
I once watched a CISO hand a board a 200-page risk assessment. Real work — months of scans, interviews, control mapping. He was proud of it, and he should have been. Then he watched the chairman flip to the executive summary, read four lines, and pass the binder to his left without a word. Nobody opened it again. Ten minutes later the board moved on to the quarterly real estate report.
That silence taught me more about governance than any framework ever did.
The Report Nobody Reads
Boards are not stupid, and they are not lazy. They are time-starved fiduciaries sitting through six agenda items in ninety minutes, and cyber is usually item five, right before “any other business.” They don’t want your methodology, your NIST subcategories, or the fact that you mapped 340 controls against ISO 27001 Annex A. They want to know three things, and I’ve heard some version of this from every chairman I’ve sat across from in twenty years:
- What can actually hurt us — in money, in customers, in regulators knocking?
- What are we doing about it, and is it enough?
- What do you need from us to close the gap — budget, headcount, a decision?
Everything else is appendix material. I learned this the hard way early in my career, building ISO 27001 from scratch at a startup where the board was three investors who cared about one thing: would a breach kill the next funding round. They didn’t need a control matrix. They needed a number.
The Formula 1 Analogy, Again
I keep coming back to brakes. Nobody in an F1 pit briefs the team principal on brake pad chemistry, disc temperature curves, or caliper torque specs before a race. The engineer says: “Brakes are good for 300 laps at this heat, we’re racing 60, we’re covered — but tire wear on the rear left is the risk today.” One sentence. Confidence plus the one thing to worry about.
Cyber governance should read the same way. Not “we have 47 open findings across four severity tiers.” Instead: “Our exposure to ransomware taking down finance for five days is a 6-figure loss with 70% likelihood inside 18 months unless we close two specific gaps — here they are, here’s the cost to close them, here’s the cost of doing nothing.”
I’ve run this comparison in front of boards at banks and insurers across Israel and Europe. The moment you translate control gaps into “days of downtime” and “cost per incident,” the room leans forward. The moment you say “CVSS 9.8,” they lean back and check their phones.

What the Slide Actually Looks Like
At BDO’s Cyber Risk Advisory, before I present anything to an audit committee, I force myself through one discipline: fit the entire risk posture on a single page, and if it doesn’t fit, I haven’t finished thinking. The page usually has four elements:
1. The Business Impact Number
Not “high/medium/low.” A number, or a tight range, derived from a real Business Impact Analysis — what does one day of ERP downtime cost this specific company, what does a customer data leak cost in regulatory fines plus churn. I did this exercise with a European manufacturing client: their BIA showed a production-line stoppage cost €180,000 per day. Suddenly, the OT segmentation project that had been “under review” for eight months got approved in one meeting, because the board could finally multiply.
2. The Heat Map, Not the Spreadsheet
Five to seven risk items, plotted by likelihood and impact, color-coded. That’s it. If an item isn’t in the top seven, it doesn’t belong on the board slide — it belongs in my working file with the CISO team.
3. The Trend Line
Boards care about direction more than snapshots. “We were red on identity governance last quarter, we’re amber now, here’s what closed the gap” tells a story of a program that works. A static list of findings tells a story of a program that’s stuck.
4. The One Ask
Every good board slide ends with a decision the board needs to make — approve budget, approve a policy exception, approve a hire. If there’s no ask, you probably didn’t need the meeting.

A Boardroom Story That Still Bothers Me
Years ago, doing a risk survey for a financial services client, I found what I’ll politely call shadow data — production customer records sitting in an unmanaged file share, no DLP, no owner, accessible to half the company. Classic DSPM blind spot: nobody set out to create this mess, it just accumulated, like sediment, until it became a lake nobody remembered digging.
I had two ways to present it. Option one: forty slides on data classification maturity, discovery methodology, and a RACI chart for remediation. Option two: “We found 40,000 customer records with no owner and no access control. If this leaks, under GDPR that’s a fine calculated on global turnover, not on the size of this file share. Here’s the six-week plan to fix it, here’s what it costs.” I chose option two. The board approved the remediation budget before I finished the sentence about the fine.
The technical work behind that slide was still real — the scans, the classification engine, the access reviews. The board never needed to see any of it. They needed to see the consequence and the exit.
Why the 200 Pages Still Matter — Just Not There
I want to be careful here, because I’m not arguing for superficiality. The 200-page report should exist. It’s the evidence, the audit trail, the thing your regulator or your insurer will ask for after an incident, the thing that proves the one-pager wasn’t invented on a napkin. It’s also the artifact your own team uses to actually do the work — the ghosts in the servers don’t get exorcised by a heat map, they get exorcised by the unglamorous, granular remediation plan that lives underneath it.
The skill — the thing I try to teach in the CAIO course and in every board briefing I run — is knowing which document belongs in which room. The 200 pages are for the engine room. The one page is for the bridge. Confuse the two, and you either bore the board into disengagement or drown your own team in slogans they can’t execute against.
Practical Takeaways
- Lead with money, not maturity scores. Translate every major risk into a real business number using an actual BIA — cost per day of downtime, cost per record exposed — before it reaches a board deck.
- Cap the board slide at one page, seven risks, one ask. If it doesn’t fit, the thinking isn’t finished; push the detail into a supporting appendix, not into the room.
- Show direction, not just position. A trend line from red to amber tells the board the program works; a static finding list tells them it’s stalled.
- Keep the 200 pages — just keep them in the right room. They’re evidence and execution fuel for your team and your auditors, not board material.
Back to the Silent Binder
That report I mentioned at the start — the one that got passed down the table unopened — the CISO rewrote his ask for the next quarter as one page: a business impact number, a five-item heat map, a trend arrow, and a single funding request. Same underlying work. Different room, different language. This time the chairman read it twice and asked a question. That’s the whole job, really — not writing more pages, but finally being understood on the page that counts.
I write From the CISO’s Diary from 20 years across BDO, ThriveDX, the IDF and my own ventures. Let’s connect: Omri Sagron on LinkedIn.