Executive reporting
Answer the board question in one page.
Where are we, what changed since last time, and what needs a decision from you. Generated from the register the work already lives in — not assembled from four spreadsheets and a memory of what happened in April.
Self-service signup opens shortly — we will set you up in the meantime


Readiness moved from 68 to 76 since July. One critical risk is open, and the cyber insurance renewal is 96 days out.
Needs a decision
- Critical risk — ransomware via phishing on plant-floor workstations: approve the treatment or formally accept it with conditions.
- Two contracts expire inside 90 days: the shipping and EDI portal (20 October) and OT line-controller support (28 November).
- Finalise the Statement of Applicability before the Stage 1 readiness review on 20 October.
Screens captured from a Sentinel workspace on 10 September 2026. Northstar Manufacturing Ltd. is a fictional example — a 180-person manufacturer in Ontario, Canada — not a customer, and its scores are computed by the product from its records rather than typed in for the picture.
The brief
Four people at the same table, asking four questions.
Not for a control catalogue and not for a maturity model. They are trying to work out whether the organisation is exposed, whether it is getting better, and whether anything is waiting on them.
- Your chair
“How exposed are we, and what are we doing about it?”
A question a control list does not answer and a status update does not survive.
Deadline: the next meeting
- A director
“Did the money we approved last quarter do anything?”
Answerable only if last quarter’s report exists in the same shape as this one.
Deadline: this agenda item
- Your audit committee
“Which risks has management decided to accept?”
The slide most often missing, and the one that most often changes a budget decision.
Deadline: before the minutes
- Your CEO
“If our largest customer asked today, what would we send them?”
A question about evidence, arriving in the shape of a question about confidence.
Deadline: usually now
Contents
Seven things, and none of them is a control list.
Every figure is openable back to the control, the item, the risk or the action it came from, which is what makes the follow-up question in the meeting survivable.
The executive page, line by line
- 01
Readiness
One figure, in the product’s own “Expected” band, with the nine weighted categories behind it one click away.
- 02
Movement
Since the last snapshot: audit readiness up, compliance and risk management down — named, so the meeting starts with the decline rather than discovering it.
- 03
Critical risks
1 open in the example register, out of 7 open and 5 mitigated or accepted, each with a treatment and a name against it.
- 04
Decisions required
The items waiting on somebody in the room: a critical risk to approve or formally accept, two contracts expiring inside ninety days, a Statement of Applicability to sign.
- 05
Overdue and due
0 actions overdue, and what falls due this month — the restore test, the phishing simulation, the SoA — with owners.
- 06
Evidence position
41 of 46 items accepted; 1 expired, 1 missing. The line that stops a two-year-old penetration test going unnoticed for another quarter.
- 07
Insurance readiness
82% with 5 underwriter concerns, 96 days to the renewal on 15 December 2026.
The board does not need another control list.
A control list is the artefact of the people doing the work. A board is a different room with a different question, and handing it the working document is how a security update becomes forty slides that nobody can act on.
Where it comes from
Generated from the register, not written the night before.
The page is a view of the records your team maintains all quarter — controls and owners, evidence with dates, the risk register, action tracking. That is the entire trick, and it is why nobody reconciles a deck against a workspace at 11pm on a Sunday. A view cannot disagree with its source.
The narrative above the numbers can be drafted from the register; the person presenting it edits and owns it. How AI works in Sentinel

- Critical risk — ransomware via phishing on plant-floor workstations: approve the treatment or formally accept it with conditions.
- Two contracts expire inside 90 days: the shipping and EDI portal (20 October) and OT line-controller support (28 November).
- Finalise the Statement of Applicability before the Stage 1 readiness review on 20 October.
The Sentinel Score
One number, and all nine of its parts.
A single figure is genuinely useful to a board and genuinely dangerous if anybody mistakes it for a verdict. So here is the whole model: nine categories, the published weight on each, and the arithmetic that produces the figure on the dashboard.
| Category | Weight | Example |
|---|---|---|
| PoliciesActive policies covering mandatory security domains | 18% | 87 |
| Evidence ReadyEvidence accepted vs missing/expired | 18% | 79 |
| Risk MgmtOpen critical/high risks and aging | 14% | 73 |
| ComplianceTask completion rate and overdue items | 10% | 67 |
| Vendor RiskVendor assessments and evidence completeness | 10% | 74 |
| ContractsRenewals, expired contracts, risk level | 9% | 69 |
| TrainingSecurity awareness training coverage | 7% | 81 |
| Control TestingControl library, testing coverage, and open findings | 7% | 67 |
| Audit EngagementsAudit workspace readiness and control testing coverage | 7% | 70 |
| Weighted total | 100% | 76 |
- 0–49Below Expected
- 50–69Developing
- 70–84Expected
- 85–94Above Expected
- 95–100Leading
Sentinel supports readiness, governance, assessment, evidence organisation and control management. CyberWave does not certify compliance, issue audit opinions, guarantee compliance, or replace independent auditors, certification bodies or legal counsel. Framework references are informational readiness mappings.

Honestly
What a number like this is not.
Six assumptions a reasonable person makes about a security score, and what this one actually claims instead.
- A certification, or something close enough to one
- A rating an insurer or an auditor has blessed
- A benchmark against companies like yours
- Proof that a control actually operated on a Tuesday
- A figure that should only ever go up
- Something nobody in the room is able to question
- A readiness indicator derived from your own workspace, and nothing more
- Nobody outside your organisation has validated it, and the page says so
- Not a peer comparison — two organisations with the same figure can have entirely different scope
- It reflects what your register holds; whether a control operates is a question for testing
- It falls when the register gets more truthful, which is the honest quarter
- Nine published weights, openable to the record behind every point
Handing it over
Three recipients, three documents, one register.
A board pack, an auditor’s evidence request and a broker’s submission are three different documents drawn from the same records. The mistake is sending the same PDF to all three and hoping.
- Board and executive
- The one-page answer, the movement, the decisions outstanding, and a narrative somebody has signed.
- Audit-ready
- The audit engagement workspace organises requirements, control testing and the evidence each request maps to. It supports the engagement; it does not perform it.
- Broker-ready
- The insurance readiness workspace assembles the questionnaire answers alongside the evidence behind them — 82% ready in the example workspace, package In Progress.
Essentials carries the readiness score and an executive summary. Full Platform adds the full executive and board reporting layer, the audit engagement workspace and the broker and underwriter evidence packages — $249 per month.

Cyber Insurance Submission Pack
A reviewed, broker-ready evidence and questionnaire package assembled from your workspace.
$499 one-time
CyberWave helps you prepare for underwriting and security questions, organise evidence, identify possible gaps and plan remediation. CyberWave is not an insurer or an insurance broker, does not bind coverage, does not interpret policy coverage as legal advice, and does not guarantee coverage, premium reduction, claim payment or insurer acceptance. You remain responsible for complete and truthful representations to your insurer or broker.
Over time
One report is an anecdote. Four is a programme.
A single snapshot tells a board where you are, which they will forget. A line tells them whether the money they approved last quarter did anything, which they will not.

The report has the same shape every time it is produced, so two quarters are comparable — which sounds minor until you try to compare two decks written by different people in different months and find that even the domain names changed.
A dip is often honesty. Readiness frequently falls the first time an organisation takes evidence expiry seriously or brings a second framework into scope; that is the register becoming more truthful, and it is worth saying out loud in the meeting before somebody reads it as a failure. The boring cadence wins: a short report every month beats a heroic one before a renewal.
Questions
What executives ask about the reporting.
Including the one that decides whether the score is worth having: how, exactly, is the number calculated.
Can we show the Sentinel Score to an insurer, a customer or an auditor?
How is the number actually calculated?
Our score went down after a quarter of real work. Why?
Who writes the narrative at the top of the report?
How much of the board reporting comes with each plan?
Does any of this replace an audit?
Produce the next board pack from the register.
Bring the framework or the renewal that is closest, get the controls and evidence in, and let the report be a consequence of the work rather than a separate project.
Self-service signup opens shortly — we will set you up in the meantime
- Published pricing — no quote-on-request tier
- No credit card required for the trial
- No automatic charge when a trial ends
- Tenant-isolated architecture, data stored in Canada
- Clear data-processing terms
- No compliance guarantee — human judgement still required