Skip to main content

Watch a board receive its quarterly security update and you will see a lot of nodding. Very few decisions. The nod is not agreement. It is the polite way to move on to the next agenda item.

“The board doesn’t get security.” “The CISO speaks a language we don’t understand.” I hear both complaints most months, sometimes about the same meeting. Both are right, and both are avoidable, because the problem is not intelligence or effort on either side. The problem is that cyber risk reporting is a translation job, and in most organisations nobody has been asked to do the translating.

The board is optimising for the things boards exist to protect: winning deals, raising money, exiting well, staying out of the headlines. The security lead is optimising for coverage: controls implemented, frameworks aligned, threats monitored. Both are legitimate. They just never meet in the middle of a slide full of red, amber and green.

Cyber risk reporting is a translation job

The fix costs nothing, and you can apply it to your very next meeting: reframe every security update as a business decision.

Not “we have 14 critical vulnerabilities.”

Instead: “Two of these could fail an enterprise buyer’s due diligence next quarter. Here is what closing them costs, and what leaving them open risks.”

Same facts. Now the board can actually decide.

Beekeeper working a hive calmly, the way cyber risk reporting should feel to a board

I have sat through both versions of this meeting. In one, the security update ran to forty slides: patch percentages, a maturity heat map, a tour of the threat landscape. Thorough, accurate, and completely undecidable. The chair said thank you, the board nodded, and the item closed with nothing agreed. In the other, at the same company two quarters later, the update was one page. Three risks, each priced: the probable cost if it lands, the cost to fix it, and the decision needed from the room. Twenty minutes later the board had funded two fixes and formally accepted the third risk, minuted, with its owner named. Nothing about the company’s security had changed between those two meetings. The reporting had.

Three questions every security update should answer

What could this cost us? In terms the board already uses: deal risk, a delayed raise, regulatory exposure, days of downtime. Not CVE scores.

What does fixing it cost? Money, time and disruption, stated plainly enough to compare against the risk.

What do you need from us? A decision, a budget, or nothing but awareness. Say which.

If an update cannot answer those three questions, it is not a board update. It is a status report that happens to be read aloud in a boardroom. The National Cyber Security Centre makes the same point in its Cyber Security Toolkit for Boards: cyber risk is a business risk, and it should be governed with the same discipline as financial or legal risk.

This translation is also why the best fractional security leaders earn their keep. They are hired as much for the ability to turn technical exposure into risk a founder or managing partner can weigh, price and act on as they are for technical depth. In my own work it is easily half the value delivered, and it is usually the half that changes what the board does next.

If your security updates need a translator on the way to the board, that is the gap to close first. It costs nothing, it can be fixed in one reporting cycle, and it changes security from a cost centre nobody understands into a set of decisions the board can own.

If you would like a second opinion on what your board sees each quarter, get in touch. Bring your last security update. Ten minutes with it will tell us most of what we need to know.