
BLOG
Board-Ready Cyber Risk Reporting for Healthcare
Published On August 19, 2026
Author: Morgan Hague
Typical cyber risk reporting quite often fails because it is written to describe operations rather than governance.
The typical report presented to executives and the board shows a dashboard full of activity, generates a lot of questions, but results in few decisions.
In healthcare, the stakes are even higher. Executives and boards need to understand how cybersecurity affects availability, clinical operations, third-party exposure, and the organization’s ability to recover. They will not get that understanding from a patch count.
The goal is to establish a framework that generates an explainable, repeatable, report that drives prioritization and accountability.
The core reporting model for effective board reporting is built on three pillars: Metrics + Narrative + Decisions.
The Core Reporting Model
A strong executive report consistently delivers:
- Metrics (the minimum set): A small number of measures signaling exposure and trends.
- Narrative (the context): Explanations of what changed, why it matters, and what happens next.
- Decisions (the outcome): The specific action required from leadership (approve, prioritize, accept, or escalate).
This reporting model is for executive governance (boards, risk committees, senior leadership) reports designed to be read in minutes and discussed in one meeting. It does not replace operational SOC dashboards or technical vulnerability reporting. Those serve different audiences, and mixing the two is one of the most common ways board reporting goes wrong.
To keep reporting defensible, document these assumptions up front:
- What counts as a “critical asset” (and who owns the list).
- How severity/risk scoring is defined.
- What data is incomplete (unknown ≠ good).
- The minimal metric set (risk, trend, exposure).
A board report does not need to include every KPI. However, it does need to provide enough information to answer these questions:
- What are our top cyber risks right now?
- Are we improving or drifting?
- How could a cyber event create material operational impact?
The Minimal Metric Set
The temptation with metrics is always to add more. Every additional measure feels like added rigor, but in a board setting the opposite is true. Each metric on the page competes for a limited amount of attention, and a wall of numbers pushes the conversation toward the data itself rather than the risk decisions the data should inform.
A practical KPI set typically fits into 6 to 8 metrics:
- Exposure and Enterprise Risk:
- Top risks (severity + trend): Top 5 to 10 cyber risks with a simple trend indicator (improving, stable, worsening) and a one-line driver.
- Critical asset coverage: Percentage of critical systems covered by core safeguards (monitoring, backup, recovery testing).
- Control Health (Executive View):
- Identity hygiene: MFA coverage for key systems, privileged accounts review cadence, and dormant account removal.
- Vulnerability remediation posture: Percentage of critical vulnerabilities remediated within the agreed window.
- Threat / Incident Impact:
- Incidents with business impact: A short count and a one-sentence summary covering downtime, data exposure, and clinical workflow impact.
- Readiness and Recovery:
- Recovery readiness confidence: Date of last restore test for critical apps and a simple confidence statement (high/medium/low) backed by evidence.
- Third-Party Exposure:
- High-risk vendor findings: Number of open high-risk vendor issues tied to critical workflows and their mitigation status.
Whatever set you land on, consistency matters more than perfection. Keep metric definitions stable quarter to quarter so trends are real trends, and always show denominators. “92% MFA coverage” means very different things depending on whether the denominator is all workforce accounts or a curated list of crown-jewel systems, and a board that has to ask is a board that has started doubting the data.
The Narrative Structure: What Changed / So What / Now What
Metrics on their own do not carry meaning. A board member looking at a remediation percentage has no way to know whether the number reflects progress, stagnation, or a change in how the number is calculated. An effective narrative will elevate data into a governance conversation, and the most reliable structure we have seen is a simple three-part arc.
Executives need context that translates cyber security into business relevance using a simple narrative arc:
- What Changed: Limit to 1 to 3 changes since the last reporting period (e.g., vendor findings mitigated, testing improved).
- So What: Explain the impact in healthcare terms (availability, operational risk, patient safety, financial and regulatory exposure) without fear mongering.
- Now What: State the top actions underway and what leadership input is needed.
This consistent lens works at several organizational levels. A CISO can use it for the full report, and a program lead can use it for a single risk area. Over a few reporting cycles, it also builds a running story the board can follow, which is something a rotating set of dashboard screenshots never achieves.
Turning Reporting into Decisions
Board-ready reporting should always end with a clear ask that is specific time-bound, owned, and measurable.
Common examples include:
- Approve funding for an identity modernization initiative.
- Prioritize a 60‑day remediation sprint for critical assets.
- Accept a defined residual risk for a time‑bounded period.
- Require vendor remediation as a contractual condition.
Common Board Questions to Prepare For
- What is our top cyber risk in business terms?y
- What has changed since last quarter, and why?
- Are we improving or drifting, and how can we prove that?
- How confident are we in recovery for critical systems?
- What is our most material third‑party exposure?
- What decision do you need from us this quarter?
- What risk are we intentionally accepting (and for how long)?
- How confident are you in the data behind these metrics?
Two things happen when reports consistently end with decisions:
- Accountability adapts and becomes traceable, as every accepted risk and funded initiative has a decision record behind it, which matters enormously in a regulatory inquiry or post-incident review.
- The board’s relationship with the security program will evolve from a simple briefing to an effective governance mechanism on one of the organization’s key risk areas that they can participate in.
Conclusion
The board doesn’t need every metric. They need a credible view of exposure and trend and a clear set of decisions.
Build your next report around Metrics + Narrative + Decisions, and leadership conversations become faster, calmer, and more actionable.
About the Author
Morgan Hague | Sr. Manager, IT Risk Management & AI Security Lead
Morgan is an experienced security and emerging technologies consultant, with varied expertise across information security, organizational governance, and IT audit practices. As the leader of the Security Risk Assessment and Strategic Risk Transformation service lines at Meditology, he has led and contributed to hundreds of consulting engagements across public and private entities.
Since 2019, he has served as lead architect and product owner of an innovative risk quantification, analysis, and reporting solution utilizing MITRE ATT&CK and similar authoritative sources to establish a data-driven and dynamic mechanism to assess, report on, and manage organizational risk – supporting a variety of premier healthcare organizations, including the nation’s largest hospital system. Morgan is currently the President of InfraGard Atlanta, and an effort lead for OWASP’s AI Security Guide.