The Report Your Board Actually Reads
Directors don't want forty slides. Loss exposure trends, top risks, and control effectiveness on one page — what boards ask about, and how we answer. A regional insurer we advise handed us their old board deck before our first engagement. Slide nine was a heat map — 43 cells, most of them some shade of amber, three of them red. The CFO told me a director had looked at it the previous quarter and asked, flat out, "Is this better or worse than last time?" Nobody in the room could answer. That is the whole problem with most cyber risk reporting. It shows a lot and says nothing at all. Boards are not asking for more detail. In our experience the audit and risk committees we sit in front of ask roughly four questions, and they ask them every quarter: How much money is at stake? What are the biggest things that could hurt us? Are our controls actually working? And is any of this getting better? A good report answers those four in the first two pages. Everything else is an appendix. Start with a number, not a color The single most useful change we make when we onboard a client onto RISKMON is replacing the color grid with a dollar figure and a trend line. Loss exposure, the modeled annualized loss across the risk register, is a number a director can hold in their head. For that insurer it was $6.8M at the 90th percentile when we starte