Decision questions Questions buyers ask before starting
What should a board cybersecurity report include?
It should focus on material risk, business impact, trend, resilience, major incidents, assurance status, critical third parties, exceptions, ownership, and explicit decisions required from leadership.
Should the board receive vulnerability counts?
Only when they support a material risk decision or trend. Raw vulnerability volume is usually operational; board reporting should translate exposure into business impact, ownership, threshold, and action.