Board reporting

A board needs to know which risks are material, what is being done, and what decision is being asked of them.

What they usually get is activity: patch counts, alert volumes, training completion. None of that supports a decision. The question to write against every slide is what the board should do differently having seen it, and most security reporting has no answer.

Checked against the primary source.

More on Governance & risk