Why we built this template
Most cyber board papers fail in one of two ways: they present technical metrics the board cannot act on, or they present risk without a decision request. Australian directors now sit under CPS 234, the SOCI Act and the Cyber Security Act 2024 — they need the report structured around the obligations they will personally answer for.
This template is the structure FORTE/CYBERx uses with Australian technology and security leaders. It survives a hard question from a non-executive director, an APRA review and an audit committee challenge.
What the template covers
Six sections, one defensible paper
- Executive summary (one page) — risk posture, change, decision request.
- Risk posture by domain — inherent vs. control maturity scoring with residual risk.
- Top three material scenarios — likelihood, dollar impact, treatment & owner.
- Framework alignment — Essential Eight, ISO/IEC 27001:2022, APRA CPS 234, SOCI, OAIC NDB, Cyber Security Act 2024, ISO/IEC 42001.
- Incident readiness & recovery — tabletop dates, MTTD/MTTR, insurance, IR retainer.
- Decision register — explicit options and recommendations for the board.
Australian regulatory anchors built in
The framework alignment tab is pre-populated with the obligations Australian boards expect to see: ACSC Essential Eight maturity, ISO/IEC 27001:2022 Annex A coverage, APRA CPS 234 information security capability, SOCI Act Risk Management Program status, OAIC Notifiable Data Breach readiness, Cyber Security Act 2024 ransomware reporting readiness and ISO/IEC 42001 for AI risk.
How to use it
Download the PDF for a print-ready board pack, or the Excel workbook to maintain a living version with formulas for residual risk and scenario exposure. Replace every bracketed placeholder with your data. Keep the executive summary to a single page — a board should be able to make the decision request from page one alone.
GENERATE IT AUTOMATICALLY
Skip the manual work — generate a board-ready paper in under 60 seconds.
FORTE/CYBERx turns your challenge into three ranked options, framework anchors and a tactical plan — populating exactly the sections this template asks for.
Start a free missionWhat to leave out of a board report
- Tool names and dashboard screenshots.
- Threat-actor names without business context.
- Technical metrics without a decision implication.
- Anything the audit committee already covered last quarter, unless it materially changed.
Frequently asked questions
What should a cyber security board report include in Australia?
An Australian board report should cover current risk posture, top scenarios, control maturity, framework alignment (Essential Eight, ISO 27001), regulatory status (APRA CPS 234, SOCI, OAIC NDB, Cyber Security Act 2024), incident readiness and an explicit decision request. Avoid raw technical metrics — translate them into business and regulatory implications.
How does the Cyber Security Act 2024 change board reporting?
The Cyber Security Act 2024 introduces mandatory ransomware payment reporting and additional incident notification obligations. Boards now expect the cyber report to confirm reporting readiness, identify named accountable executives and show that the entity can meet the statutory timeframes for notification.
How does APRA CPS 234 affect cyber board reporting?
CPS 234 makes the board ultimately accountable for information security capability. The board paper must show current capability against CPS 234 obligations, evidence of third-party assurance, incident notification readiness and any material weaknesses identified by internal audit or the regulator.
Is this template suitable for SMEs and non-APRA entities?
Yes. The template is anchored to Essential Eight and ISO/IEC 27001:2022 — frameworks every Australian organisation can adopt. The APRA CPS 234 and SOCI rows are optional and can be removed for entities not covered by those obligations.
How often should I present this report to the board?
ASX 200 and APRA-regulated entities should brief the board at least quarterly. Critical-infrastructure entities covered by the SOCI Act should align cadence to their Risk Management Program. Australian SMEs typically present at least bi-annually with ad-hoc updates after material incidents.