Cyber Incident Board Notices: What the Board Should Record When Management Reports an Incident
Target keyword: cyber incident board notification
Intent: Informational / How-to
Last updated: 2026-10-06
Reading time: ~8 minutes
Who this guide is for
Chairs, audit and risk committee members, board secretaries, and investor directors who need to answer one question with evidence: "Which cyber incidents was the board told about, when, and what did the board ask for next?"
This is practice guidance, not legal advice. Whether an incident triggers a duty to notify regulators, customers, or investors depends on your industry, the data involved, contracts, and (for public companies) securities disclosure rules. Those calls belong to management, outside counsel, and incident-response advisors. A board's notice log is a record of what the board was told and what it asked for, not a determination of anyone's legal obligations. The duty of oversight hub explains why boards keep this kind of record.
What a board notice log is (and is not)
Management and the security team run incident response: detection, containment, forensics, and any required notifications. The board needs something much smaller: a dated line for each incident management brought to it, so the record shows the board heard about it and followed up.
A board notice log does three things:
- Shows the board was informed. A dated entry with the briefing attached is what directors point to later when someone asks "when did the board know?"
- Keeps follow-ups from drifting. A follow-up date the board set ("report back on root cause by the 15th") becomes something anyone can see has passed.
- Separates open from closed. Closed incidents stay in the record with their closing date instead of disappearing from the agenda and from memory.
It is not a security operations tool, not a substitute for the incident-response plan, and not a log of every alert. Severity is the label the board chose after the briefing, not a technical score.
What to record for each notice
- The date the board was notified. Not the date the incident started — the date the chair or management told the board. Those can be weeks apart, and the gap is itself worth knowing.
- A short, factual title. "Third-party SaaS credential exposure" is enough. Keep personal data and attacker details out of the board log; they belong in the incident file.
- A severity label the board agrees on. Low / Medium / High / Critical. Write down that it is the board's judgment, so no one mistakes it for a CVSS rating or a regulator's classification.
- The briefing document. The incident memo or tabletop report the board actually saw, so the record shows what was in front of directors.
- A follow-up due date, if the board asked for one. Root cause, remediation status, insurer notice, counsel's view on notification. A board-set date is a reminder, not a legal deadline.
- A closing date. When management reports the incident closed and the board accepts that, record the date and keep the entry.
What audit committees and investors look for
| Question | What the log should show |
|---|---|
| What has the board been told about this year? | Every notice with its date noticed, open or closed |
| Is anything still open? | Open notices, each with a follow-up date where the board asked for one |
| Has a follow-up slipped? | Open notices whose board-declared follow-up date has passed |
| What did the board see? | A linked briefing document per notice where one exists |
| Do directors know the policy? | A current information security policy acknowledgment for each director |
Two mistakes come up again and again: incidents discussed in executive session with nothing written down, and follow-up requests that live only in someone's notes until the next meeting. If the incident might become serious, ask counsel how to handle privilege before writing detail into the board record.
How Prepared Board handles this today
Cyber incident board-notice log. /app/cyber-incident-notices is a dated log of cybersecurity incidents the chair or management has notified the board about. Each notice has a board-declared severity label, date noticed, short title, optional same-board Document, optional closed date, and optional board-declared follow-up due. Severity shows as "High (board-declared)", "Critical (board-declared)", and so on. Chair, Admin, or Owner enables the log in Settings; Chair, Secretary, Admin, or Owner adds and edits; directors, the CEO, the CFO, and advisors can read it. Saving confirms "Notice added (board-declared — not a detection product)." Copy for your agent copies the log as markdown.
Board Go cue. When an open notice is past its board-declared follow-up date, Board Go on the board home shows a soft cue — "Open cyber incident notice past board-declared follow-up" (or the count when there are several) — linking to the log. Nothing is blocked.
Risk radar. /app/risk-radar lists every open notice under "Open cyber incident notices" as an inside signal, with the date the board was notified, the board-declared label, and the follow-up date, linked to the log. Chair, Secretary, Admin, or Owner record the board's choice per item: Added to risk register, Discuss next meeting, Watch, or Not relevant (with a required reason). Choosing the register is how a notice becomes a risk the board oversees over time — see the board risk register guide.
Policy acknowledgment. /app/info-security-policy tracks each director's annual "Information security / cybersecurity acknowledgment" of the board-filed policy (an in-app acknowledgment, not eSign).
Where it shows up. A notice strip appears on board proof and in the diligence snapshot. Investor directors and sponsors see "Cybersecurity incident board notices across your boards" on /app/portfolio: open and closed counts, open notices past their follow-up date, and open notices the board labeled High or Critical — only for boards where they hold an ACTIVE membership and their role can open that board's log. Copy cyber incident notice status for your agent copies those counts.
Honest limits:
- Board-declared notices only. Not a detection product, not MDR, and not legal breach-notification advice. Prepared Board does not scan systems.
- No regulator contact and no notification determination. Prepared Board does not contact regulators and does not decide whether a notice triggers a statutory duty.
- No cyber score. Severity and follow-up dates are set by the board; Prepared Board does not compute a cyber score or rank boards against each other.
- A passed follow-up date is a soft cue, not a finding. It means the board's own date passed — not that anyone missed a legal deadline.
- No outreach. Nothing is emailed to management or directors; reminders are what you see in the app. Nothing is sent.
- No certification claim.
Check every product claim on this page against Facts or the machine-readable /agent-facts.json.
Try it: Northlight Robotics
Northlight Robotics is a seeded venture-backed demo board (not a real company). Incidents and names below are demo data; the shared demo password is an evaluation login, not SSO.
| Sign in | a sample board (see /sample-decision) / password123 (Elena Voss, chair), or pick Northlight at Try a board |
| Open | /app/cyber-incident-notices |
| See | "Third-party SaaS credential exposure (open)" — High (board-declared), noticed Sep 28, 2026, follow-up due Oct 1, 2026, now past, so Board Go shows the follow-up cue. "Vendor email phishing campaign (contained)" — Medium (board-declared), noticed Mar 12, 2026, closed Apr 2, 2026, kept as history. Each links its briefing document |
| Then open | /app/risk-radar |
| See | The open SaaS credential notice listed under open cyber incident notices, beside overdue actions and other inside signals |
| Also | /app/info-security-policy — the Northlight Robotics Information Security / Cybersecurity Policy acknowledgment tracker |
| Pack (public) | /pack/demo-pack-northlight-q4 |
Board-type guides
Related guides
- Board Risk Register
- Board Committee Charters
- Annual Board Policy Acknowledgments
- Director Indemnification and D&O Insurance
Conclusion
A board notice log earns its keep when every incident management reported has a date, a board-agreed label, the briefing behind it, and a follow-up the board can see slipping before the next meeting. Sign in as the Northlight chair to see an open credential-exposure notice past its follow-up date, and verify every claim on Facts.