Back to Field Notes
Compliance & Regulation/Field Note

Communicating Cyber Risk to the Board — A Working Template

Boards do not need vulnerability counts. They need a clear answer to: are we more or less exposed than last quarter, and why?

Author

Diana Petrov

Director, Governance Practice

Published

April 14, 2026

Read

9 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 01Board cyber-risk reporting is often dense, technical, and unhelpful. The board's actual questions are simpler: are we more or less exposed than last quarter, why, and what is the plan? A working template structures the conversation around those questions.
  • 02Four-page template: page 1 risk posture summary (trend on a small set of agreed metrics), page 2 material changes (what changed in the threat or estate this quarter), page 3 top three risks (with owners, plans, quarterly milestones), page 4 decisions requested (where board input is needed).
  • 03Metrics the board can use: time to detect (against tested baseline), time to respond (median for confirmed incidents), coverage of critical assets by required controls, significant gaps with target close dates. Concrete, comparable, not subject to vendor marketing.
  • 04What to leave out: vulnerability counts without context, tool inventories, activity counts (alerts processed, training completed). The board does not need to manage these; the team does.

Board cyber-risk reporting is often dense, technical, and unhelpful. The board's actual questions are simpler: are we more or less exposed than last quarter, why, and what is the plan? A working template structures the conversation around those questions.

The four-page template

  • 01Page 1 — Risk posture summary: trend on a small set of agreed metrics
  • 02Page 2 — Material changes: what changed in the threat or estate this quarter
  • 03Page 3 — Top three risks: with owners, plans, and quarterly milestones
  • 04Page 4 — Decisions requested: where the board input is needed

Metrics the board can use

Time to detect (against tested baseline). Time to respond (median for confirmed incidents). Coverage of critical assets by required controls. Significant gaps with target close dates. These are concrete, comparable, and not subject to vendor marketing influence.

What to leave out

Vulnerability counts without context. Tool inventories. Activity counts (alerts processed, training completed). The board does not need to manage these; the team does.

#Board#Communication#Risk

/WRITTEN_BY

Diana Petrov

Director, Governance Practice · Alexa Cybersecurity