Board reporting in security is the periodic account a board or risk committee receives about how the security program is performing and what risk the organization is carrying. Boards are not asking for detail. They are asking whether the level of risk being run is the level they agreed to.
Where the organization sits against the levels it agreed to fund, and whether the gap is closing. See protection level agreement.
Direction of travel over several periods, not a single snapshot.
Which risks moved, and whether that movement was a decision or a surprise.
What the next increment of protection would cost.
Almost everything else is detail the board will not use and cannot act on.
They report activity instead of outcome. Alerts triaged, patches applied, awareness sessions delivered. All true, none of it answers the question the board asked.
They present a snapshot with no comparable history, usually because the history is not comparable. The tooling changed, the method changed, and nobody recorded either. See definition drift.
They cannot survive a follow-up question. A director asks where a figure came from and the answer takes three weeks and two analysts.
And they take a fortnight to assemble, which means the pack describes a quarter that is already over.
In regulated sectors the same material gets requested by supervisors, often retrospectively and often covering periods where the tooling has since changed. A pack that cannot be reproduced with its supporting evidence is a finding waiting to happen.
Metric Maestro measures the program continuously, so the board pack is drawn from a record that already exists rather than assembled from exports in the two weeks before the meeting.
Because each value carries the formula version and the records behind it, a follow-up question from a director or a supervisor has an answer the same day. And because definitions stay fixed while tools underneath them change, the multi-period trend a board is being asked to judge is a comparison of like with like.
From the blog