DTG-MR19 · Board & Executive Governance · 4 min

How Do You Know When Your Risk Reporting Has Stopped Reflecting Reality?

Risk reporting that has stopped reflecting reality is a more common governance condition than most practitioners acknowledge. The indicators are subtle: metrics that have…

DTG-MR17 · Board & Executive Governance · 4 min

The Risk Appetite Statement Nobody Refers to When Making Risk Decisions

The risk appetite statement was developed over three months. It involved the board, the executive team, the CISO, and the CRO. It was approved at the highest governance l…

DTG-MR15 · Board & Executive Governance · 4 min

When Leadership Visibility Ends at the Edge of the Slide Deck

The slide deck is the governance product that the security and privacy functions deliver to leadership. It is curated, organized, and designed to communicate effectively…

DTG-MR11 · Board & Executive Governance · 4 min

The CISO's Report Was Accurate. The Board's Understanding Was Not

The CISO presented the quarterly security report to the board. The report was accurate in every particular: the metrics were correctly calculated, the risk ratings were d…

DTG-MR09 · Board & Executive Governance · 4 min

The Board Asked About Cyber Risk. The Report Answered About Cyber Activity

The CISO's quarterly report to the board contained forty-three slides. It covered vulnerabilities patched, phishing simulations completed, security awareness training com…

DTG-MR08 · Board & Executive Governance · 4 min

Activity Metrics Are Not Risk Metrics. Stop Presenting Them as the Same Thing

The security dashboard presents: 94,000 vulnerabilities remediated this quarter. 2,847 phishing emails blocked. 99.3 percent of systems with current endpoint protection.

DTG-MR02 · Board & Executive Governance · 4 min

The Numbers That Run Your Risk Program Are Wrong

This is not a claim that your data is fabricated or your team is incompetent. It is a claim about the nature of risk measurement. Risk is the product of likelihood and im…

DTG-EG22 · Board & Executive Governance · 4 min

Accountability Without Visibility Is Just Blame With Extra Steps

Enterprise governance programs assign accountability with confidence. Risk owners are named. Control owners are documented. The RACI is populated and reviewed.

DTG-EG20 · Board & Executive Governance · 5 min

The Governance Program That Survived Every Audit and Failed One Incident

The governance program had a perfect audit record. No significant findings in four consecutive external audits. Internal audit consistently rated the security program as…

DTG-EG19 · Board & Executive Governance · 4 min

Hardest Problems in Enterprise Governance Don't Have Framework Answers

Governance frameworks are excellent tools for the governance problems they were designed to solve. NIST CSF provides structure for cybersecurity risk management.

DTG-EG16 · Board & Executive Governance · 4 min

The Incident That Revealed How Shallow the Governance Program Actually Was

The governance program had been in place for four years. It had passed external audits. It had received favorable board assessments. The maturity scores had improved cons…

DTG-EG13 · Board & Executive Governance · 5 min

The Quiet Accumulation of Risk That the Quarterly Report Never Captured

Risk accumulates in the space between reporting cycles. Not catastrophically — not in events that are unmistakable at the time. It accumulates through the incremental dec…

DTG-EG10 · Board & Executive Governance · 4 min

Strategic Risk Is Easy to Discuss. Operational Risk Is Where Leaders Go Quiet

Board discussions of strategic risk are substantive. The risk that a competitor deploys AI capabilities faster than the organization. The risk that regulatory change affe…

DTG-EG07 · Board & Executive Governance · 4 min

Delegating Risk Ownership Without Delegating Risk Visibility Is Not Governance

The board assigned risk ownership for cyber risk to the CISO. The CISO assigned ownership of specific risks to business unit leaders. Business unit leaders assigned opera…

DTG-EG05 · Board & Executive Governance · 4 min

Governance That Scales on Paper and Fragments Under Pressure

The governance framework covered the organization at its current scale. The risk committee structure, the control ownership model, and the reporting mechanisms were desig…

DTG-EG02 · Board & Executive Governance · 5 min

Everyone Owned the Risk. Nobody Got the Call at 2am

The incident started at 11:47pm on a Wednesday. The security operations team detected it at 12:14am. By 12:30am they needed a decision: contain the affected systems and a…

DTG-372 · Board & Executive Governance · 9 min

Board-Level Reporting Highlights Trends. Not Exposure

Board risk reporting shows trends: improvement in coverage percentages, reduction in open findings, increase in training completion rates. These are activity trends.

DTG-361 · Board & Executive Governance · 9 min

Boards See Compliance. Not Operational Risk

Board risk reporting is built around compliance metrics and audit outcomes: controls in place, assessments completed, findings remediated. What it is not built around is…

DTG-142 · Board & Executive Governance · 11 min

Board Reports Highlight Activity. Not Exposure

Boards receive reports that describe what the security and privacy organization has done: incidents responded to, controls implemented, assessments completed, training de…

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center