CISO board report template, section by section
A board security report has one job: give directors enough to discharge their duty of care and make the two or three decisions only they can make. Most reports fail because they report activity instead.
A quarterly security report to a board should run to about five pages and contain nine things: a one-page summary, the risk position and how it moved, incidents and near misses in the period, compliance and audit status, a short set of trended control measures, third-party exposure, progress against the roadmap, spend against budget, and the decisions being asked of the board. Everything else belongs in an appendix or in a different meeting.
The structure below is what works in front of Canadian boards and audit committees at companies between 50 and 500 people. The board report builder at the foot rearranges it for your audience.
The test every section has to pass
A director reading your report is discharging a duty of care. Under the Canada Business Corporations Act, directors must exercise the care, diligence and skill a reasonably prudent person would in comparable circumstances. That is the standard your report exists to support. If a section does not help a director make a decision, ask a better question, or demonstrate that the board applied its mind to a risk, cut it.
1. The one page summary
Written last, read first, and for many directors the only page read at all. It carries the overall risk position in a sentence, the single most important change since the last meeting, anything that happened that a director would be embarrassed to hear about from somebody else, and the decisions you are asking for. Put the decisions on this page, not at the end. A report that buries the ask on page five gets a discussion instead of a decision.
Write it in business language. Not "we remediated 14 critical findings" but "the two issues that could have exposed customer data are closed, and the remaining work is scheduled for the second quarter". A director is not qualified to judge the first sentence and is qualified to judge the second.
2. Risk position and how it moved
Five to eight risks, no more, expressed as business consequences rather than technical conditions. Each one gets a current rating, the rating last quarter, a named owner who is an executive rather than an engineer, and one line on what changed. The movement column is the section's whole value. A static risk register tells a board nothing, and a register where everything is amber forever tells them the ratings are decorative.
Include accepted risks explicitly, with who accepted them and when. It is the most commonly missing item in reports written by technical people, and the one a director most needs. Accepting a risk on the company's behalf is a governance act, and a risk the board has never been told was accepted has not been accepted.
How a risk line should read
The difference between a line a director can act on and a line they cannot is whether it names a consequence, a number and a person.
| Weak version | Version a director can use |
|---|---|
| Legacy systems present elevated risk | The billing platform runs on an unsupported database. If it fails we cannot invoice for an estimated two weeks. Replacement is budgeted at $180,000 CAD and scheduled for Q3. Owner: CTO |
| Third-party risk is being addressed | Four of our eleven suppliers holding customer data have not completed a security review. Two are contractually overdue. Owner: COO, target end of Q2 |
| Phishing remains a threat | Two staff entered credentials into a phishing page this quarter. Multi-factor authentication stopped both. This is the control we are relying on and we have tested that it holds |
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
3. Incidents and near misses
Every incident in the period, including the ones that came to nothing, with what happened, what the impact was, what stopped it, and what changed as a result. Near misses matter more than a clean quarter, because a clean quarter usually means either good controls or poor detection and the report should say which.
For Canadian companies this section carries a statutory hook. PIPEDA requires you to report breaches of security safeguards that create a real risk of significant harm to the Privacy Commissioner and to affected individuals, and separately requires you to keep a record of every breach for 24 months whether or not it was reportable. The board should see the count of records in that register each quarter. If the register is empty, say so and say why you believe it, because an empty breach register is either good news or an absence of monitoring.
4. Compliance and audit status
One line per obligation: what it is, what state it is in, the next date that matters, and whether that date is at risk. Cover the voluntary frameworks such as SOC 2 or ISO 27001 and the statutory obligations together, because directors do not distinguish between them and should not have to. Where you operate in Quebec, Law 25 obligations belong here. Where you hold Ontario health information, PHIPA does. Where you bid on federal work, the security conditions in the solicitation do.
Be specific about audit findings. A board that hears "the audit went well" for three quarters and then hears about a qualified opinion has been badly served. Report open findings with dates, and report the ones you are going to miss before you miss them.
5. A small number of trended measures
The measure set
Four to six, the same ones every quarter, each with a target and a trend line. Changing the measures each quarter is how a program hides. The measures that survive contact with a board describe whether a control is working, not how much activity occurred.
- Percentage of staff and contractors covered by multi-factor authentication, including administrative and service accounts.
- Time to remove access after someone leaves, measured as a maximum rather than an average.
- Percentage of critical vulnerabilities remediated inside the policy window, with the count of exceptions.
- Backup restores tested in the period, and whether each succeeded.
- Security review completion rate for suppliers holding customer data.
- Open audit findings past their due date.
Measures to leave out
Resist the count of blocked attacks, the count of alerts, and anything produced by a tool's default dashboard. Those measure the internet, not your program.
6. Third parties
Directors have become alert to supplier risk because most publicised failures now arrive through one. Report how many suppliers hold customer or employee personal information, how many have been reviewed, which reviews are overdue, and any supplier incident that touched you. PIPEDA makes you accountable for personal information transferred to a third party for processing, which means a supplier's failure is your failure in the Commissioner's eyes. Say that to the board once a year.
7. Roadmap progress and spend
What was planned for the quarter, what landed, what slipped and why. Slipped items need a reason and a new date, not a colour. Pair it with spend against budget and, more importantly, with what additional money would buy. A board cannot fund a request it has not seen quantified, and "we need more resources" is not a request. "Two hundred thousand dollars adds a security engineer, which takes vulnerability remediation from 60 percent inside window to 90 percent" is a request.
8. The decisions you are asking for
Usually two or three, sometimes none, and this is the section that distinguishes a report from a briefing. Risk acceptances that exceed the tolerance the board has set, budget approvals, policy approvals, and any appetite question where the answer is properly the board's rather than management's. Write each as a proposition the board can accept or decline, with the consequence of each option, and record the answer in the minutes.
What to leave out
Most of what technical teams want to include. Vulnerability counts by severity, tool screenshots, CVE identifiers, architecture diagrams, project plans, and any status colour without a written definition of what it means. All of it belongs in an appendix that nobody is required to read. A five page report that is read is worth more than a thirty page report that is skimmed.
And leave out reassurance
A report that says the company is secure is either wrong or unfalsifiable. What a board can act on is a clear statement of what you are exposed to, what you are doing about it, and what you have decided to live with.
How often, and who writes it
Quarterly to the full board or the audit committee, with a short written update between meetings if something material happens. Annual is too infrequent to show movement and monthly is more governance than a company of this size needs. Whoever owns the security program writes it, which for most companies at this scale is a fractional or virtual CISO rather than an employee, and board reporting is one of the deliverables to name explicitly in that engagement. It consumes a large share of a retainer, so check it is priced in rather than assumed.
For federally regulated financial institutions the bar is higher and set externally: OSFI's technology and cyber risk guidance expects senior management and the board to receive regular, meaningful reporting on technology and cyber risk. If that applies to you, build the report around your regulator's expectations first and use the structure here to fill the gaps.
Take the template away
The nine sections above are the template and there is nothing withheld. Print the page, or copy the headings into your own document and work down them. The board report builder asks five questions and lays the same sections out with the emphasis shifted to whoever is reading, then offers the editable document.
Before you write the first draft
Each item is one a director will notice the absence of, and most are facts to collect rather than prose to write.
0 of 0 ready ·
Print it
This page prints to a few pages without anything cut off. Take it into the room on paper and work down the headings. Nothing here is behind a form: the email field on the builder buys the same template as an editable document.
Somebody has to write this every quarter
If nobody currently owns the security program, board reporting is one of the deliverables to name in the engagement. Tell us what your board is asking for and we will match it to Canadian providers who write and present this material.
Get matchedCommon questions
How long should a board security report be?
Five pages of substance plus an appendix nobody is obliged to read. The one page summary should stand alone, because for some directors it will be the only page read before the meeting. Length is not a proxy for rigour, and a long report tends to be a sign that nobody was willing to decide what mattered.
Should the report include a maturity score?
Only if you are going to show the same score every quarter and explain the movement. A single number is useful as a trend and misleading as a snapshot, because a board has no way to judge whether 2.8 is good. If you do use one, name the model, keep the assessor consistent, and never let the score replace the risk section.
Who should present the security report to the board?
Whoever owns the security program, which should be a named individual who can answer a follow-up question in the room. Having the CTO present it is workable in a small company but creates a governance problem when the person building the platform is also the person assuring it, and audit committees notice. If a fractional CISO owns the program, they should present it and be in the room.
What do directors ask that reports fail to answer?
Three questions, reliably. What would hurt us most if it happened tomorrow. What are we choosing not to fix, and who decided that. And are we getting better or worse. A report that answers those three directly will survive almost any board, and one that does not will generate the same questions verbally every quarter.
Is a board report required by law in Canada?
Not as a specific document for most companies. What exists is the directors' duty of care under corporate statutes, which is discharged in part by being informed, and sector rules that go further. Federally regulated financial institutions have explicit expectations from OSFI about board level technology and cyber risk reporting. For everyone else the report is how you evidence that the board applied its mind, which matters most in the aftermath of an incident.