1 of 7

[Q4 2022] Security Update�[YOUR COMPANY] Board of Directors

BY [YOUR NAME] [TITLE]

[DATE]

2 of 7

Risk�How Has Our Business Risk Changed Over The Past [Time Period]?

Top Risks To Our Business In 2023

  • Risk 1

Short description of risk

  • Risk 2

Short description of risk

  • Software Supply Chain Integrity

Controlling the source of 3rd party libraries via trusted repositories and compiling libraries from source remains a top priority to reduce the risk of supply chain attacks

Summary

  • [x%] Risk reduction over the past quarter based on completion of Center for Internet Security (CIS) Top 18 Controls
  • Projecting [x%] reduction in risk at the end of next quarter
  • Total risk reduction at end of year expected at [x%]

3 of 7

Security Governance & Controls�What Has Improved our Risk Posture?

Security Controls Implemented In Q4 2022

  • Control or Process 1

Outcome of implementing new control

  • Asset Inventory

Improved visibility via inventory of all network, storage, compute and endpoints on premises and in the cloud

  • Control or Process 3

Outcome of implementing new control

4 of 7

External Compliance�How Have We Improved In The Eyes Of Our Customers?

  • Completed [ISO27001/SOC1/SOC2/FedRAMP/HITRUST] in Q42022
  • Customer demand for [SOC1/SOC2/HITRUST] continues to be strong with [SOC2] as the most requested
  • 3rd Party External penetration test reports are showing a decrease in external vulnerabilities resulting in a moderate improvement to our external security posture.
  • Targeting completion of [FedRAMP/HITRUST] in 2023 based on customer demand
  • Compliance reports and audits were indirectly associated with [$] revenue in 2022

5 of 7

Security Operations�Security Operations & Incident Metrics

Resolution Time

Revenue Impact

Response Time

2022: 5 Hours

2023: 30 Min

2022: 48 Hours

2023: 10 Hours

2022: $5M

2023: $40M

6 of 7

2023 Look Ahead�What Are We Planning To Focus On In The Future?

Focus 1

Focus 2

Software Supply Chain

Lack of source control for 3rd party libraries and missing linkage of software repos to production applications

Risk 1

Risk 2

Software Supply Chain Integrity

Focus Area

Risk Area

7 of 7

Thank You