JOEY VICTORINO Independent Technical Judgment

Field Notes · Institutional Security · 6 min read

Boards need decisions from security, not telemetry.

The standard board security update is a page of measurements: patching percentages, training completion, alert volumes, phishing click rates, a maturity score trending upward. The numbers are usually accurate. They are also, in the form presented, unusable: no consequence attached, no owner named, no decision requested. That form converts oversight into spectatorship, and it leaves directors carrying accountability they were never given the means to discharge.

What the board is actually there to do

A board does not run the security program, and reporting that implicitly asks it to is misdirected. Its function is oversight: satisfying itself that management has identified the material risks, that someone owns them, that the resourcing is deliberate, and that the risks the company is carrying are carried knowingly. Governance frameworks have converged on this framing. NIST's Cybersecurity Framework 2.0 added a dedicated Govern function precisely because outcomes depend on established roles, accountability, and oversight rather than on controls alone.

For public companies the expectation has also become a disclosure obligation. Under the SEC's 2023 cybersecurity rules, registrants must describe, in their annual report, the board's oversight of risks from cybersecurity threats, including the relevant committee or subcommittee and the processes by which it is informed. A board that receives only telemetry has a governance process it must now describe, and describing it accurately would be uncomfortable.

Why measurement without structure fails

The failure is not that metrics are useless. It is that a metric presented alone omits every element that would let a director act on it. Four omissions do most of the damage:

  • No consequence. "94% of endpoints patched within 30 days" does not say what the remaining 6% are, whether they include the systems that would matter most, or what exposure the gap creates. A number without a stated consequence cannot be weighed against anything.
  • No denominator that matters. Completion percentages are computed over an inventory. If the inventory is incomplete, or if it treats a domain controller and a meeting-room display as equivalent units, the percentage measures activity rather than risk. Directors are rarely told which denominator they are looking at.
  • No owner. A trend presented without a named accountable executive belongs to nobody in the room, which means the board cannot direct a question at anyone or follow up next quarter.
  • No request. Most security updates ask for nothing. A board's usable outputs are approval, refusal, resourcing, escalation, and recorded acceptance. A report that requests none of them has not engaged the board's actual authority.

The result is a familiar dynamic: the presentation is received, a few questions are asked about the most legible number, the minutes record that a cybersecurity update was given, and the company's risk position is exactly where it was. Everyone has behaved reasonably and nothing has been governed.

The consequence for directors

Telemetry reporting creates a specific asymmetry. It transfers the appearance of oversight to the board while leaving the substance with management. If a serious incident follows, the record shows a board that was briefed regularly and asked to decide nothing. Directors then discover that they were accountable for a risk posture they had never been shown in a form they could evaluate, and the briefing history, which looked protective, documents the gap. The protection a board actually wants is a record of decisions it made knowingly, including the risks it agreed to accept.

The four elements a board security report should carry

The corrective is structural and does not require more pages. Every security report to a board should contain four things, in this order:

  1. The position. The material risks in business terms, ranked, with the reasoning visible. Not a register of eighty items: the small number of ways this company could be seriously hurt, stated so a non-technical director can repeat them accurately.
  2. What changed since the last report, and why. Movement in the position, and its cause: a new product surface, an acquisition, a customer obligation, a control that now works, a threat that became relevant. Change with attribution is what allows a board to see whether management is steering or reacting.
  3. The decisions requested. Explicit asks with options and consequences. Fund this, or accept this exposure until the next fiscal year. Approve this exception, or accept the delay to the product launch. Escalate this to the audit committee. If nothing is being requested, say so deliberately rather than by omission.
  4. What is being accepted, on the record. The risks management is carrying by choice, named, with the rationale. This is the artifact that converts implicit acceptance into governed acceptance, and it is the one most often missing.

Metrics still belong in the pack. Their place is supporting evidence for the position and the change, not the substance of the report. A useful test of placement: if a metric cannot be attached to one of the four elements, it belongs in an appendix or nowhere.

A test that exposes a decorative metric

For any number proposed for a board pack, ask: what would we do differently if this number were twice as bad, and what would we do differently if it were perfect? If both answers are "nothing," the metric is decorative. It may still be operationally useful inside the security team, where it drives daily work, and that is where it should stay. Board reporting has a different job, and the same number rarely serves both.

A second, sharper question directors can ask without technical knowledge: which of these numbers would have moved before the incident you are most worried about? If none of them would have, the pack is measuring the parts of the program that are easy to measure rather than the parts that carry the risk. That is a common and forgivable condition. It is not a condition that should survive being noticed.

The strongest objection

Two objections deserve answers. The first: some boards, in regulated industries, are required to review specified metrics, and examiners expect to see them. Correct, and it does not conflict with the argument. Mandated metrics are a floor and belong in the pack as compliance evidence. The question is whether they are the report or an attachment to it, and treating a regulatory reporting minimum as the governance conversation is the error.

The second, and more serious: boards vary in technical literacy, and decision-oriented reporting demands more of directors than receiving a dashboard does. A board that has been trained on trend lines for years may experience a decision-shaped report as an escalation, or as management pushing accountability upward. That reaction is real and is a transition cost rather than a reason to continue. It is also usually short-lived, because the first time a board is asked to accept a named risk in writing, with the alternative and its price stated, most directors recognize the format as the one they already use for capital allocation and legal exposure. The security conversation is joining a structure they know, not inventing one.

What good looks like

In a company reporting well, several things are observable. A director can state the company's top security risks without prompting. The minutes record decisions and acceptances rather than attendance. The security leader arrives with a request and leaves with an answer. The pack is shorter than it used to be, and the appendix is longer. And when an incident occurs, the board's first question is answerable from its own prior record: we knew about this class of risk, we accepted it on these terms in February, and here is what we said would trigger revisiting it.

Conclusion

Board security reporting fails in a specific, correctable way: it presents measurement without consequence, ownership, or a request, which leaves directors informed and unable to govern. The fix is formal rather than technical. State the position, state what changed and why, ask for the decisions that are actually needed, and record what the company is choosing to accept. Metrics remain useful as evidence for those four things. Presented as a substitute for them, they produce the most expensive outcome available to a board: the documented appearance of oversight, without its substance.

Related: What the First 90 Days of Security Leadership Should Actually Produce, on building the risk position and written acceptances this reporting format depends on.

Board reporting that asks for decisions

Board preparation and executive risk translation are part of Fractional CISO / Standing Independent Advisory: the risk position written so directors can act on it, decisions framed with options and consequences, and acceptances recorded. Strategic at $8,500/month, Embedded at $12,500/month, 90-day initial term. I hold at most two standing relationships at a time.

Know a director who receives a security dashboard every quarter and has never been asked to decide anything? Send them this note.

Sources

  • National Institute of Standards and Technology, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, February 2024. Cited for the Govern function: cybersecurity risk management depends on established organizational roles, accountability, and oversight.
  • U.S. Securities and Exchange Commission, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, adopted July 2023. Cited for the annual-report requirement that registrants describe the board of directors' oversight of risks from cybersecurity threats, including the responsible committee and the processes by which it is informed. Applies to SEC registrants; private companies are not subject to the rule.

← All Field Notes