
Board reporting drawn from the same record your risk owners actually use.
The executive dashboard in Horizon turns your risk register, control status and remediation progress into a board-ready view, so the figures in the meeting match the figures your team is working to.
Board packs that don't match what the risk owners are working from.
Cyber risk reporting to a board or audit committee tends to be built as a separate exercise from the day-to-day risk management work. Someone — often a CISO, IT manager or an external consultant — pulls together a slide deck ahead of the meeting, summarising a position that has usually moved on by the time it's presented, and translating technical detail into language a non-technical board can absorb in the time available.
That translation step is where things go wrong. Important nuance gets lost, figures get rounded in ways that flatter or understate the real position, and there's rarely a clear line from a headline statistic on a slide back to the risk register entry or control evidence that supports it. If a board member asks a follow-up question, the answer often isn't available in the room.
Insurers and larger clients running due diligence add another layer of the same problem. A questionnaire arrives asking for evidence of risk management maturity, control coverage and remediation performance, and answering it properly means someone reconstructing a current picture from several different sources, usually against a deadline that doesn't allow for it to be done carefully.
There's also a consistency problem across meetings. If the quarterly board pack is built independently each time, from whatever documents happen to be to hand, it's hard for a committee to see genuine trends — whether remediation is actually speeding up, whether the same control gaps keep reappearing, or whether risk scores are drifting up or down for a real reason rather than a change in who compiled the report.
None of this reflects a lack of effort. It reflects the fact that board-level reporting and operational risk management are usually built on different foundations, maintained by different people, on different timescales — so keeping them aligned takes constant manual work that's easy to deprioritise when other things are urgent.
- Board figures that don't trace back cleanly to the underlying risk register
- Reports rebuilt independently each quarter, making trends hard to see
- Insurer and client due diligence requests answered under deadline pressure
- Follow-up questions in the meeting that nobody can answer on the spot
One record, read two ways — by risk owners and by the board.
The executive dashboard doesn't run a separate reporting process; it reads directly from the same Horizon record your consultant maintains with your risk owners. When a risk is rescored, a control's evidence is renewed, or a remediation item is closed, the dashboard reflects it — there's no separate step where someone manually updates a board slide from a different source.
We work with you to agree what the board actually needs to see, which is usually a smaller and more strategic set of figures than the full register: overall risk trend, control maturity against Cyber Essentials and ISO 27001:2022 Annex A, evidence currency, supplier and third-party assurance status, and remediation progress from Secure Chain managed services where applicable.
Your Secure Chain consultant sets a reporting cadence with you — commonly quarterly for the board and monthly for management — and takes the dashboard into the meeting alongside you, explaining what has changed and why, rather than leaving you to interpret a slide deck alone. The dashboard gives the board something accurate to look at; the consultant gives them the context.
Because the same figures sit behind both the operational register and the executive view, a board member's question can be traced back to the specific risk, control or remediation item behind it, in the meeting if needed, rather than promised as a follow-up action.
For insurer renewals and client due diligence questionnaires, the dashboard export gives you a structured starting point — current risk position, control coverage and remediation performance — that can be adapted to the specific questions asked, rather than built from scratch each time a request lands.
- Dashboard figures drawn directly from the live risk register, not recalculated separately
- Reporting scope agreed with your consultant to suit board, not technical, audiences
- Consultant-led presentation of the dashboard, not a document sent unexplained
- Board questions traceable back to the specific risk or control behind them
Everything in the engagement, set out up front.
The executive dashboard is built on top of your existing Horizon risk and control data, configured to your reporting needs.
Executive summary view
Overall risk trend, control maturity and evidence currency presented for a non-technical audience.
Board-ready exports
A downloadable report formatted to sit inside an existing board or committee pack.
Framework maturity view
Control coverage shown against Cyber Essentials and ISO 27001:2022 Annex A at a summary level.
Remediation trend reporting
Progress on outstanding vulnerabilities from Secure Chain managed services, shown as trend rather than raw list.
Supplier assurance summary
Third-party register status rolled up into a single view of where supplier risk currently sits.
Consultant-led review
Your Secure Chain consultant presents the dashboard and answers questions, rather than leaving it to speak for itself.
What you receive.
- Configured executive dashboard linked to your live risk register
- Agreed reporting cadence for board and management review
- Board-ready export template for committee packs
- Framework maturity summary against Cyber Essentials and ISO 27001:2022 Annex A
- Remediation trend view drawn from managed services data
- Supplier and third-party assurance summary
- Role-based access for board members and senior management
- Consultant briefing notes ahead of each reporting cycle
Built for organisations that need the work done properly.
Boards asking for regular cyber updates
Organisations where cyber risk has become a standing board or audit committee agenda item needing a consistent format.
Firms facing insurer or client due diligence
Businesses regularly asked to evidence risk management maturity as part of renewal or procurement.
Companies with a CISO or risk lead reporting upward
Teams who need a reliable, current view to present without rebuilding it manually each cycle.
Regulated or growing businesses under scrutiny
Organisations where governance expectations have increased faster than internal reporting processes have kept up.
What changes once the work is done.
What changes once board reporting draws from the live record.
Figures the board can trust
Reporting drawn from the same data your risk owners use, not a separately maintained summary.
Real trend visibility
A consistent view across reporting cycles, so genuine progress or drift is visible rather than reset each quarter.
Fewer unanswered questions
Board queries can be traced back to the underlying risk or control in the meeting, not followed up later.
Faster response to due diligence
A structured starting point for insurer and client questionnaires, built from current data rather than assembled under pressure.
More useful board conversations
Time in the meeting spent on decisions and priorities, not on establishing what the current position actually is.
Clearer accountability at senior level
Risk trend and control maturity visible to the people ultimately accountable for it, on a predictable schedule.
A dashboard changes what the board conversation is about.
The most noticeable effect of moving board reporting onto a live dashboard isn't the format — it's what the meeting itself becomes about. When the figures are trusted and consistent from one quarter to the next, the discussion moves away from clarifying what the numbers mean and towards what to do about them: which risks need budget, which controls are behind schedule, and whether remediation is actually keeping pace with what's being found.
It also changes how audit committees and insurers are handled. A request for evidence of cyber risk management maturity stops being a fire drill answered from whatever documents can be found in time, and becomes a case of exporting a current, structured view and adapting it to the specific questions asked. That doesn't guarantee a particular outcome from an insurer or a client, but it removes most of the scramble that damages confidence during those conversations.
We're careful not to oversell what a dashboard changes on its own. It doesn't fix a control gap or decide a risk appetite — that's still the work your Secure Chain consultant does with your team between reporting cycles. What it does is make sure the board sees an accurate version of that work, consistently, without depending on someone manually reconciling several sources before every meeting.
Clients across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London use the dashboard alongside quarterly or monthly reviews with their consultant, and the pattern that tends to matter most to boards isn't any single figure — it's being able to see, meeting after meeting, whether the direction of travel is genuinely improving.
Questions we are asked most often.
Who is the executive dashboard built for?
Boards, audit committees, senior management and, increasingly, insurers and larger clients running due diligence. It's designed to be read by people who need to understand the organisation's cyber risk position and what's being done about it, without needing to interpret a technical risk register or a vulnerability scan report themselves.
Where do the dashboard's figures come from?
Directly from the same Horizon record your consultant maintains — the live risk register, control status against Cyber Essentials and ISO 27001:2022 Annex A, evidence currency, and remediation progress from Secure Chain managed services. Nothing on the dashboard is recalculated separately, so the board sees the same position your risk owners are working from.
How often is the dashboard updated?
It reflects the register as it stands, so figures move as risks are scored, controls are updated or evidence expires. For reporting purposes, most clients agree a cadence with their consultant — commonly quarterly for board packs and monthly for management review — so the export used in a meeting is a snapshot taken at a known point.
Can we export a report for a board pack?
Yes. The dashboard can be exported into a board-ready format covering overall risk position, control maturity, evidence status and outstanding remediation, so it can sit inside an existing board pack alongside financial and operational reporting rather than as a standalone technical document.
Does this replace our consultant's board presentation?
No. The dashboard gives the board an accurate, current picture to look at; your consultant still attends and explains what has changed, what's being prioritised and why, and answers the questions a static export can't. The dashboard supports that conversation rather than substituting for it.
Will this satisfy our insurer or a client's due diligence request?
It gives you a structured, evidenced answer to send rather than assembling one from scratch under deadline pressure. Whether it fully satisfies a specific insurer or client depends on what they've asked for, but having current risk, control and evidence data organised in one export removes most of the scramble that these requests usually cause.
Does the dashboard show individual vulnerabilities?
At board level it shows remediation progress and trends rather than a line-by-line vulnerability list, which is more appropriate for a technical audience. The underlying detail is available in Horizon for risk owners and IT teams who need it, so the dashboard stays readable without hiding the detail entirely.
Who can access the executive dashboard?
Access is role-based, so board members and senior management see the executive view while risk owners and technical staff work with the fuller register and control detail. You decide who from your organisation is added and at what level.
Cyber risk management platform
The underlying Horizon record the executive dashboard is built directly on top of.
Compliance support
Consultancy across ISO 27001 and other frameworks that feed into the control maturity view.
Vulnerability management as a service
The managed remediation work that feeds the dashboard's remediation trend reporting.
See the dashboard against a board pack like yours.
We can show you how a live risk register turns into board-ready reporting, or start with a free consultation to talk through what your current board pack is missing.
Book a dashboard demo