Eighteen months later, a significant security incident occurred. The board's post-incident review found that the conditions that produced the incident had been present in the environment for at least twelve months before the incident. The conditions were not reflected in the CISO's reports. The CISO had not been reporting on them because they were outside the scope of the established reporting framework. The reports were accurate. The board's understanding of the organization's security posture was not.
Accuracy Is Not the Same as Adequacy
Security reporting that is accurate within its scope can be inadequate for the board's governance purposes if the scope does not cover the conditions most relevant to the organization's risk position. A reporting framework established three years ago may accurately describe the security program's activities and outcomes in the domains it was designed to cover while being silent on the conditions that have emerged since the framework was established.
The board that receives accurate reporting within an inadequate scope is better informed than the board that receives no reporting. It is not adequately informed. The distinction matters because boards that are receiving accurate reports from their CISO may not perceive any reason to question whether the reporting scope reflects the full risk picture. The reports look complete. They are complete within their scope. The scope gap is invisible without external reference.
Accurate reporting within a scope that does not reflect the full risk picture produces an informed board whose information is incomplete. The board cannot know what is not in the reports they receive. Assuring that reporting scope reflects the current risk landscape is a governance responsibility that sits above the reporting itself.
Three Ways Reports Are Accurate and Inadequate Simultaneously
Scope That Predates Significant Environmental Changes
A reporting framework designed when the organization was primarily on-premises may accurately report on on-premises security metrics while being silent on the cloud environment that has grown to host 60 percent of production workloads. The reporting is accurate for what it covers. The board's understanding of the security posture of 60 percent of the production environment is based on reports that do not address it.
Metrics That Capture the Governed Population, Not the Full Population
Security metrics based on the population of systems within the governance program's scope accurately describe security posture within that population. Systems added to the environment outside the program's scope, vendor systems with access to the environment, and SaaS applications provisioned without IT involvement are outside the metric population. The board sees metrics that describe 80 percent of the environment and understands them as describing the environment.
Risk Ratings That Are Relative to Historical Baselines
Risk ratings that express risk as relative to historical baselines — better than last quarter, at historical low, trending in the right direction — describe the risk position relative to the organization's own history. They do not describe the risk position relative to the current threat landscape or relative to peer organizations. The organization that has consistently improved its internal risk metrics while the external threat landscape has escalated may have an improving internal risk position and a deteriorating external risk exposure simultaneously. The relative improvement is real. It does not describe the absolute exposure.
Closing the Scope Gap
Closing the gap between accurate reporting and adequate governance information requires periodic assessment of whether the reporting scope reflects the current risk environment — not just whether the current reports are accurate within their current scope. This is a governance meta-question: not 'is the CISO reporting accurately?' but 'is the CISO reporting on the right things?'
The mechanisms for this assessment: annual reporting scope review that asks whether significant environmental changes, new risk categories, or changed threat landscapes have created risk dimensions that are not in the current reporting scope. External reference comparison that identifies risk categories receiving regulatory attention or appearing in peer organization incidents that are not in the current reporting framework. Post-incident scope reviews that ask whether the conditions that produced the incident were within reporting scope.
The board's role in this is to ask the meta-question directly: is there significant risk in our environment that we are not being informed about through current reporting? The CISO who is asked this question regularly, by a board that understands the scope gap as a governance risk, is a CISO who has organizational support for expanding reporting scope when the risk landscape changes.
Assure that the reporting scope reflects the current risk landscape, not just that the current reports are accurate. The scope gap is the governance gap.
Conduct the annual reporting scope review. Ask what the reports do not cover. Compare the scope to the risk landscape. The gap between them is the governance information gap.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
