WHAT’S INSIDE
Most Board Reports Measure Effort, Not the Posture Directors Must Govern
Board oversight of cyber risk became disclosable fact for U.S. public companies in 2023, and private organizations now field the same questions from investors, insurers, acquirers, and enterprise customers. Most board reporting fails not from a lack of data but from the wrong data: activity metrics that describe effort rather than posture. AI has added a category of risk most board packages do not yet contain.
This guide sets out what regulators and stakeholders now require, defines the elements of a report a board can actually govern with, names the failure patterns, and provides a quarterly reporting structure aligned to the ARISE Framework™. IBM’s 2025 breach research found that 20 percent of breached organizations were compromised through unsanctioned AI use that governance never saw, the exposure a silent board package leaves unmanaged.
What a governable report contains. Seven elements every board package needs: material risks in business terms, posture against a named framework, decisions with their costs attached, detection and response readiness, third-party exposure, an AI section, and incidents stated plainly.
The failure patterns. Four recurring failures that make a report unusable: activity presented as achievement, fear used as a budget strategy, the once-a-year deep dive, and reporting anchored to no framework and therefore no trend.
Reporting through ARISE. A quarterly reporting spine in which each of the seven ARISE domains, GOVERN, MANAGE, IDENTIFY, PROTECT, DETECT, RESPOND, and VALIDATE, contributes one section, so directors see trajectory rather than snapshots.
Appendix A, the board reporting readiness question set. Eleven questions split between the executives who prepare the report and the directors who receive it, six for the preparers and five for the recipients, used to expose the gap current reporting must close.