Most boards hear about security once a year, usually after something went wrong. A slide appears, someone reads it out, and everyone moves on. That worked when security was an IT problem. It doesn't work now that regulators have put the board itself on the hook.

NIS2 and DORA changed the question. It's no longer "is the security team doing its job?" It's "can management show they're steering this, with evidence?" That means metrics your board can read, trust, and act on. This post covers which metrics matter, how to present them, and how to avoid the vanity numbers that make a program look healthier than it is.

Why the board is now accountable

NIS2 and DORA both push responsibility up. Under NIS2, management bodies have to approve cybersecurity risk measures and oversee how they're carried out, and members can be held personally liable for failures. DORA does the same for financial entities, putting the management body in charge of the digital operational resilience framework and requiring it to stay actively informed.

The practical effect is simple. Your board can't treat security as a black box it funds and forgets. It has to demonstrate oversight, and oversight without numbers is just a claim. That's why board reporting moved from a nice-to-have to a governance requirement. The metrics you bring are the evidence that management steers the program instead of hoping it works.

The metrics that matter

A good board report answers a few plain questions: are our controls working, what's broken, how fast do we fix it, and where's the risk trending? Six metrics cover most of that ground.

Control health

Show the share of controls that are implemented and operating as designed, split by framework. A single number across SOC 2 Type II, ISO 27001, GDPR, NIS2, and DORA hides too much, so break it out. The board doesn't need every control, it needs to see which frameworks are solid and which are thin.

Open findings by severity

Count your open findings and group them by severity. Ten low-severity findings and one critical are very different situations, and a raw total blurs them. Severity is what tells the board where to look.

Overdue remediation

A finding with a due date that's passed is the metric auditors and regulators care about most, because it shows whether your process actually closes the loop. Track how many remediation items are overdue and how long they've been sitting. This is often the single most honest signal of program health.

Training completion

Awareness training completion is a required control under most frameworks and a leading indicator of culture. Report the completion rate and flag teams that lag. It's simple, but a low number here undercuts every other assurance you give.

One incident is an anecdote. The trend is the story. Show incident volume over time, time to detect, and time to respond, so the board sees whether you're getting faster or falling behind. Under NIS2 and DORA, response times aren't just operational, they're reportable.

Vendor risk

Your risk includes your suppliers. Report how many vendors you've assessed, how many are overdue for review, and how many carry unresolved high risks. DORA is explicit about third-party risk, so this metric has teeth now.

Leave the vanity metrics out

The fastest way to lose a board's trust is to bring numbers that look impressive and mean nothing. "We ran 4,000 scans this quarter" tells them about activity, not outcomes. "We have 300 controls" says nothing about whether they work.

Every metric you present should tie to a decision the board can make: approve a budget, accept a risk, or move a deadline. If a number can't change what anyone does, cut it. A short report of six metrics that drive decisions beats a dashboard of forty that drive nods. Trend and target matter more than raw counts, so show direction and a threshold, not just today's figure.

How to present it to a board

Boards don't read dashboards, they read stories with numbers attached. A few habits make your report land:

  • Lead with the exceptions. Start with what's off track and what you're doing about it, not a wall of green.
  • Give every number a trend and a target. "Overdue remediation is 12, down from 19, target under 5" says far more than "12".
  • Attach an owner and a date to each risk. Accountability is the point of the meeting.
  • Keep it to one page per framework at most. Detail lives in the OptiTech Console, not the board deck.
  • End with decisions, not information. Tell the board exactly what you need from them.

How OptiTech surfaces your program metrics

The reason board reporting hurts is that the numbers usually live in five places, and someone spends a week stitching them into a slide that's stale the day it's presented. OptiTech removes that step because the metrics come from the same program that runs your day-to-day compliance.

Your controls, findings, remediation items, training records, incidents, and vendor assessments all live in one program in the OptiTech Console. Control health, open findings by severity, and overdue remediation are already calculated, so a board view is a filter, not a research project. Because every number links back to its underlying evidence, a director who asks "how do we know?" gets an answer in a click instead of an email thread.

Data stays in the EU, in Stockholm or Frankfurt, which is one less question you field from a nervous board. And the same program that produces the board report feeds your trust center, so the assurance you show your directors is the assurance you show your customers.

Report the trend, not the snapshot

A single figure invites the wrong question. Bring the last few quarters and a target for every metric, so the board debates direction and priorities instead of arguing about whether one number is good or bad.

Getting started

You don't need a perfect program to give the board a useful report. Start small and improve each quarter:

  1. Pick your six metrics and define what each one means, so the numbers stay consistent meeting to meeting.
  2. Set a target and a trend for each, even a rough one, so the board has something to steer toward.
  3. Assign an owner to every open risk before the meeting, so accountability is clear.
  4. Pull it from one source so the report reflects reality on the day, not last month.

NIS2 and DORA turned board reporting into a governance duty, but they also gave security leaders a real seat at the table. Bring metrics that drive decisions, show the trend, and your board moves from nodding along to actually governing.

Ready to give your board numbers it can trust? Book a demo and see how OptiTech turns your program into board-ready metrics.