Board reporting
A board needs to know which risks are material, what is being done, and what decision is being asked of them.
What they usually get is activity: patch counts, alert volumes, training completion. None of that supports a decision. The question to write against every slide is what the board should do differently having seen it, and most security reporting has no answer.
Checked against the primary source.
