Compliance & Risk

Communicating Cybersecurity to the Board and Executive Team

W. Scott Montgomery

Communicating Cybersecurity to the Board and Executive Team
Communicating Cybersecurity to the Board and Executive Team

Directors are accountable for cyber risk. Most of them are not getting the information they need to oversee it.

Ask a board member how the organization is doing on cybersecurity, and the answer usually depends on the last presentation they sat through. Sometimes that was a forty-slide deck of firewall statistics and patch counts. Sometimes it was a reassuring five minutes from the IT director at the end of a long meeting. Sometimes it was nothing at all until an incident forced the conversation. None of these give a director what they need: a clear, consistent picture of how much cyber risk the organization is carrying, whether that risk is going up or down, and what management needs from the board to keep it in check.

That gap is not a technology problem. It is a communication problem, and it is one of the most fixable weaknesses we see in mid-market organizations. The fix is a short, disciplined, monthly cybersecurity dashboard built around the questions boards actually ask, populated with the right measures, and maintained with enough rigor that directors can trust it.

Why cybersecurity is a board responsibility

Cybersecurity used to be treated as an operational IT matter. That view has not survived the last decade. Ransomware can halt production or order processing for days, business email compromise can redirect a six-figure payment in an afternoon, and a single vendor breach can expose customer data the organization never directly touched. Those are enterprise risks, and enterprise risks belong to the board.

Regulators, courts, and insurers have all moved in the same direction:

  • Director oversight duties. Under the Delaware Caremark standard, reinforced in Marchand v. Barnhill (2019), directors are expected to make a good-faith effort to ensure a reporting system exists for mission-critical risks. For most organizations today, cyber risk qualifies.
  • SEC disclosure rules. Public companies must now describe the board's oversight of cybersecurity risk and management's role in assessing and managing it (Regulation S-K Item 106), and must disclose material incidents on Form 8-K within four business days of determining materiality. Private companies with public-company customers, lenders, or acquirers feel the downstream effect.
  • Financial services requirements. The FTC Safeguards Rule requires the Qualified Individual to report in writing to the board at least annually. The Interagency Guidelines and NCUA Part 748 place approval and oversight of the information security program with the board of directors, and the FFIEC examination process tests whether that oversight is real.
  • NYDFS Part 500. The amended regulation requires the CISO to report to the senior governing body and expects that body to have sufficient understanding of cybersecurity to exercise effective oversight.
  • NIST CSF 2.0. The 2024 update added a new Govern function, placing cybersecurity strategy, risk appetite, roles, and oversight at the center of the framework rather than at its edges.
  • Cyber insurance underwriting. Carriers increasingly ask how security is governed and reported, not just which tools are installed. A documented board reporting cadence supports the application and the claim.

The common thread is that a board can no longer say it was not told. It is expected to ask, to receive regular and meaningful information, and to act on it. That expectation only works if the information arrives in a form directors can use.

The translation problem

Security teams are fluent in their own metrics: vulnerability counts, alert volumes, patch percentages, blocked emails. Boards think in a different vocabulary: exposure, trend, cost, accountability, and decisions. When technical data is handed to directors without translation, one of two things happens. Either the board disengages because the material is impenetrable, or it latches onto a single number without the context to know whether that number is good or bad.

A useful board report answers five questions, every time, in the same order:

  • How exposed are we right now? A short set of indicators, each with a target, so the board can see at a glance what is on track and what is not.
  • Is it getting better or worse? Twelve months of history, so a single bad month is not mistaken for a crisis and a slow decline is not missed.
  • What has actually happened? Incidents, near misses, downtime, and dollars, along with what changed as a result.
  • What are our biggest risks, and who owns them? A short, scored list with named business owners, not just the IT department.
  • What do you need from us? Specific decisions: funding, risk acceptance, policy approval, each with a management recommendation and a date.

What a board-ready cybersecurity dashboard looks like

Digital Elevation has developed a Board Cybersecurity Dashboard workbook designed around those five questions. A one-page Dashboard summary is generated automatically from a set of simple monthly input tabs, so the board sees the same layout every month and management spends its time on the content rather than the formatting.

Workbook tabWhat it gives the board
DashboardA one-page summary: overall posture, KPIs on target, critical risks, incidents and near misses for the month, decisions needed, a three-line executive summary, and 12-month trends.
Key Risk IndicatorsMeasures grouped by Exposure, Identity, Detection and Response, Recoverability, People, Third Parties, and Program, each with a target, an amber threshold, a direction (higher or lower is better), and a calculated status and trend.
Incidents and Incident LogMonthly counts by severity, near misses blocked, reportable incidents, business downtime, and financial impact, plus a short log of notable events and what changed afterward.
Top Cyber RisksA scored risk register (Likelihood x Impact) with business impact, a named owner, treatment plan, status, prior-month comparison, and expiration dates for any accepted risks.
Compliance, Audit and InsuranceOpen findings, regulatory obligations, customer requirements, and insurance renewal attestations, each with an owner, due date, and Red, Amber, or Green status.
Critical Third PartiesThe vendors whose failure or compromise would materially affect the business, and whether each has a current security review.
Roadmap and BudgetFunded security initiatives with budget, spend, percent complete, and target date, so the board can see whether money is turning into progress.
Decisions RequestedWhat management needs from the board this month, with type, amount, recommendation, and deadline.
Sample Board Cybersecurity Dashboard: a one-page monthly report showing posture, KPIs, risks, incidents, decisions, and trends.
Sample Board Cybersecurity Dashboard generated from the tracking workbook (illustrative data). View full size (PDF).

What this looks like in practice

The sample data in the workbook (fictional, but representative of what we see in mid-market organizations) shows why this format works. Over twelve months, the sample organization reduced open critical vulnerabilities on internet-facing systems from 9 to 1, cut the number of privileged accounts in half, brought MFA coverage for administrative and remote access to 100 percent, and reduced mean time to contain an incident from 30 hours to 7. A board seeing that trend line knows its security investment is producing results.

The same dashboard also surfaces what is not working. End-of-life systems in production are down from 14 to 4, but the target is zero. Critical vendors with a current security review have doubled, but only to 80 percent against a 100 percent target, and the backup provider has not been reviewed at all. The security roadmap has slipped from 95 percent delivered against plan to 76 percent. A good dashboard does not hide those facts; it puts them in front of the people who can do something about them.

That is where the Decisions tab earns its place. In the sample, management asks the board to approve $85,000 to accelerate the replacement of end-of-life servers, explicitly tied to the ransomware risk those systems create. It asks the board to formally accept the risk of a legacy ERP system that cannot enforce MFA, with compensating controls and a fixed expiration date. And it asks for approval of updated Incident Response and Acceptable Use policies needed for the cyber insurance renewal. Each request is specific, justified, and traceable back to a risk or a metric on the same page. That is what board oversight of cybersecurity is supposed to look like.

Why monthly tracking matters

Most boards meet quarterly, so it is fair to ask why the data should be updated monthly. The answer is that trends are only meaningful if the underlying data is captured consistently. A monthly cadence gives management an early warning when a measure starts drifting, keeps risk owners engaged between board meetings, and means the quarterly board package is a summary of work already done rather than a scramble to reconstruct the last three months. It also builds the documented history that regulators, auditors, insurers, and acquirers increasingly ask to see.

Monthly tracking also benefits the executive team directly. The same dashboard that informs the board gives the CEO, CFO, and COO a shared view of security posture, makes ownership of each risk visible, and turns budget conversations into evidence-based discussions rather than competing opinions.

The hard part is deciding what to measure

A spreadsheet is the easy part. The value of a board dashboard depends entirely on what goes into it, and this is where most organizations struggle. We regularly see the same pitfalls:

  • Vanity metrics. Numbers that are large and impressive, such as millions of blocked emails, but that say nothing about whether risk is going up or down.
  • Too many measures. Forty KPIs that bury the five that matter. A board-level set should be small enough to absorb in a few minutes.
  • No targets or thresholds. A value without a target cannot be judged. Setting targets also forces management and the board to agree on risk appetite.
  • Unreliable data. Measures that require heroic manual effort each month tend to be skipped, estimated, or quietly abandoned.
  • Risks without owners. When every risk belongs to IT, the business units that actually create and accept the risk are not accountable for it.
  • Missing obligations. Compliance deadlines, customer security requirements, and insurance attestations that live in someone's inbox rather than in front of the board.

It is also worth being clear about what a dashboard cannot do. It does not replace periodic risk assessments, penetration testing, or independent audits; it reports on them. Metrics can be gamed if targets are tied to compensation or if no one validates the source data. And a dashboard is a starting point for a board conversation, not a substitute for one. The organizations that get the most from this approach use the dashboard to drive better questions, not to avoid them.

A board can no longer say it was not told.

It is expected to ask, to receive regular and meaningful information, and to act on it. That expectation only works if the information arrives in a form directors can use.

How Digital Elevation helps

Digital Elevation offers a Board Cybersecurity Reporting engagement that takes a mid-market organization from no structured board reporting, or reporting that is not working, to a sustainable monthly dashboard the board and executive team trust. Our security team works with your leadership to:

  • Understand your obligations. We identify the regulatory, contractual, customer, and insurance requirements that apply to your organization and build them into the Compliance tracker with owners and due dates.
  • Identify and score your top risks. Through facilitated working sessions with executives and business owners, we build a right-sized risk register with consistent Likelihood and Impact scoring, named owners, and clear treatment plans.
  • Select the right KPIs. We help you choose a focused set of key risk indicators tied to those risks, set realistic targets and amber thresholds that reflect your risk appetite, and confirm where each data point will come from and who will report it.
  • Map your critical vendors. We identify the third parties whose compromise or failure would materially affect the business and establish a review cadence for each.
  • Establish the baseline. We populate the workbook with your current data, align the security roadmap and budget, and help prepare the first board presentation, including how to frame decisions requested of the board.
  • Support the monthly cadence. Choose a Facilitated Engagement, where we coach your internal team as it takes ownership of the monthly update, or a Digital Elevation-Led Engagement, where our team collects the data, updates the dashboard, and prepares the board package as part of an ongoing vCSO relationship.

Every engagement is aligned to NIST CSF 2.0 and the frameworks that apply to your industry, including GLBA, FFIEC and NCUA guidance, HIPAA, PCI DSS, and SEC disclosure expectations where relevant. And because Digital Elevation is a full security and compliance practice, if the dashboard surfaces gaps in incident response, vendor risk, data protection, or technical controls, you are already working with the team that can help close them.

Is your board getting the cybersecurity picture it needs?

Let Digital Elevation help you build a board cybersecurity dashboard that tells a clear, honest story every month. We will scope an engagement that fits your team, your timeline, and your budget. Start the conversation, or reach out directly at info@digitalelevationusa.com or 616-600-4737.

W. Scott Montgomery is Director of Security at Digital Elevation, where he leads security and compliance engagements for mid-market organizations across financial services, healthcare, and other regulated industries.

Share this post