What belongs on the board’s cyber and AI page — and what does not

There are two kinds of cyber paper that reach Caribbean boards, and neither of them works.

The first is thirty slides prepared by someone technical, containing patch counts, vulnerability severities, tool coverage percentages and an architecture diagram. It is accurate, it represents real work, and it is unreadable by the audience it was written for. Directors skim it, nobody asks a question, and the minute records that the board received an update on cybersecurity.

The second is two sentences in the CEO’s report: cybersecurity remains a priority; no significant incidents occurred during the period. It is readable, brief, and contains no information at all. It cannot be wrong, because it says nothing that could be tested.

Between the unreadable and the uninformative sits a document most boards have never been given: one page that tells them where the organization stands, whether it is improving, and what needs a decision.

That page is not hard to produce. But it does require somebody to produce it on a schedule, in the same format, every period — and that turns out to be the difficult part.

1.  What a board is actually deciding

Before designing the page, it helps to be precise about what directors are being asked to do. On cyber and AI, a board makes three decisions and no others.

Accept. The position is understood and tolerable. This is a real decision, and it should be recorded as one — governed risk acceptance, with a name attached, not silence that later gets described as acceptance.

Fund. Something needs resources it does not currently have. The board is the only body that can supply them.

Escalate. Something requires management attention beyond what the reporting line is giving it, or requires the audit committee to look more closely.

Every item on the page should serve one of those three. A metric that cannot lead to accept, fund or escalate is not a governance metric. It may be an excellent operational metric — and it belongs in the operations meeting.

This is the filter that makes the one-page test possible. Not “is this true?” but “what would this cause the board to do?”

2.  The six things that belong on the page

One. The current position, dated. Where the control environment stands against a defined standard, expressed simply enough to be read in ten seconds. A maturity rating, a red-amber-green by domain, or both. And a date — the date the position was measured, not the date the paper was printed.

Two. The direction of travel. The same measure for the previous three or four periods. Direction is worth more than level. A board that knows it is at three and rising has different work to do than one at three and falling, and the level alone cannot distinguish them.

Three. Open exceptions, by age. Not a count — a count can be gamed by closing easy items. Age is what matters: how many items are open, and how long the oldest has been open. A register where the oldest item is 400 days old is telling the board something no summary paragraph will.

Four. Ownership of the open items. By name and by date. Not “IT” — a person. Not “in progress” — a target date, and a note when the date moves.

Five. The vendor watchlist. Which third parties changed materially this period: added AI capability, suffered an incident, let an assurance report expire, or triggered a contractual question. Most boards have no visibility of this at all, and it is where a growing share of the exposure now lives.

Six. Incident and readiness posture. Incidents this period, near misses worth naming, and whether the response arrangements have been exercised recently enough to be believed.

That is the page. Everything else is an appendix.

Illustrative control dashboard — position, trend, exceptions and vendor watchlist on one view

3.  The four things that do not belong

Raw vulnerability counts. “We closed 1,240 vulnerabilities this quarter” is a number without a denominator, a severity distribution or a trend. It sounds like progress and carries no meaning at board level.

Tool inventories. Which platforms are deployed is a procurement fact, not a control outcome. The board’s question is whether the controls work, not what was bought.

Vendor marketing language. If a phrase in the board pack could appear in a product brochure, it is doing sales work rather than reporting work. Terms like “next-generation,” “AI-powered” and “military-grade” should not survive the edit.

Anything undated. An assertion with no date attached cannot be assessed. It is the single most common defect in the cyber papers we read, and it is also the easiest to fix.

4.  Every number carries a date

One point of evidence, or twelve

This is worth isolating, because it is the discipline that changes the character of the whole document.

Attach a date to every figure on the page and two things happen immediately. Numbers that are quietly a year old become visibly a year old — and somebody has to decide whether that is acceptable. And the board acquires a question it can ask about anything, in any meeting, without technical knowledge: as of when?

The reason this matters more with AI in the picture is that the underlying position now moves faster than it used to. A vendor can add model-driven functionality to a platform in a release note. A team can adopt a generative tool in an afternoon. An access right granted for a project can outlive the project by two years. None of these announce themselves, and all of them change the position between one board meeting and the next.

An annual assessment answers the question for one date. For the other eleven months, the honest answer to as of when is: last November.

5.  Trend beats snapshot

A single reading tells a board where things stand. Four readings tell it whether the organization is capable of improving — which is the more important question, and the one a single assessment structurally cannot answer.

Trend also changes the conversation from defence to management. A director looking at one red rating asks who is responsible. The same director looking at four periods of a red rating slowly turning amber asks what would make it move faster. The second question is more useful, and management is far more willing to bring bad news into a room where the trajectory is visible.

There is a discipline cost. Trend only works if the measure stays constant — same domains, same scale, same definitions, period after period. The temptation to improve the framework every cycle must be resisted, because a redesigned dashboard resets the history and the organization loses the only thing that took time to build.

6.  The open items list is the real document

If a board reads only one section, it should be this one.

The rating is a summary. The trend is context. The open items list is where the actual state of the organization lives: what is broken, who is fixing it, and whether the fixing is happening.

Three properties make it useful.

It carries forward. Items appear and remain until closed. Nothing falls off because a reporting period ended, a project finished, or the person who raised it left.

It ages visibly. Each item shows how long it has been open. An item that has been open through four board meetings is itself a governance finding, independent of its technical content.

Closure means retested, not reported. An item moves to closed when somebody independent has checked that the fix works — not when the owner said it was done. Otherwise the list becomes a record of intentions.

A findings register that only ever grows is a problem. A findings register that empties suspiciously fast is a bigger one.

7.  Who prepares the page

A practical question, and the answer determines how much the page is worth.

If the team operating the controls also prepares the board’s assessment of those controls, the document is self-assessment. That is not disqualifying — most reporting works this way and often works well — but the board should know which kind of document it is holding, because the two carry different weight with a regulator, an insurer or an external auditor.

The separation is straightforward to arrange. The people who run the systems supply the data. Somebody who does not run them assembles, tests and reports it. That party can be internal audit, where it has the capacity and independence. Where it does not, it can be an external provider — provided that provider is not also selling and operating the technology it is reporting on.

We monitor; we do not operate. That distinction is the entire reason the resulting dashboard can be used as evidence rather than as a management assertion.

8.  Capability without headcount

There is a practical obstacle behind all of this, and it deserves naming rather than stepping around.

Producing a credible page every quarter requires somebody whose job it is. Most organizations in this region — credit unions, mid-sized financial institutions, public sector agencies, utilities, professional firms, data-sensitive SMEs — cannot justify a full internal cyber governance team. They may have a capable IT manager who is fully occupied keeping systems running, and no dedicated capacity for oversight of those systems.

The result is the pattern we see repeatedly: a good assessment is commissioned, useful findings are produced, and then nothing happens for eleven months because there is no standing capability to carry the work between engagements. The assessment was not wasted, but most of its value was.

A managed monitoring cadence solves a resourcing problem, not a technology one. The organization gets the oversight function without the headcount, at a rhythm set to its own board calendar, and the findings from the last assessment are actually carried to closure rather than filed.

9.  Setting the cadence

Match it to the governance calendar rather than to a technical convention.

If the audit committee meets quarterly, monitor quarterly and deliver the pack in the week before papers go out — not the week after the meeting, which is the most common failure and renders the work invisible.

Monthly suits organizations with higher exposure, active remediation programmes, or a regulatory examination in prospect. Monthly does not mean a monthly board paper; it means the position is refreshed monthly so the quarterly paper is current rather than reconstructed.

Between cycles, one thing should be able to interrupt the rhythm: a material change — a significant incident, a major vendor event, a new AI deployment touching regulated data. Waiting six weeks to mention any of those defeats the purpose of monitoring.

Collect, assess, report, track — and again next period

10.  Start with the page you wish you had

The practical starting point is not a tool selection or a framework decision. It is to write, on one side of paper, the report the board wishes it received — the six elements above, filled in with today’s honest answers, including the gaps.

That draft will be uncomfortable. Several boxes will read “not known” or “not currently measured.” That is the finding, and it is the most valuable output of the exercise.

From there the work is ordinary: decide who supplies each input, decide who assembles and tests it, set the cadence to the governance calendar, and produce it again next period in exactly the same format. The second edition is where the value starts, because it is the first one with a trend.

The organizations that handle cyber and AI risk well over the next few years will not be distinguished by having bought better technology. They will be the ones whose boards could say, at any point, what the position was — and as of when.

Ten questions for your next board or audit committee meeting

  1. Can our current cyber and AI reporting be read in ten minutes by a non-technical director?
  2. Does every figure in it carry the date it was measured?
  3. Can we see the same measures for the previous three periods?
  4. How many control exceptions are open, and how old is the oldest?
  5. Is every open item owned by a named person with a target date?
  6. When an item is closed, who verified the fix — and was it the same person who made it?
  7. Which vendors changed materially this period, and how would we know?
  8. When were our incident response arrangements last exercised?
  9. Who prepares our cyber reporting — and do they also operate the controls?
  10. Does the pack reach us before the meeting or after it?

Frequently asked questions

What is the format of a continuous control monitoring engagement?

A monthly or quarterly managed advisory service, delivered through remote monitoring, interviews, document review, dashboard reporting and management meetings. The output is a recurring Cyber & AI Control Monitoring Report.

How is this different from a one-off assessment?

An assessment establishes the position on a date. Monitoring maintains it, tracks exceptions to closure, and produces a trend. The two work together — most organizations assess first and monitor after.

Do you need access to our systems?

Not necessarily. The service works largely from indicators, reports and documentation you already produce, supplemented by interviews. Where deeper access helps, it is scoped and agreed rather than assumed.

We already have a managed security provider. Does this duplicate them?

No, and the distinction matters. A managed security provider operates controls. This service reports independently on whether the control environment is working — including the parts your provider runs. The separation is what gives the reporting its standing.

Can it be aligned to our audit committee calendar?

Yes, and it should be. The cadence is set so the pack is available before papers go out, not after the meeting.

Who typically commissions this?

Boards, audit committees, chief risk officers, chief executives, and internal audit functions seeking standing coverage of an area they cannot resource full time.

Download the brochure

Dawgen Global’s Cybersecurity & AI Continuous Control Monitoring service covers seven monitoring areas — cyber risk, AI usage and exposure, vendor and third-party risk, access and identity, AI audit trails and evidence, incident response readiness, and executive dashboard reporting — and delivers a recurring control dashboard, an exception and remediation tracker, a vendor watchlist, and a board and audit committee reporting pack.

Download the service brochure for the full scope, deliverables and engagement format.

REQUEST A CONSULTATION

[email protected]   |   dawgen.global/contact-us

47 Trinidad Terrace, New Kingston, Jamaica   |   876-929-3670  |  876-665-5926  |  US 855-354-2447

About Dawgen Global

Dawgen Global is an independent, integrated multidisciplinary professional services firm headquartered at 47 Trinidad Terrace, New Kingston, Jamaica, serving more than 15 territories across the Caribbean. Founded and led by Dr. Dawkins Brown, Executive Chairman, the firm is independent and not affiliated with any international network. It delivers a full suite of professional services under one roof: audit and assurance; tax advisory; IT and digital transformation; risk management; cybersecurity; actuarial and insurance regulatory advisory; HR advisory; mergers and acquisitions; corporate recovery; business advisory and strategy; accounting BPO and virtual CFO services; and legal process outsourcing.

The proposition is simple: big-firm capability without the big-firm price. Dawgen Global’s integrated approach is built for the specific complexities and opportunities of the Caribbean market, helping organizations make sharper, better-informed decisions that drive measurable progress.

To explore a partnership, reach out:

by Dr Dawkins Brown

Dr. Dawkins Brown is the Executive Chairman of Dawgen Global , an integrated multidisciplinary professional service firm . Dr. Brown earned his Doctor of Philosophy (Ph.D.) in the field of Accounting, Finance and Management from Rushmore University. He has over Twenty three (23) years experience in the field of Audit, Accounting, Taxation, Finance and management . Starting his public accounting career in the audit department of a “big four” firm (Ernst & Young), and gaining experience in local and international audits, Dr. Brown rose quickly through the senior ranks and held the position of Senior consultant prior to establishing Dawgen.

https://www.dawgen.global/wp-content/uploads/2023/07/Foo-WLogo.png

Dawgen Global is an integrated multidisciplinary professional service firm in the Caribbean Region. We are integrated as one Regional firm and provide several professional services including: audit,accounting ,tax,IT,Risk, HR,Performance, M&A,corporate recovery and other advisory services

Where to find us?
https://www.dawgen.global/wp-content/uploads/2019/04/img-footer-map.png
Dawgen Social links
Taking seamless key performance indicators offline to maximise the long tail.
https://www.dawgen.global/wp-content/uploads/2023/07/Foo-WLogo.png

Dawgen Global is an integrated multidisciplinary professional service firm in the Caribbean Region. We are integrated as one Regional firm and provide several professional services including: audit,accounting ,tax,IT,Risk, HR,Performance, M&A,corporate recovery and other advisory services

Where to find us?
https://www.dawgen.global/wp-content/uploads/2019/04/img-footer-map.png
Dawgen Social links
Taking seamless key performance indicators offline to maximise the long tail.

© 2023 Copyright Dawgen Global. All rights reserved.

© 2024 Copyright Dawgen Global. All rights reserved.