Cyber Governance7-minute read·Marcin Pajdzik·April 2026

Deciding What the Board Needs to Know About Cyber Risk

A board cannot delegate accountability for the adequacy of the information on which it oversees material cyber risk. Management may develop and produce the reporting, but the board must determine whether it supports the judgements the board is required to make. Where the board never exercises that accountability, its oversight is defined by management by default.

Directors remain accountable for that oversight whether or not the information in front of them supports it. A board that accepts the reporting it is given has accepted a standard set by someone else.

Why boards receive operational metrics

Vulnerability counts, patch rates and phishing results measure what the security team has done. A report showing 94% of critical patches applied within the agreed service-level target does not say whether the remaining 6% includes the system processing customer payments, or whether that exposure sits within the organisation's risk appetite.

Where no requirement has been set, reporting defaults to what the function already produces, and the result passes through board meetings without producing judgement, challenge or a documented response.

That has a consequence in the governance record. A board that accepts a paper it cannot evaluate, one that does not let it test the position or judge whether a response is required, produces minutes that simply note the paper was received. Over several reporting cycles, that pattern accumulates into a record of noted reports with no exercise of judgement on file.

The minutes may not capture every question a director raised in the room, but they are among the documents examined when the adequacy of the board's oversight is questioned, and a record with no evidence of judgement, challenge or follow-up is difficult to distinguish from a record of no oversight.

What adequate reporting contains

Risk framing
The reporting should identify the organisation's material cyber risks and state the residual exposure after controls are applied. It should also describe how that position has moved since the previous report, including where it has deteriorated. Controls degrade and threat environments shift, so the movement matters as much as the level. Each risk should be stated in terms of what the business actually loses if that risk materialises, such as operational interruption, financial cost or legal and regulatory consequence.
Appetite and ownership
Residual exposure becomes a governance position when it is assessed against the organisation's risk appetite for that category of risk. Each material exposure should also name the executive accountable for it, separate from the CISO who reports it. An enterprise risk appetite does not automatically mean cyber exposures have been assessed against it. Where that link has never been established and scrutinised, the board's first governance task is to satisfy itself that cyber exposures are assessed appropriately against that appetite, informed by what management proposes.
Decision content
Only some of what the reporting raises belongs to the board. Within appetite, a risk is management's to manage, though its trend and any change in assumptions still belong in the reporting. Approaching that boundary, a risk calls for board challenge and monitoring rather than a passive note. The same holds where a control has degraded. Outside appetite, a risk is escalated, but escalation is not itself a board decision, and restoring the position can still be management's job. What the board itself decides is narrower: accepting the exception, changing the appetite, or approving a response beyond management's delegated authority. New investment above that threshold is one example. Adequate reporting names which of these applies to each material risk.

How a board tests whether its reporting is adequate

A board assessing its current reporting can put three questions to management and the CISO at the next cycle. How has the residual exposure on each material risk moved since the last report? What is the plausible range of business impact if each materialises, in operational, financial or legal terms? For each material risk, who owns the response, and does it call for management action, board challenge and monitoring, or a formal board decision?

If those questions cannot be answered in the meeting, or require preparation outside the standard reporting process, the format is not working. Clear answers in the room show that management can answer the questions today. The reporting is doing what it should when the same answers already sit in the paper the board received, tied to a named owner. Where the answer calls for board engagement, the outcome of that engagement belongs in the minutes as a decision, a judgement, or an agreed follow-up.

Recording the board's reporting requirement somewhere durable, such as committee terms of reference, board-reserved matters or the enterprise risk framework, makes it a standing obligation that survives a change of chair or CISO, whether responsibility sits with the full board or a committee to which it has delegated that responsibility.

A requirement recorded that way also gives the board evidence that it set the standard, which matters when a supervisory authority, an auditor or an insurer asks how the board exercised oversight.

How this affects your organisation

For board members and senior executives, the quality of cybersecurity reporting determines what the board can later be shown to have known and to have decided. That is true whether or not a specific incident ever puts it to the test.

Reporting that gives the board nothing to evaluate may be evidence, in the board's own record, that the accountability question has not yet been answered. The reporting standard in front of a board reveals whether it has been consciously assessed and accepted, or simply allowed to become the default. The three questions from the previous section are the practical way to find out which is true. Put them to management and the CISO at the next cycle.

If your board is reviewing how it receives and evaluates cybersecurity information, an advisory call is a useful starting point.

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.