Security leadership

Reporting exposure to a board without a single scary chart

Boards do not need to be frightened; they need to know whether the thing is getting better, how you know, and what you want from them. Two pages is enough.

The instinct to bring a board the worst thing you found is understandable and almost always counterproductive. It gets attention once. It does not get a budget line, and it does not get the standing mandate you actually need.

What a board can act on

  • A direction of travel with a stated measurement method.
  • What is currently unacceptable, in business terms, with a date attached.
  • Specific decisions you want from them, with the effect of each.
  • What you will report next time, so progress is checkable.

One number, explained

A single exposure score works if — and only if — you publish how it is calculated. An unexplained number invites either blind trust or blind dismissal, and both are worse than an argument about methodology.

Publish the method with the number. A metric nobody can challenge is a metric nobody believes.

Say what did not improve

Boards are unusually good at detecting selective reporting. Naming the area that got worse, and why, buys more credibility than three quarters of green. It also makes the ask that follows much easier to grant.

Two pages

Where things stand. What changed. What we will do. What we need. If it does not fit, the problem is usually that the underlying model is not clear enough yet — not that the board needs more slides.


Every company, figure and quotation in this article is fictional sample content written for the template.

Next step

See your own surface the way an attacker reads it

A four-week proof of value connects one cloud account, your DNS and your identity provider, and ends with a written readout of what was found.

Book a walkthroughOpen the console demo

Illustrative product data. Nothing on this site performs a live scan.