Why the CVE slide fails
The most common cyber board slide is a technical artefact wearing a suit: a large number of vulnerabilities, a patch-rate percentage, a coloured grid, and a quarter-on-quarter delta on the count. It feels rigorous. It governs nothing. A director cannot weigh '4,200 criticals, down 6%' against the cost of the control that would reduce it, cannot slot it into the enterprise risk appetite, and cannot tell whether the business is materially safer than it was.
The failure is one of translation. The board's job is to allocate capital and set tolerance for risk across the whole enterprise. A CVE count is denominated in a unit no other risk on the board's agenda uses. Until cyber risk is expressed in the same terms as credit, market and operational risk — probability and money — it cannot be governed alongside them.
The four questions a board actually has
Strip away the noise and a board wants four things from a cyber report. Are we exposed beyond the risk appetite we approved, and specifically where? Is the trend getting better or worse, and what is driving it? Among our material cyber risks, which represent the largest probable loss, so we fund the biggest reducers first? And what, precisely, do you need us to decide today?
Every element of a good report should map to one of those questions. If a chart does not help answer one of them, it belongs in the appendix or the SOC dashboard, not on the board slide.
Quantify a few scenarios, not every finding
The backbone of a board report is a small library of well-scoped risk scenarios — 'ransomware disrupts order processing', 'compromise of the customer data store', 'critical third-party outage' — each quantified in monetary terms. An approach such as FAIR (Factor Analysis of Information Risk) decomposes each scenario into loss event frequency and loss magnitude, uses calibrated ranges rather than false-precision point estimates, and produces an annualised loss expectancy with confidence bands.
Expressed this way, cyber risks become comparable to each other and to the cost of the controls that reduce them. The board can see whether a proposed $2M investment removes more than $2M of expected loss, and where the next dollar of security spend does the most good. Five defensible scenarios in dollars beat five thousand findings in a table every time.
Rank exposure by reachability, not by count
Where technical detail does belong, frame it by business impact. Rather than a raw vulnerability count, show exposure ranked by whether a weakness is reachable — can an attacker actually get from an internet-facing entry point to a crown-jewel asset — and whether it is being exploited in the wild, using signals like CISA's Known Exploited Vulnerabilities list and EPSS.
A handful of exploitable, reachable exposures on critical assets is a far more honest picture of risk than a five-figure total that treats a theoretical flaw on a test box the same as a live path to the customer database. Reachability turns a scary number into an accurate one.
Make every number traceable — and ask for a decision
A board will, and should, challenge the headline figures. The report has to survive that. Every number on the slide should trace back to the evidence beneath it — the scenarios, the exposures, the control state — so a probing question is answered with a drill-down, not a shrug. That traceability is also what makes the report auditor-ready and defensible after the fact.
Finally, end on the ask. A board report is not a status update; it is a request for governance. Name the decisions: approve this investment, formally accept this exception until the fix lands, revisit this element of the risk appetite. When the story runs cleanly from exposure to loss to trend to decision, the board can do its job — and the CISO gets an answer instead of a nod.