raises it, which reads to a board as posture worsening at the moment it improved, so it quietly discourages looking harder.

How do we compare ourselves to peers?

Ratings are normalised, so a sector comparison is a direct read rather than a constructed argument. That is the question boards ask most often and the one internal metrics answer worst.

How often should we report?

Quarterly suits most boards, with the rating trended across quarters rather than presented as a point-in-time number. Material changes should not wait for the cycle.

Can we export this rather than rebuild it each quarter?

Yes. Reports are audience-tailored, so the board version is an executive summary and trend rather than the technical detail engineering needs, generated from the same underlying evidence.

What if the trend is flat after significant investment?

Then that is the conversation worth having, and a reporting model that can surface it is more useful than one that cannot. Boards tend to respect the question more than a green light they suspect is decorative.

Related

Where this connects

Board pack template →

The quarterly report structure, ready to adapt.

Supply chain monitoring →

Where the concentration slide comes from.

Reports →

Audience-tailored exports for board, audit and engineering.

Put your vendors on the board

Start with ten vendors. Expand when the first alert pays for the year.