Why this module exists. The board is not your peer audience. They are not security practitioners. The report that wins your peers’ approval — a 40-slide dive into MITRE ATT&CK coverage — is the report that loses the board. This module is the operational pattern for the inverse: the report that lets a non-technical decision-maker make one of three calls (accept, mitigate, escalate) in fifteen minutes.
The four-layer model — what every board report needs
| Layer | What it answers | Pages |
|---|---|---|
| 1. Outcome | “Are we more secure than last quarter?” | 1 |
| 2. Risk position | “Where are we exposed, and what is the trend?” | 1 |
| 3. Programme delivery | “What did we promise, what did we ship, what slipped?” | 1 |
| 4. Decisions needed | “What do you, the board, need to decide today?” | 1 |
Four slides. Backed by a 20-page appendix for the reader who wants more, but the slides above are the deliverable. The discipline of compression is the work.
Layer 1 — the outcome slide
One sentence summary of the quarter, three KRIs with arrows, one “what kept the CISO up at night” callout. The KRIs that work:
- Mean time to remediate KEV-listed vulnerabilities (days, with trend arrow). Auditors respect this. Boards understand it. Practitioners can move it.
- Percentage of human accounts on phishing-resistant MFA (with trend). Concrete, achievable, visible.
- Incidents in the quarter, by severity (count, with comparison to same quarter last year). Resist normalising; the absolute number is the conversation starter.
What does not belong: number of blocked attacks (vanity), number of trained employees (effort, not outcome), CVE count (noise).
Layer 2 — the risk position slide
The risk register, top 5 only. Each row: risk name, current likelihood × impact, residual after current controls, treatment owner, expected closure quarter. The arrows showing trend since last report are what gets debated; the static heatmap is what gets ignored.
Be specific. “Cyber risk” is not a row; “Unrestricted SSH from third-party-vendor IP ranges to production hosts” is. Boards engage with concrete; they switch off with abstract.
Layer 3 — the delivery slide
Three lists. Shipped this quarter (5-7 items). Slipped, with explicit reason (1-3 items). On track for next quarter (5-7 items). The slipped list is the credibility-builder — every CISO who only reports green for four quarters and then drops a yellow loses the board’s trust. Reporting yellow when it is yellow buys trust for when you really need to defend a programme.
Layer 4 — the decisions slide
The most-skipped slide. Without it, the board is being briefed, not engaged. Each decision in a fixed structure:
- Decision needed: one sentence. “Accept residual risk on legacy AS400 estate until 2027 sunset,” or “Approve budget addition of ₹3.2 Cr for SOC modernisation,” or “Mandate cross-functional steering committee for DPDP compliance programme.”
- Options considered: two or three, briefly.
- Recommendation: yours, with reasoning.
- What happens if not decided: the consequence of inaction.
A board report with no decisions slide is informational. A board report with three decisions on the slide is governance. The difference matters when the regulator asks why the board did or did not act.
Cadence — when to report what
- Quarterly: the full four-layer report. Aligned to the board’s risk-committee cadence.
- Monthly: written update to the Risk Committee chair only. One page, no slides. KRIs + anything material since the last report.
- Ad hoc: any incident reaching the “material” threshold — defined in your incident classification matrix — triggers a same-day note to the Risk chair, even if not yet a regulator-reportable event.
- Annual: external attestation summary (SOC 2, ISO 27001), regulator filings, the year-in-review version of the quarterly report.
Indian board-specific structures
RBI Cyber Security Framework, IRDAI Information & Cyber Security Guidelines, and SEBI CSCRF all mention the CISO and board-level oversight. Three practical effects:
- Minutes are regulator-visible. The risk-committee minutes that record your report are inspected. Specific phrasing matters: “Board considered and accepted the residual risk” is the structure auditors look for.
- An Annual Board Affirmation on cyber posture is a SEBI CSCRF artefact. Your quarterly reports feed into that affirmation; structure them to make the annual summary mechanical, not creative.
- Incident materiality assessment is regulator-relevant. Have a written threshold (e.g., “any breach affecting >1,000 customer records, or any unavailability >4h on customer-facing systems”) so the board’s question “is this material?” has a defensible answer.
What to avoid
- Industry threat-landscape recaps. The board read the same news article. Use the time for your specifics.
- Detailed remediation tickets. Operational details belong in the appendix, not in front of the board.
- Heat maps with no movement. If the picture is identical to last quarter, you have either not been doing the work or not been measuring the right thing.
- Acronyms without definitions. The board chair will not ask what “MITRE ATT&CK” means; they will tune out.
Key takeaways
- Four-slide structure: outcome, risk position, delivery, decisions needed.
- Three KRIs that work: KEV MTTR, MFA coverage, incident count by severity.
- Report yellow when it is yellow — credibility compounds.
- Decisions slide is what makes it governance, not a briefing.
- Indian-board specifics: minute phrasing matters, materiality threshold pre-defined, annual affirmation pre-structured.
Get a DPDP gap assessment
Free 30-minute call. We map your data flows against DPDP §8 obligations and tell you exactly which gaps to fix first. Auditor-defensible output.