Skip to content

cyber incident board notification

Cyber Incident Board Notices: What the Board Should Record When Management Reports an Incident

How a board keeps a dated record of the cybersecurity incidents management has told it about — date noticed, board-declared severity, follow-up due, closing date, and the briefing document — and how Prepared Board keeps that log today without acting as a detection product or breach-notification advice.

~8 minutes· Informational / How-to· Updated 2026-10-06· Markdown for your agent

Cyber Incident Board Notices: What the Board Should Record When Management Reports an Incident

Target keyword: cyber incident board notification
Intent: Informational / How-to
Last updated: 2026-10-06
Reading time: ~8 minutes


Who this guide is for

Chairs, audit and risk committee members, board secretaries, and investor directors who need to answer one question with evidence: "Which cyber incidents was the board told about, when, and what did the board ask for next?"

This is practice guidance, not legal advice. Whether an incident triggers a duty to notify regulators, customers, or investors depends on your industry, the data involved, contracts, and (for public companies) securities disclosure rules. Those calls belong to management, outside counsel, and incident-response advisors. A board's notice log is a record of what the board was told and what it asked for, not a determination of anyone's legal obligations. The duty of oversight hub explains why boards keep this kind of record.


What a board notice log is (and is not)

Management and the security team run incident response: detection, containment, forensics, and any required notifications. The board needs something much smaller: a dated line for each incident management brought to it, so the record shows the board heard about it and followed up.

A board notice log does three things:

  1. Shows the board was informed. A dated entry with the briefing attached is what directors point to later when someone asks "when did the board know?"
  2. Keeps follow-ups from drifting. A follow-up date the board set ("report back on root cause by the 15th") becomes something anyone can see has passed.
  3. Separates open from closed. Closed incidents stay in the record with their closing date instead of disappearing from the agenda and from memory.

It is not a security operations tool, not a substitute for the incident-response plan, and not a log of every alert. Severity is the label the board chose after the briefing, not a technical score.


What to record for each notice

  1. The date the board was notified. Not the date the incident started — the date the chair or management told the board. Those can be weeks apart, and the gap is itself worth knowing.
  2. A short, factual title. "Third-party SaaS credential exposure" is enough. Keep personal data and attacker details out of the board log; they belong in the incident file.
  3. A severity label the board agrees on. Low / Medium / High / Critical. Write down that it is the board's judgment, so no one mistakes it for a CVSS rating or a regulator's classification.
  4. The briefing document. The incident memo or tabletop report the board actually saw, so the record shows what was in front of directors.
  5. A follow-up due date, if the board asked for one. Root cause, remediation status, insurer notice, counsel's view on notification. A board-set date is a reminder, not a legal deadline.
  6. A closing date. When management reports the incident closed and the board accepts that, record the date and keep the entry.

What audit committees and investors look for

QuestionWhat the log should show
What has the board been told about this year?Every notice with its date noticed, open or closed
Is anything still open?Open notices, each with a follow-up date where the board asked for one
Has a follow-up slipped?Open notices whose board-declared follow-up date has passed
What did the board see?A linked briefing document per notice where one exists
Do directors know the policy?A current information security policy acknowledgment for each director

Two mistakes come up again and again: incidents discussed in executive session with nothing written down, and follow-up requests that live only in someone's notes until the next meeting. If the incident might become serious, ask counsel how to handle privilege before writing detail into the board record.


How Prepared Board handles this today

Cyber incident board-notice log. /app/cyber-incident-notices is a dated log of cybersecurity incidents the chair or management has notified the board about. Each notice has a board-declared severity label, date noticed, short title, optional same-board Document, optional closed date, and optional board-declared follow-up due. Severity shows as "High (board-declared)", "Critical (board-declared)", and so on. Chair, Admin, or Owner enables the log in Settings; Chair, Secretary, Admin, or Owner adds and edits; directors, the CEO, the CFO, and advisors can read it. Saving confirms "Notice added (board-declared — not a detection product)." Copy for your agent copies the log as markdown.

Board Go cue. When an open notice is past its board-declared follow-up date, Board Go on the board home shows a soft cue — "Open cyber incident notice past board-declared follow-up" (or the count when there are several) — linking to the log. Nothing is blocked.

Risk radar. /app/risk-radar lists every open notice under "Open cyber incident notices" as an inside signal, with the date the board was notified, the board-declared label, and the follow-up date, linked to the log. Chair, Secretary, Admin, or Owner record the board's choice per item: Added to risk register, Discuss next meeting, Watch, or Not relevant (with a required reason). Choosing the register is how a notice becomes a risk the board oversees over time — see the board risk register guide.

Policy acknowledgment. /app/info-security-policy tracks each director's annual "Information security / cybersecurity acknowledgment" of the board-filed policy (an in-app acknowledgment, not eSign).

Where it shows up. A notice strip appears on board proof and in the diligence snapshot. Investor directors and sponsors see "Cybersecurity incident board notices across your boards" on /app/portfolio: open and closed counts, open notices past their follow-up date, and open notices the board labeled High or Critical — only for boards where they hold an ACTIVE membership and their role can open that board's log. Copy cyber incident notice status for your agent copies those counts.

Honest limits:

  • Board-declared notices only. Not a detection product, not MDR, and not legal breach-notification advice. Prepared Board does not scan systems.
  • No regulator contact and no notification determination. Prepared Board does not contact regulators and does not decide whether a notice triggers a statutory duty.
  • No cyber score. Severity and follow-up dates are set by the board; Prepared Board does not compute a cyber score or rank boards against each other.
  • A passed follow-up date is a soft cue, not a finding. It means the board's own date passed — not that anyone missed a legal deadline.
  • No outreach. Nothing is emailed to management or directors; reminders are what you see in the app. Nothing is sent.
  • No certification claim.

Check every product claim on this page against Facts or the machine-readable /agent-facts.json.


Try it: Northlight Robotics

Northlight Robotics is a seeded venture-backed demo board (not a real company). Incidents and names below are demo data; the shared demo password is an evaluation login, not SSO.

Sign ina sample board (see /sample-decision) / password123 (Elena Voss, chair), or pick Northlight at Try a board
Open/app/cyber-incident-notices
See"Third-party SaaS credential exposure (open)" — High (board-declared), noticed Sep 28, 2026, follow-up due Oct 1, 2026, now past, so Board Go shows the follow-up cue. "Vendor email phishing campaign (contained)" — Medium (board-declared), noticed Mar 12, 2026, closed Apr 2, 2026, kept as history. Each links its briefing document
Then open/app/risk-radar
SeeThe open SaaS credential notice listed under open cyber incident notices, beside overdue actions and other inside signals
Also/app/info-security-policy — the Northlight Robotics Information Security / Cybersecurity Policy acknowledgment tracker
Pack (public)/pack/demo-pack-northlight-q4

Board-type guides

Related guides


Conclusion

A board notice log earns its keep when every incident management reported has a date, a board-agreed label, the briefing behind it, and a follow-up the board can see slipping before the next meeting. Sign in as the Northlight chair to see an open credential-exposure notice past its follow-up date, and verify every claim on Facts.

Try a board → Northlight

Prepared Board is a board decision operating system — agendas, packs, decisions, and audit trails in one place — so fiduciary process is easier than the workaround. Verify product claims on Facts.

Learn about Prepared Board →

See it on a real record

Prepared is in an invite-only beta. See what a finished decision record looks like, or request a pilot for your board.

Cite this page: Prepared Board, "Cyber Incident Board Notices: What the Board Should Record When Management Reports an Incident," https://preparedboard.com/guides/cyber-incident-board-notices (updated 2026-10-06). Anchor: #cite-this. Product claims are verified on /facts.