How should IT and cybersecurity risk be reported to the board?
Report IT and cybersecurity risk to the board in business terms: the top risks and their potential impact, whether each is improving or worsening, decisions or funding needed, recent incidents and lessons, and readiness to respond. Keep it short, consistent quarter to quarter, and mapped to a recognized framework such as NIST CSF 2.0. Public companies also have SEC disclosure obligations on cybersecurity governance.
What boards actually need
Boards do not need patch counts or firewall statistics. They need to understand which technology risks could materially harm the business, how well they are managed, and what decisions are being asked of them.
NIST's Cybersecurity Framework 2.0 was written with this audience in mind. Its Govern function covers organizational context, risk management strategy, roles and responsibilities, policy, oversight and supply chain risk, and NIST names executives and boards of directors among the audiences that can use the framework to guide cybersecurity decisions.
A practical report structure
- Top five to ten risks, each with business impact, current status and trend
- Progress on the IT and security roadmap against plan
- Incidents since the last report, their impact and what changed as a result
- Readiness: incident response plan status, last exercise, backup restore tests
- Third-party risk: key IT and cloud providers and any concerns
- Compliance status for obligations such as CMMC, HIPAA or GxP
- Decisions requested: risk acceptance, funding or policy approval
If you are a public company
The SEC adopted cybersecurity disclosure rules on July 26, 2023. Regulation S-K Item 106 requires registrants to describe their processes for assessing, identifying and managing material cybersecurity risks, the board's oversight of those risks, and management's role and expertise. New Form 8-K Item 1.05 requires disclosure of a cybersecurity incident the company determines to be material, generally within four business days of that determination.
Annual disclosures applied beginning with fiscal years ending on or after December 15, 2023. Form 8-K incident reporting began on December 18, 2023, with smaller reporting companies given an additional 180 days. Board reporting practices should support what the company says in those filings.
Private companies benefit too
Private companies are not subject to these SEC rules, but investors, lenders, acquirers, insurers and large customers increasingly ask similar questions. A consistent board report builds the record you will need in diligence and shows that leadership has been overseeing technology risk deliberately.
Keep the same format each quarter so trends are visible, and record board decisions on risk acceptance in the minutes.
Avoid the common mistakes: reporting activity, such as tickets closed or tools bought, instead of risk; changing the format so trends disappear; presenting only good news until an incident forces a different conversation; and failing to ask for a decision when one is needed.
Common follow-up questions
Who should present IT risk to the board?
The executive who owns technology risk, such as the CIO, a fractional CIO or a CISO, usually alongside the CEO or CFO. The presenter should be able to answer business questions directly and should not be the same person reporting on their own vendor's performance without independent input.
How often should the board hear about cybersecurity?
Quarterly is common, with an annual deeper review of strategy, incident response readiness and major risks. Material incidents should be escalated promptly between meetings according to a documented process, so board members are never surprised by events.
Should board reports include a security score?
Scores can help show trends, but on their own they can mislead. Pair any score with the specific risks behind it, what is being done about them and what decisions are needed. Boards should understand the risks, not just a number.
LAN Service Group prepares IT and cybersecurity risk reporting for leadership and boards of small and mid-size businesses as part of its IT strategy and fractional CIO-style leadership.
Talk to LAN Service Group (888) 281-7243