Modernization governance / August 2026
Reporting resilience to the board after an outage
A post-incident review explains one outage to the people who lived through it. A board needs to know whether the organization is improving, and that answer requires the same report shape every time, scored, and read a second time ninety days later. The governance change that matters most is who presents it and how often.
The Wrong Document
A narrative answers what happened. The board asked something else.
After a serious outage the technology function almost always brings the board a post-incident review. It names a cause, steps through the timeline, and sets out the fixes engineering has already made. For the people who were in the room, that is the right document. For a board it fails. Several read over a few years will not show whether resilience is improving, flat, or getting worse, because no two use the same structure.
There is a second gap. The discipline most organizations built around security incidents, pairing a named owner with a scored severity and a dated remediation plan, is usually reserved for events involving an attacker. That boundary does not match how boards think. A supplier fault can take a business offline for a week without meeting any regulatory definition of a breach, and the board will still want the same evidence trail.
The regulatory clock reinforces the point. Under the Securities and Exchange Commission's cybersecurity disclosure rule, a public company has four business days from determining that a cybersecurity incident is material to decide whether to report it. A supplier fault may never start that clock. Boards ask for the same speed and the same evidence anyway, which tells you the expectation now runs ahead of what any single regulation requires.
The Trigger
Agree what qualifies before the next incident, not after it.
Define the trigger narrowly enough to keep the report usable and widely enough that no awkward incident can be excluded. Two thresholds work well. A duration of customer-facing disruption and an unplanned cost estimate, whichever is crossed first. The risk committee should set both in advance, in writing, with no exemption for an outage a business unit would prefer not to raise.
Setting the threshold beforehand removes an argument that otherwise happens at the worst possible time, with the people deciding whether an incident qualifies being the people who would present it.
The Format
The same four sections, in the same order, every time.
The order is part of the instrument. Changing it between incidents makes the reports incomparable.
Read the timeline against the Recovery Time Objective and Recovery Point Objective already agreed for that system, because what a board wants to know is whether the RTO and RPO on file survived a real failure.
- Timeline and detection window. When the fault entered the environment, the moment monitoring or a customer first saw it, and the interval between those two points. That interval is the number that improves or does not.
- Cause and blast radius. What failed, how many systems, users or revenue-producing transactions were affected, and whether exposure stayed inside one supplier, region or business unit.
- Control failures and compensating actions. Which safeguard already in place ought to have caught this, and what kept the damage smaller than it might have been. This section is where candour is hardest and most valuable.
- Forward-looking commitments. Specific, dated changes with a named owner. Not general assurances that lessons were learned.
- Supplier concentration exposure. A fifth section, added whenever a supplier runs underneath more than one business-critical system.
A supplier account of a failure typically covers what happened and the fix applied. It does not address whether your own safeguards should have caught it. That analysis has to happen inside your environment, and it is the board's business.
The Score
Score it, then score it again at ninety days.
A format produces comparable evidence only when it is scored. Weight the sections on a fixed scale and publish the weights, with the most weight on cause and blast radius, the section left vaguest in a first draft. Severity then becomes a number tracked across quarters instead of an adjective.
The score matters less than the fact that it is produced twice. Once shortly after the incident. Again ninety days on, at which point the committed changes have either been completed or they have not. Publishing only the first score leaves most post-incident reporting without consequence. Publishing both gives the format weight.
The vocabulary for this is already published. The National Institute of Standards and Technology updated its Cybersecurity Framework to version 2.0 in February 2024. It added a sixth function, Govern, for board-level oversight of risk decisions, alongside the original five: identify, protect, detect, respond, recover. Adoption is voluntary, and Govern is nonetheless the language several risk committees now reach for when they describe what belongs in a board-facing report.
Concentration
Two supplier questions most organizations cannot answer with a number.
Large simultaneous outages are usually a story about concentration before they are a story about one defect. When a single supplier update reaches a meaningful share of an estate at once, that is a description of market structure. A standard application inventory will not surface it, because the supplier in question is the layer running underneath every application.
Ask two questions in this section, and require numeric answers. First, if this supplier pushed a faulty update tonight, how many production systems would be hit inside the hour, before any of our people could step in. Second, have we tested a way to reverse or bypass such an update on our own. Most organizations we review cannot answer either one, and that finding belongs inside the resilience report and not in a separate supplier risk binder.
A regional utility had four years of post-incident reviews and no way to compare any two of them. We set the qualifying thresholds with the risk committee, fixed the section order, and required a score produced twice for every incident. The ninety-day re-score exposed a set of commitments nobody had finished, and closing them produced a 27 percent cost benefit measured against the prior year of unplanned downtime.
Governance
Change who presents it and how often, or the format becomes a checkbox.
One function should own the report end to end and brief the board directly, instead of the finding being filtered through whichever team comes out of the story best. We recommend that the chief information security officer, or whoever owns risk in the equivalent role, presents the scored report. The business unit that owned the failed system attends to answer questions, not to present. Separating those two roles improves the candour of what a board hears, because neither can then soften the numbers of the other unnoticed.
Give the report a cadence independent of whether anything qualified. Put it in a fixed quarterly place on the risk committee agenda and present it even in an empty quarter. A committee shown this report only after a bad quarter will read it as a confession. A committee shown it every quarter reads it as a measuring device.
What To Do Next
Five steps to put the format into standing use.
- 1. Set the qualifying thresholds with the risk committee now, in writing, with no exemptions available later.
- 2. Adopt the four required sections in fixed order for every incident that qualifies from now on, and not only for the next large one.
- 3. Publish the weighting so severity becomes a tracked number and not an adjective.
- 4. Re-score every incident at ninety days, confirm the commitments were completed, and report both scores together.
- 5. Give one owner responsibility for briefing the board directly, with the business unit that ran the failed system in the room to answer.
The organizations that look prepared after the next widescale outage will not be the ones with the strongest single review. They will be the ones able to put six quarters of the same report in front of a board and point at a line moving the right way.
Related Service
Modernization and Transformation Governance
We set the reporting instrument, then sit with the risk committee until it reads the numbers without us.
Start A Conversation