HireACISO

Board security report builder

The structure of a board security report changes with who reads it and what drove security this year. This lays out the sections in the right order for your situation, with the prompt for each one and the measures worth trending.

Last reviewed 2026-08-31Written by Jacob Masse, TrazTech Inc.

A board security report has one job: give directors enough to discharge their duty of care and make the two or three decisions only they can make. The sections that carry that job are the same everywhere. Their order, their weight and the prompts under them are not, and getting the order wrong is why so many of these reports generate a discussion instead of a decision.

Five questions. The full outline appears on this page with the prompt for every section, and nothing is emailed anywhere unless you ask for it at the end. What belongs in each section, and why a director needs it, is set out at length on the board report template.

Who is this report actually for?

The audience changes which sections carry the weight more than anything else does.

What is driving security this year?

What happened in the period being reported?

Near misses belong in the report. A quarter with nothing in it is a claim that needs supporting.

Which measures can you actually produce this quarter?

Tick only what you can put a real number against. A measure you cannot produce every quarter is worse than one fewer measure.

What are you asking the board to decide?

A report with no ask is a briefing. That is a legitimate choice once in a while and a bad habit every quarter.

Two items every version carries

Whatever the outline says, these belong in the report and are the two most commonly missing. Accepted risks, with the name of whoever accepted them and the date, because accepting risk on the company's behalf is a governance act and a risk the board was never told about has not been accepted. And the count of entries in your PIPEDA breach record register, because the record of every breach has to be kept for 24 months whether or not it was reportable, and an empty register is either good news or an absence of monitoring.

Who writes it

Whoever owns the security program, and they should be in the room to answer the follow-up. For most Canadian companies between 50 and 500 people that is a fractional or virtual CISO rather than an employee, and board reporting is one of the deliverables worth naming explicitly in the engagement, because it quietly consumes a large share of a retainer. The hours calculator shows what that share looks like at your size.

Common questions

How long should a board security report be?

Five pages of substance plus an appendix nobody is obliged to read. The one page summary should stand alone, because for some directors it will be the only page read before the meeting. Length is not a proxy for rigour, and a long report usually means nobody was willing to decide what mattered.

How many measures should we trend?

Four to six, the same ones every quarter, each with a target. Changing the measures each quarter is how a program hides. If you can only produce two honestly, report two and say what you are building to be able to report the rest, which is itself a useful thing for a board to hear.

Should we report a maturity score?

Only if you will show the same score every quarter and explain the movement. A single number is useful as a trend and misleading as a snapshot, because a board has no way to judge whether 2.8 is good. The maturity assessment scores seven domains separately for exactly that reason.

What if nothing happened this quarter?

Say so, and say why you believe it. A clean quarter means either the controls held or you cannot see what is happening, and the report should make clear which. Reporting near misses is what makes a quiet quarter credible.

Need someone to own the reporting

Tell us what your board is asking for and we will match the scope to Canadian providers who write and present this material.

Get matched