A good board security report answers four questions: what are our biggest cyber risks, are they getting better or worse, are they within the level of risk we've agreed to accept, and is our spending reducing them. It does that in business language, with a small set of metrics shown as trends, and it fits on one page with detail in an appendix.

For US public companies, the stakes have gone up. The SEC's cybersecurity disclosure rules now require a description of board oversight of cybersecurity risk in the annual report. This post covers what those rules ask for and how to build a report boards can use.

What do the SEC's cybersecurity rules require about board oversight?

The SEC adopted its cybersecurity risk management, strategy, governance and incident disclosure rules on July 26, 2023. Among other things, they added Item 106 to Regulation S-K.

Item 106(b) requires companies to describe their processes for assessing, identifying and managing material risks from cybersecurity threats. Item 106(c) covers governance, in two parts:

  • Board oversight. Describe the board's oversight of risks from cybersecurity threats. Where applicable, identify any board committee or subcommittee responsible, and describe how the board or that committee is informed about those risks.
  • Management's role. Describe management's role in assessing and managing material cybersecurity risks, including which positions or committees are responsible, their relevant expertise, how they're informed about and monitor the prevention, detection, mitigation and remediation of incidents, and whether they report to the board or a board committee.

The annual report disclosures apply to fiscal years ending on or after December 15, 2023. For calendar-year companies, that means the Form 10-K being prepared now. The separate Form 8-K requirement to disclose material cybersecurity incidents took effect on December 18, 2023, and smaller reporting companies will have to comply starting June 15, 2024. The SEC's press release summarizes the rules and dates.

One practical consequence: the way you report to the board is now something the company describes publicly. If the 10-K says the audit committee receives quarterly cybersecurity briefings, those briefings need to happen, and they need to be substantive.

Private companies aren't covered by these rules. Even so, lenders, investors, acquirers, insurers and large customers increasingly ask similar questions about oversight.

Why do board security reports often miss the mark?

The common problems:

  • Too technical. Reports full of tool names, alert counts and acronyms directors can't interpret.
  • Activity instead of outcomes. "We blocked 2 million attacks" says nothing about whether the organization is safer.
  • Snapshots with no context. A single number, with no trend or target, can't tell a director whether things are improving.
  • No link to decisions. The report informs but never asks the board for anything.

Boards don't need to understand how security controls work. They need to understand risk, direction and trade-offs well enough to challenge management and make decisions.

How do you frame security in terms of risk?

Start from business impact, not technical findings. Describe your top five to seven cyber risks in terms of what could happen to the business.

Technical framing Risk framing
Unpatched servers in the data center Extended outage of order processing during peak season
Weak access controls on the CRM Exposure of customer personal data, with notification costs and loss of trust
No security review of suppliers A supplier with access to our systems is compromised and used to reach our data

For each risk, show:

  • Current rating (likelihood and impact) against the organization's risk appetite
  • Direction since the last report
  • The accountable executive
  • The main actions underway and when they'll be complete

If your organization has an enterprise risk register, cyber risks belong in it, rated on the same scale as other business risks. Boards find it much easier to weigh a cyber risk when it's expressed in the same terms as financial, operational and legal risks.

Which security metrics should the board see?

Pick six to eight metrics and keep them stable from quarter to quarter. Each should connect to one of your top risks and have a target.

Metric What it tells the board
Critical systems with MFA enforced (%) Coverage of a control that blocks many account takeovers
Median days to fix critical vulnerabilities on internet-facing systems How long known weaknesses stay exposed
Critical systems with a successful restore test in the last 12 months (%) Whether we can recover from a major outage
Critical vendors assessed in the last 12 months (%) How well supplier risk is managed
Top risks within appetite (count out of total) Overall risk position
Significant incidents and time to contain How often things go wrong and how quickly they're handled
Overdue audit and assessment findings Whether commitments are being met
Date of last incident response exercise, and actions closed Readiness and follow-through

Leave out vanity metrics. Counts of blocked attacks and alerts processed describe activity. They move with factors outside your control and don't indicate risk.

A single data point can't answer the board's real question: is this getting better? Show each metric over the last four to six quarters, alongside its target.

A few practices help:

  • Keep definitions consistent. If you change how a metric is calculated, say so and restate prior periods where you can.
  • Explain the movement. A one-line note, such as "increase reflects the acquisition of two subsidiaries," prevents misreading.
  • Use simple visuals. A small trend line or an up, down or flat indicator next to each metric is enough.
  • Show the direction of risk, not only controls. If the top risks are moving toward appetite, say so. If one is getting worse, lead with it.

Boards tend to trust a report more when it shows problems honestly. A report where everything is always green invites skepticism.

How do you tie security spending to risk reduction?

Directors will ask whether the money is working. Answer by linking every significant investment to a specific risk and a metric that should move.

For each major initiative, state:

  1. The risk it addresses
  2. The current metric value and the expected value after delivery
  3. The cost, split into one-time and ongoing
  4. When the board should expect to see the change

Then report back. If a project promised to raise MFA coverage on critical systems from 70% to 100% by June, show the progress each quarter.

When asking for new budget, present options rather than a single request. For example: fund the project and bring the risk within appetite by the end of the year, fund a smaller version and reduce it partially, or accept the risk and record that decision. That gives the board a real decision and makes accepted risks visible.

Avoid invented return-on-investment figures. Directors can usually spot a number built on guesswork, and it undermines everything else in the report.

How do you avoid jargon?

Write for an intelligent reader who doesn't work in security. Some practical rules:

  • Replace acronyms with plain descriptions, or drop them.
  • Describe what a control does, not what it's called. "The software on laptops and servers that detects and stops attacker activity" rather than a product category acronym.
  • Lead each section with the conclusion.
  • Keep technical detail in an appendix for directors who want it.

A useful test is to have someone outside IT, such as a finance or legal colleague, read the draft. If they can't explain the main message back to you, rewrite it.

What does a one-page board security report look like?

Here's a structure that works for most organizations:

1. Headline (two or three sentences) Overall position and the single most important change since the last report. For example: "Cyber risk is broadly stable. Recovery capability improved after restore testing of all critical systems. Supplier risk remains above appetite."

2. Top risks A table of five to seven risks with current rating, trend, whether each is within appetite, the owner and the next milestone.

3. Key metrics Six to eight metrics, each with current value, target and a trend over recent quarters.

4. Notable events since the last report Significant incidents and how they were handled, results of audits or assessments, and exercises completed.

5. Decisions or support requested Anything the board needs to approve, fund or accept. If nothing is needed, say so.

Appendix (separate pages) Metric definitions, details of initiatives, incident summaries and a short glossary.

How often should the board hear about cybersecurity?

Most organizations report to the responsible committee, often audit or risk, every quarter, and to the full board at least once a year. Agree in advance which events trigger an immediate briefing between meetings, such as a severe incident or any incident that might need to be assessed for materiality.

For public companies, make sure the escalation path from the security team to the people making materiality decisions is documented and tested, given the four-business-day window for Form 8-K disclosure after an incident is determined to be material.

Frequently asked questions

Does the SEC require a cybersecurity expert on the board?

No. The SEC proposed a requirement to disclose board members' cybersecurity expertise but did not adopt it in the final rules. Companies must describe the relevant expertise of the management positions responsible for cybersecurity risk.

Which board committee should oversee cybersecurity?

It varies. Many organizations assign it to the audit committee, some to a risk committee and a few to a dedicated technology committee. What matters is clear responsibility and regular, substantive reporting.

How long should a board security report be?

One page for the main report, plus an appendix for detail. Directors receive large board packs, and a concise report is more likely to be read and discussed.

Who should present the report?

Usually the CISO or senior security leader, often with the CIO or another executive sponsor. Directors benefit from hearing directly from the person accountable for security.

Key takeaways

  • Frame security as business risk, rated on the same scale as other enterprise risks.
  • Report six to eight stable metrics, each with a target and a trend.
  • Link spending to specific risks and report on whether the metrics moved.
  • Present funding requests as options, including explicit risk acceptance.
  • Keep the main report to one page and in plain language.
  • Public companies should make sure their board reporting matches what they describe under Item 106.