HireACISO

How to report security to a board

A board security update is four pages and twenty minutes. It answers what changed, what we are exposed to, what we are spending, and what we need from the directors. Control counts and vulnerability totals belong in an appendix nobody reads.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Report to a board once a quarter, in four pages, covering four things: the material changes since last time, the top risks with an owner and a date on each, spending against budget in Canadian dollars, and the decisions you need from the directors. Twenty minutes of the meeting, with an appendix for the detail. Directors are being asked to show they applied their minds to cyber risk, and they cannot do that with a slide of vulnerability counts.

For the document itself rather than the argument, the board report template has it in full, and the board report builder orders the sections around your audience and this year's driver.

The four questions directors are actually asking

Are we going to be in the news?
Answer with your top three risks, the current state of each, and what would have to go wrong. Name the scenario in plain words: a customer database exposed, payroll fraud through a compromised mailbox, ransomware that stops shipping for a week.
Are we spending the right amount?
Answer with spend to date against budget, the ratio against IT spend, and one sentence about whether it is enough. Comparable figures are on security budget benchmarks.
Are we meeting our obligations?
Contractual commitments to customers, certification status, privacy duties under PIPEDA or Law 25, and any regulator expectations. This is where a missed obligation gets found early and cheaply.
What do you need from us?
A budget approval, a policy ratification, a decision to accept a risk, or nothing. Say which. A report with no ask trains the board to stop reading.

What to leave out

Common board slides and what to replace them with
Do not presentBecausePresent instead
Number of blocked attacks It measures internet background noise, not your security Incidents that required a human decision, and how long each took
Total open vulnerabilities The number is meaningless without exposure and exploitability Critical findings on internet-facing systems, with age
Percentage of controls implemented Implemented is not the same as operating, and boards cannot tell Controls with evidence for the full period, and the exceptions
A red, amber and green heat map with no numbers The colours are an opinion presented as data Three risks with a plain-language scenario and a dollar or downtime estimate
Training completion at 100 per cent It measures clicking, not behaviour Phishing simulation report rate, and time to report. See awareness training

Say the number, or say you cannot

Directors are used to financial materiality, so a risk without a magnitude does not register. You do not need a quantitative risk model to give one. A sentence like "if this happened, we would be down for three to five days and the direct cost would be $200,000 to $500,000 CAD, before any customer loss" is defensible if you can show the working, and more useful than a red square.

Where you cannot estimate, say so, and say what it would take to find out. A security lead who admits the limits of what they know is more credible on the things they do claim.

If you only have twenty minutes

Open with the ask. Directors read the first page and the last, and a report that buries a budget request on page four gets deferred to the next quarter by default. State what you need, then justify it.

Cadence, and what happens between meetings

  1. Quarterly written report, circulated at least five days ahead, four pages plus appendix.
  2. Twenty minutes on the agenda, most of it questions rather than presentation.
  3. An annual session with more depth: the strategy, the risk appetite, and the year's budget.
  4. A standing rule that a material incident is reported to the chair within a defined window rather than waiting for the next meeting. Write the window into your incident response plan.

For public companies the fourth item is not optional. Registrants filing in the United States disclose material cybersecurity incidents on Form 8-K, and describe board oversight of cyber risk in their annual filing, which means the board has to be able to show it received something. That is covered on SEC cyber disclosure for Canadian companies. In Europe, NIS2 goes further and requires management bodies to approve the risk-management measures and to follow training, with personal liability attached.

Get someone who can carry the board conversation

Board reporting is the part of the job that is hardest to hire for and easiest to get wrong. Tell us what you need and compare fractional CISOs who have done it.

Get matched

Common questions

Should a vCISO present to the board, or should the CEO?

The vCISO should present, with the executive sponsor in the room. A board hearing security only through the CEO is hearing a filtered version, and directors generally want to ask the practitioner directly. Write the board access into the engagement, because a contractor has no standing to insist on it later.

How much detail do directors want?

Less than you think on technical detail and more than you think on consequence and money. Directors are not evaluating your control design. They are trying to establish that a competent person is on it, that the spending is proportionate, and that they will hear about a problem early.

What if the news is bad?

Report it in the quarter it happens, with what you are doing and what it will cost. The reputational damage to a security lead comes from a board discovering a known problem from somebody else, not from the problem. A first report that contains only good news is usually a report that has been edited.

Do we need a separate cyber committee?

Below about 500 people, no. Cyber risk sits with the audit committee or the full board in most Canadian companies of this size. A separate committee creates a place for the topic to be parked. Where it does make sense is in regulated financial institutions with an existing risk committee structure.