Templates

Two documents, and the fields that keep them alive.

A board report structure for the ten minutes you get on the agenda, and a risk register with the columns that make it maintainable. Both work in a spreadsheet and neither needs our software. Both are in preparation rather than published — so they are described here field by field, and each one names the page that covers the same ground today.

Self-service signup opens shortly — we will set you up in the meantime

Board summarySentinel interface, reproduced
Northstar Manufacturing Ltd. · September 2026

Readiness moved from 68 to 76 since July. One critical risk is open, and the cyber insurance renewal is 96 days out.

Needs a decision

  • Critical risk — ransomware via phishing on plant-floor workstations: approve the treatment or formally accept it with conditions.
  • Two contracts expire inside 90 days: the shipping and EDI portal (20 October) and OT line-controller support (28 November).
  • Finalise the Statement of Applicability before the Stage 1 readiness review on 20 October.

The board summary the report template is a manual version of — generated from the register, with every figure traceable to a record. Example workspace; Northstar Manufacturing Ltd. is fictional.

The templates

What will be in each, listed rather than summarised.

Neither is published yet. Setting them out in full anyway is the honest form of a coming-soon page: you can tell whether the document would answer your question, and a request tells us which to finish first.

  • template

    In preparation

    Board Cybersecurity Report Template

    A structure for reporting security to a board that has ten minutes: where we are, what moved since last time, what is overdue, and the decisions that need them.

    Who it helps

    Whoever presents security to a board or audit committee — frequently a CTO, COO or finance lead who is not a security specialist and gets one slot on the agenda.

    What it will contain

    • A first page that answers the only question the board asked: our readiness position, the movement since the last report, and the two or three items that need a decision from them.
    • A risk section that reports treatment decisions, owners and dates rather than a colour matrix nobody can act on.
    • Wording for reporting a gap to a board without either alarming them or burying it.
    • An incidents and near-misses section, with a note on what belongs in the minutes and what belongs in the appendix.
    • A page for what the programme has cost and what the next period needs, because that question follows every security update ever given.
    • A list of what to leave out: raw vulnerability counts, tool logos, and any figure you cannot trace back to a record.
  • template

    In preparation

    Cyber Risk Register Template

    A register with the fields that make it maintainable — owner, treatment decision, linked control, review date — and no column that exists only to look thorough.

    Who it helps

    A team that ran one risk workshop, produced a genuinely good document, and has not opened it since — and now needs it for a renewal, an audit or a board pack.

    What it will contain

    • The columns: risk description, the asset or process affected, current assessment, controls already in place, treatment decision, owner, target date and review date.
    • Worked entries for the risks most growing organisations actually carry, written the way a register entry should read rather than as a category.
    • The four treatment decisions, and how to record the one you chose — including accepting a risk deliberately, which is a decision and not an omission.
    • Scoring guidance that does not pretend a five-by-five grid is a measurement.
    • Why the review date is the field that decides whether this document is still alive in six months, and who has to see it when that date arrives.

Asking goes through the contact page and reaches a person. There is no download handler on this site and nothing here pretends to be one, and there is no marketing consent box to tick.

Why these fields

Most registers die of the same four omissions.

The difference between a register that is still true next quarter and one that is quietly fiction is not the scoring method, the colour scheme or the number of columns. It is these four — which is why both templates look sparser than the ones you may have seen.

  1. A person, not a team

    Owner has to be one name. “IT”, “Security” and “Management” are all ways of writing down that nobody is accountable. When a real name goes in the cell, somebody notices when the date passes — and both templates are built to make an empty owner visible rather than easy.

  2. The decision, written down

    A risk entry without a treatment decision is an observation. Reduce it, avoid it, share it or accept it — and if you accept it, record who accepted it and when. Deliberate acceptance is a perfectly respectable answer; an unrecorded one looks like an oversight a year later.

  3. A review date, and a reason to honour it

    This is the field that decides whether the document is alive in six months. A register with no review dates is a snapshot of one afternoon’s thinking. A register with review dates that nobody surfaces is the same thing with extra columns.

  4. Figures you can trace

    Every number in a board report should be openable. If the only source for “87% complete” is the person who typed it, one sceptical director costs you the whole meeting. The template prefers counts of specific things over a percentage nobody can audit.

If nobody would notice its absence for a quarter, it was never a register.

Every field in both templates exists to answer one question: will anybody open this when nothing is due? A document that fails that test was never a register — it was a record of having held a workshop.

Method

Five steps once it is in front of you.

In this order, because each step depends on the one before it: you cannot record a treatment decision for an entry nobody owns, and you cannot review a register that has no dates in it.

  1. 01

    Fill it in for the risks you actually have

    Not a generic list borrowed from a standard. Six to twelve entries that describe your own exposure — the supplier holding your customer data, the admin account three people share, the backup nobody has restored from — beats forty inherited categories.

  2. 02

    Put one name in every owner cell

    Do this before you refine any wording. An entry without an owner cannot progress, and finding out that four entries have no plausible owner is itself one of the more useful outputs of the exercise.

  3. 03

    Record the treatment decision you have actually made

    Including the uncomfortable ones. If you are living with something because closing it costs more than it is worth this year, write that down with the person who decided it. That is a defensible position; a blank cell is not.

  4. 04

    Set review dates you can defend

    Tie them to something real — the renewal, the quarter end, the contract review — rather than scattering dates evenly. A date that coincides with a meeting which already exists is a date that gets honoured.

  5. 05

    Report from it rather than rewriting it

    When the board pack is due, the report should be a view of the register, not a fresh document assembled from memory. The moment those two diverge you have two versions of the truth, and the board is reading the one nobody maintains.

The honest limit

A template has no way to tell you a date has passed.

Everything above is achievable in a spreadsheet, and plenty of organisations run a respectable register that way for a year or two. What a file cannot do is notice — that the control owner left in March, that the evidence behind entry seven expired, or that a figure in last quarter’s board report no longer matches anything.

  • The same columnsowner, treatment, rating as likelihood × severity, target date — the fields the template is built around
  • 7 open, 5 mitigatedin the example workspace, counted rather than described
  • One register, several audiencesa board, an underwriter, an auditor and a customer questionnaire — in files that becomes four documents that disagree

See risk and actions

Risk registerSentinel interface, reproduced
7
Open
1
Critical
2
High
4
Medium
0
Low
5
Mitigated
  • Ransomware via phishing on plant-floor engineering workstations
    Category
    Cyber
    Rating
    Critical4×5
    Status
    Open
    Owner
    Priya Raman
    Treatment
    Mitigate
    Target
    30 Nov 2026
  • Privileged accounts without PAM / shared local admin credentials
    Category
    Cyber
    Rating
    High3×4
    Status
    Open
    Owner
    Priya Raman
    Treatment
    Mitigate
    Target
    31 Oct 2026
  • Unpatched OT/SCADA vendor appliance (vendor-managed)
    Category
    Third-party
    Rating
    High3×4
    Status
    Open
    Owner
    Marc Lévesque
    Treatment
    Transfer
    Target
    15 Dec 2026
  • + 2 more in the workspace

Two ways to run it

Where the spreadsheet stops being the right tool.

Not a reason to buy anything this week. Run the template by hand for a quarter and this table will tell you which row you have started to resent.

Sentinel
Getting started
Same day, on a published price, with the register and the report already connected.
Ownership
A named owner on the control and the action, with the due date attached to them.
Review dates
Flagged in the evidence list — each item carries an expiry, so a lapsed one stands out.
Evidence
Attached to the control, with status and expiry on every item.
Board reporting
A view of the register, so every figure can be opened in front of the person asking.
Answering an insurer or a customer
Answered once and reused, from the same controls and the same evidence.
A spreadsheet register
Getting started
Immediate, free, and nobody has to approve it. This is a real advantage and the reason to start here.
Ownership
A name typed in a cell. Nothing tells that person the date arrived.
Review dates
Present, and dependent on somebody remembering the file exists.
Evidence
A folder somewhere else, linked by convention at best.
Board reporting
Rewritten each quarter from the register, from memory, the night before.
Answering an insurer or a customer
Answered from scratch each time, because neither exercise knows what the other proved.

The checklists tell you what to put in these

A register is easier to fill in after a readiness pass, because the gaps a checklist finds are the first entries worth recording. All three are described item by item on the guides page: Cyber Insurance Readiness Checklist, ISO 27001 Readiness Checklist, Security Questionnaire Checklist.

Straight answers

What a template does not settle.

A well-kept register and a clear board report make the conversations with your auditor, your broker and your directors much shorter. They do not decide the outcome of any of them, and it matters that the page says so.

Questions

Before you ask for one.

Six questions about the templates themselves — when they exist, what you may change, and what they will and will not stand up to.

Can I have one of these today?
Not yet — neither template is published, and this page says so instead of putting a download button in front of a contact form. Ask for the one you need and a person will tell you where it stands. If a board meeting or a renewal is close, the pages linked from each entry answer the same question now.
What will they be — a spreadsheet, a document?
Ordinary working documents, built so a small team can fill one in together and so nothing depends on our software. There is no self-serve download handler on this site, so nothing here will ever be presented as one.
Can we change them, or put our own logo on them?
Yes. They are starting shapes, not artefacts to preserve. Rename the columns to match the language your organisation already uses — a register people can read in their own vocabulary gets maintained, and one written in somebody else’s does not.
Is the board report template appropriate for an audit committee?
It works for both, with one adjustment: an audit committee usually wants the risk section and the overdue items in more detail, and a full board usually wants the first page and the decisions. The structure keeps those separable so you are not writing two documents.
Will a completed risk register satisfy an auditor or an insurer?
It is the right kind of artefact and far better than nothing. Whether it satisfies anyone depends on whether it is current, owned and evidenced — which is a question about how you maintain it, not about the template. Auditors and underwriters both notice a register whose review dates all passed a year ago.
Do we have to agree to marketing to get one?
No, and there is nothing to agree to right now: commercial email is on hold until we can send it to the Canadian standard properly, so there is no mailing list and no newsletter anywhere on this site. There is no marketing consent box on any page, because there is no programme to consent to.

Run the register by hand first.

Fill one in, work it for a quarter, and you will know exactly which parts you are tired of maintaining yourself. That is a far better reason to look at software than a feature list.

Book a walkthrough

Self-service signup opens shortly — we will set you up in the meantime

  • Published pricing — no quote-on-request tier
  • No credit card required for the trial
  • No automatic charge when a trial ends
  • Tenant-isolated architecture, data stored in Canada
  • Clear data-processing terms
  • No compliance guarantee — human judgement still required