Why most cyber board papers fail
The two most common failures are presenting technical metrics the board cannot act on, and presenting risk without a decision request. A board paper is not a status report — it is a request for a decision. If the paper does not end with options the directors must choose between, it has not done its job.
The board paper structure
Six sections that always belong
- Risk posture summary — one page, against Essential Eight maturity and ISO 27001 control families.
- Top three scenarios with likelihood, impact and current control coverage.
- Regulatory obligation status (APRA CPS 234, SOCI, OAIC, Privacy Act reforms).
- Incident readiness — last tabletop date, MTTR, last material incident, recovery posture.
- Decision request — risk appetite, investment envelope, accountability assignments.
- Appendix: control evidence, audit findings, third-party assurance status.
Framework anchors the board expects
ACSC Essential Eight maturity is the de facto Australian baseline and the question every audit committee asks first. ISO/IEC 27001:2022 provides the control language. APRA CPS 234 applies to authorised entities. The SOCI Act risk management program applies to critical infrastructure. For AI-related decisions, ISO/IEC 42001 and the federal AI Ethics Principles are now expected.
Translating cyber into board language
Replace MTTR with "how long until the business is operational." Replace "vulnerability count" with "exposure to material loss event." Replace "patch compliance" with "preventable incident risk." The board does not need the metric — they need the decision implication of the metric.
FOR CISOs WALKING INTO A BOARD
Generate a board-ready cyber risk paper in under 60 seconds.
FORTE/CYBERx structures the challenge into three ranked options, framework anchors and a tactical plan — exactly what an Australian board paper requires.
Start a free missionWhat to leave out
- Tool names and dashboard screenshots.
- Threat-actor names without business context.
- Technical metrics without a decision implication.
- Anything the audit committee already saw last quarter, unless it materially changed.
FAQ
How should a CISO present cyber risk to the board in Australia?
In Australia, boards expect cyber risk to be presented in business terms — financial exposure, regulatory exposure, operational impact — anchored to recognised frameworks such as ACSC Essential Eight and ISO 27001:2022. The board paper should state the current risk posture, the top three scenarios, the controls in place, the gaps and a clear decision request.
What should be in a cyber risk board paper?
A defensible cyber risk board paper contains: current risk posture against framework, top scenarios with likelihood and impact, control coverage, residual risk, regulatory obligations (APRA CPS 234, SOCI, OAIC), incident readiness status and an explicit decision request with options. Avoid raw technical metrics.
How often should the board hear about cyber risk?
APRA-regulated entities are expected to brief the board on cyber risk at least annually, with more frequent updates after material incidents or significant change. ASX 200 boards now expect at least quarterly reporting. Critical-infrastructure entities under SOCI should align cadence to their risk management program.
What does the board actually need to decide?
Boards rarely need to decide on technical controls. They need to decide on risk appetite, investment envelope, third-party risk thresholds, incident response posture and accountability. Frame the paper around those decisions, not around the threat landscape.