Board reporting
One slide that survives the follow-up question
A completion percentage invites the wrong conversation. A graded, benchmarked trend with the movement explained gets you the second meeting — and, usually, next year's budget.
- 1 page
- for the board pack
- Quarterly
- trend with commentary
- Percentile
- against your industry
The report
Generated, not assembled the night before
Trend, benchmark, department breakdown and two or three sentences explaining the movement — produced from the same events the console shows, so nothing has to be reconciled by hand at quarter end.
- Quarter-over-quarter deltas
- Industry and size percentile
- Commentary generated with the export
Defensibility
Every number drills to a name
When a board member asks which departments are dragging the average, the answer is one click away rather than a follow-up action. That is the difference between reporting on a programme and running one.
- Per-department and per-site breakdown
- Repeat-failure cohort size over time
- Export to PDF, or API into the risk register
- Susceptibility rate10
- Credential-submit rate8
- Repeat-clicker rate8
- Time-to-click6
- Report rate9
- Real-threat response7
- Training completion6
- Multi-channel exposure7
- Department risk5
- Tenure / onboarding risk5
Questions
Asked on every first call
The ones that decide whether a first call turns into a second one.
2 questions
What metrics should a board actually see?
Four: the Behavioral Risk Score with its direction of travel, phish-prone rate, report rate, and your percentile against comparable organisations. Completion belongs in the appendix — it answers an operational question, not a governance one.
Can we put the score in our risk register?
Yes. Read it over the REST API with the factor breakdown intact, or receive it on a signed webhook whenever it changes. Several customers drive a GRC entry directly from it.
Keep reading
Related
See last quarter's report format
We will walk through a real board pack, redacted, and the numbers behind each panel.