Board Reporting Pack
Monthly Report - 1/12/2026
Top 5 Risks
Third-Party Vendor Data Breach Risk
In Progress - Enhanced monitoring implemented
Ransomware Attack Surface
Controls in place, testing scheduled Q2
Legacy System End-of-Life
Migration plan approved, funding pending
Insider Threat - Privileged Access
PAM solution deployed, monitoring active
Regulatory Compliance Gaps
Remediation 75% complete, on track
Top 5 Actions
Complete SOC 2 Type II Audit
Deploy MFA for All Critical Systems
Annual BCP Testing Exercise
Vendor Risk Reassessment (Critical Tier)
Security Awareness Training Rollout
Key Highlights
- Zero critical security incidents this period
- Phishing simulation click rate decreased 15% (improvement)
- 3 new critical vendors onboarded with full due diligence
- Completed 12 of 15 planned audit remediation items
- Board-approved cybersecurity budget increase for Q2
Budget Approval for EDR Platform Upgrade
Current endpoint protection reaching end-of-life. Upgrade required to maintain security posture and compliance.
Recommendation: Approve $125,000 for CrowdStrike Falcon Complete deployment
Financial Impact: $125,000
Accept Residual Risk - Legacy Loan System
Legacy system cannot support modern authentication. Compensating controls in place (network segmentation, enhanced monitoring).
Recommendation: Accept residual risk for 12 months with quarterly reviews
Updated Remote Work Security Policy
Policy revisions to address hybrid work environment and BYOD considerations.
Recommendation: Approve updated policy effective March 1, 2025
Annual Enterprise Risk Assessment
Risk identification complete, impact analysis in progress
Tabletop Exercise - Core System Outage
Scenario developed, participants confirmed
Annual Security Awareness Training
28% of staff not yet completed, follow-up emails sent
Remediate Prior Year Audit Findings
12 of 15 findings closed, 3 in final validation
FFIEC CAT Self-Assessment
Scheduled to begin Q2