Playbook · Worldwide

Board Cyber Reporting and Metrics Pack

Directors are now accountable for cyber oversight under SEC disclosure rules, the EU NIS2 Directive, and DORA. This pack gives you the metrics that inform decisions, a repeatable quarterly agenda, and the documentation that proves oversight actually happened.

Metrics that belong in a board pack

  • Top five enterprise cyber risks with owner, trend, and treatment status.
  • Control coverage: percentage of assets with endpoint detection, logging, and multi-factor authentication.
  • Critical and high vulnerability remediation performance against the stated service level.
  • Mean time to detect and mean time to contain, with the trend over four quarters.
  • Third-party risk: number of critical suppliers, assessments completed, and unresolved findings.
  • Incident summary: volume by severity, material incidents, and regulator notifications filed.
  • Resilience evidence: recovery tests completed, restore success rate, and gaps against recovery objectives.
  • People risk: training completion and phishing simulation failure rate for privileged users.
  • Program delivery: roadmap milestones met, budget consumed, and capability gaps carried forward.
  • Insurance and residual risk position, including any coverage conditions not yet met.

Metrics to leave out

  • Raw alert or blocked-attack counts, because they measure noise rather than risk.
  • Tool inventories without an outcome attached.
  • Scores from frameworks the board has not agreed to be measured against.
  • Technical findings with no business impact statement or decision request.

Quarterly agenda template

  1. 01Risk posture: what changed since last quarter and why it matters commercially.
  2. 02Incidents and near misses, including anything that could become a disclosable event.
  3. 03Regulatory and contractual obligations, with status of any pending attestation or audit.
  4. 04Roadmap and investment: progress, blockers, and the decisions requested from the board.
  5. 05Resilience: results of the most recent recovery or tabletop exercise, and the actions arising.
  6. 06Forward look: the two or three risks expected to grow in the next two quarters.

Oversight evidence to retain

  • Minutes recording the cyber discussion, questions asked, and decisions taken.
  • The reporting pack itself, versioned and dated.
  • Risk acceptance records signed by the accountable executive.
  • Documented cyber expertise or advisory support available to the board.
  • Materiality assessment process for incident disclosure decisions.

Reporting cyber risk to a board or audit committee?

Dephiant builds the reporting pack, presents alongside your team, and prepares directors for the questions regulators, insurers, and customers now ask.