The National Association of Corporate Directors has argued that cyber literacy should be like financial literacy — not every director needs to be an auditor, but every director should be able to read the numbers.
Not everyone needs to be an auditor, but everyone should be able to read a financial statement.
I agree.
But there’s a fundamental problem.
Boards are still being handed the wrong financial statements.
Most cyber reporting looks professional — maturity scores, heat maps, patching statistics, phishing results, vulnerability counts. These metrics are presented as business risk, but they rarely connect to what boards actually govern: revenue, operations, and financial exposure.
Imagine a CFO walking into a board meeting and presenting:
- Number of journal entries completed
- Percentage of invoices processed on time
- Average days to reconcile accounts
- ERP system uptime
And concluding:
“Finance maturity improved this quarter.”
No revenue discussion. No exposure analysis. No downside scenarios.
The board would throw them out of the room.
Directors would ask:
- What’s our exposure?
- Where are we vulnerable?
- What could it cost us?
- What decisions do you need from us?
Instead, cyber reporting often substitutes activity metrics for risk reporting.
The Top 5 Things That Don’t Belong in Your Cyber “Financial Statements”
If this were finance, operational metrics would never replace financial statements.
Yet cybersecurity reporting does this every quarter.
These metrics are not useless.
They belong in management dashboards.
They do not belong in board reporting.
Boards govern risk and capital, not security operations.
What Boards Actually Need
Cyber reporting should look more like a financial statement:
- Revenue exposed to a cyber disruption
- Critical business processes at risk
- Third-party dependency exposure
- Estimated financial impact ranges
- Recovery capability vs business tolerance
These are the cyber equivalents of income statements and balance sheets.


