Risk Management
Security Governance That Boards Actually Use

How to report on security and risk in a way that supports decisions rather than filling an agenda slot.
Board reporting on security has a recognisable failure mode: a dense pack of metrics that nobody challenges, followed by a decision to defer. The problem is rarely the board. It is the report.
Under NIS2 and DORA, management bodies carry explicit accountability for cyber risk oversight. That raises the stakes on reporting quality considerably: a director who cannot demonstrate that they were given the information needed to govern is in a materially worse position than one who declined a clearly presented recommendation.
The fix is not a longer pack. It is a shorter one that makes the exposure, the options and the decision unmistakable — and that leaves a record of what was put in front of whom, and when.
Report exposure, not activity
Patch counts, training completion rates and ticket volumes measure activity. They tell a board nothing about whether exposure went up or down this quarter. Lead with the small number of things that changed the organisation's risk position, and say by how much.
Where a number is an estimate, label it as one and state the assumption. Boards handle uncertainty well when it is made explicit and badly when it is hidden behind false precision.
A useful discipline is to ask what a metric would have to do before anyone acted on it. If phishing simulation click rates fell from 12% to 9%, would any decision change? If not, the number is reassurance rather than information, and it is occupying space that a consequential number could use. The metrics worth a board's attention are the ones with a threshold attached and a named consequence for crossing it.
Trend direction usually matters more than absolute value. A board rarely needs to know that there are 14,000 unpatched findings; it needs to know that critical externally-facing exposure has been rising for three consecutive quarters despite additional spend, because that combination is the one that calls for a decision.
Bring decisions, not updates
Every security paper should end with a request: approve this investment, accept this residual risk in writing, or assign this owner. A paper with no decision attached is an information item, and information items get skimmed.
Written risk acceptance is also the mechanism that makes accountability real — in both directions. It protects the security function from carrying a risk it never had the budget to address, and it gives the board a documented basis for the trade-offs it chose. Under NIS2 and DORA, where management bodies hold explicit responsibility for cyber risk oversight, that record has moved from good governance hygiene to evidence a supervisor may ask to see.
Give each decision a stated expiry. A risk accepted in writing should return for review at a defined point rather than remaining accepted indefinitely, because the conditions that justified acceptance — a compensating control, a planned migration, a quiet trading period — rarely hold for long.
Respect what the board is for
Non-executive directors bring judgement about capital allocation, reputation and strategic risk. They are not the right audience for architectural detail, and presenting it invites either deference or an unhelpfully narrow line of questioning. Translate technical exposure into the consequences they are equipped to weigh: revenue at risk, regulatory exposure, customer commitments that could not be met.
Assume roughly fifteen minutes of genuine attention and build the paper accordingly — one page that stands alone, with the detail available as an annexe for anyone who wants it. A board that reads one page carefully governs better than one that skims forty.
Keep the same three charts
Consistency beats comprehensiveness. Three well-chosen views, reported identically every quarter, allow a board to develop intuition for the trend. A new dashboard each quarter resets that intuition to zero.
This requires resisting the temptation to redesign the pack whenever a new tool produces a more attractive visualisation. The value of a chart a board has seen eight times is that they notice the anomaly without being told — and that recognition is worth more than any improvement in presentation.

Olha Mann
Founder & Principal Consultant
CISSP · CISM · CEH · ISO/IEC 27001:2022 Lead Auditor



