If This Were Finance, the Board Would Throw You Out of the Room

The NACD says cyber literacy should be like financial literacy — not every director needs to be an auditor, but every director should be able to read the numbers. I agree. But boards are still being handed the wrong financial statements. Most cyber dashboards measure activity — attacks prevented, vulnerabilities mitigated, and control coverage — instead of what boards actually govern: revenue exposure, operational disruption, and financial impact. Imagine a CFO presenting invoices processed, journal entries completed, reconciliation metrics, and ERP uptime. The board would throw them out of the room. Cyber reporting needs to evolve from technical metrics to business risk. Until it does, cyber literacy alone won’t improve governance.

The National Association of Corporate Directors has argued that cyber literacy should be like financial literacy — not every director needs to be an auditor, but every director should be able to read the numbers.

Not everyone needs to be an auditor, but everyone should be able to read a financial statement.

I agree.

But there’s a fundamental problem.

Boards are still being handed the wrong financial statements.

Most cyber reporting looks professional — maturity scores, heat maps, patching statistics, phishing results, vulnerability counts. These metrics are presented as business risk, but they rarely connect to what boards actually govern: revenue, operations, and financial exposure.

Imagine a CFO walking into a board meeting and presenting:

 

  • Number of journal entries completed
  • Percentage of invoices processed on time
  • Average days to reconcile accounts
  • ERP system uptime

 

And concluding:

“Finance maturity improved this quarter.”

No revenue discussion. No exposure analysis. No downside scenarios.

The board would throw them out of the room.

Directors would ask:

 

  • What’s our exposure?
  • Where are we vulnerable?
  • What could it cost us?
  • What decisions do you need from us?

 

Instead, cyber reporting often substitutes activity metrics for risk reporting.

The Top 5 Things That Don’t Belong in Your Cyber “Financial Statements”

If this were finance, operational metrics would never replace financial statements.

Yet cybersecurity reporting does this every quarter.

Article content

These metrics are not useless.

They belong in management dashboards.

They do not belong in board reporting.

Boards govern risk and capital, not security operations.

What Boards Actually Need

Cyber reporting should look more like a financial statement:

 

  • Revenue exposed to a cyber disruption
  • Critical business processes at risk
  • Third-party dependency exposure
  • Estimated financial impact ranges
  • Recovery capability vs business tolerance

 

These are the cyber equivalents of income statements and balance sheets.

RELATED POSTS

Discover more from Stasiak

Subscribe now to keep reading and get access to the full archive.

Continue reading

[mailpoet_form id="5"]
[mailpoet_form id="1"]