# Cybersecurity board report template

CYBERSECURITY BOARD REPORT — DECISION BRIEF
Company / business service: [name and scope]
Meeting date / evidence cut-off: [dates]
Prepared by / evidence reviewer: [names and roles]

1. DECISION REQUIRED
Approve / defer / request validation: [specific action]
Amount, currency, cost horizon and budget cap: [values]
Budget approver / decision deadline: [name and date]

2. EXPOSURE AND BUSINESS CONTEXT
Loss scenario and affected service: [description]
Baseline annual gross loss: [mean and selected percentile, or unknown]
Sources, model version and assumptions: [links and dates]
Insurance treatment and exclusions: [state explicitly]

3. ALTERNATIVES
Option | first-year cost | modeled mean | modeled P95 | evidence gaps
[baseline] | [cost] | [value] | [value] | [gaps]
[proposed] | [cost] | [value] | [value] | [gaps]
[alternative / held option] | [cost or unknown] | [values or not modeled] | [gaps]

4. RECOMMENDATION AND WHAT COULD CHANGE IT
Chosen objective and why this option fits: [reason]
Required work and implementation dependencies: [items]
Sensitivity / missing evidence that could reverse the choice: [items]

5. APPROVAL AND FOLLOW-THROUGH
Decision / conditions / approver / date: [record]
Execution owner and due date: [name and date]
Verification evidence and next review: [test, owner and date]
Observed control change: [evidence or not yet verified]
Modeled financial change: [recomputed estimate or not yet modeled]

Source: https://valty.ai
Free to adapt for your organization. Replace placeholders with reviewed, scoped evidence.
