Back to Blog

What the Board Actually Wants in Q4 Security Updates

Q4 is the audit committee's sign-off quarter, and the year has to close on a number. Here is how to build a dollar figure that survives a skeptical director's follow-up questions, which parts of the standard security deck quietly get cut before the meeting, and the two slides that actually get read.

Quick Answer

Q4 is the audit committee's sign-off quarter, and the year has to close on a number. Here is how to build a dollar figure that survives a skeptical director's follow-up questions, which parts of the standard security deck quietly get cut before the meeting, and the two slides that actually get read.

Willis (a WTW business) and Reed Smith LLP published their 2026 Global Directors' and Officers' Survey on September 17, 2026. For the first time in the survey's history, cyber attack risk overtook data loss as the #1 personal-liability concern named by directors themselves. 83% of North American respondents ranked cyber as very or extremely important, up from 76% and #2 the year before. Data loss dropped from #1 (77%) to #2 (81%). The rankings look small on paper. What they change about the Q4 board packet is not small.

Q4 2026 is the first quarterly reading cycle after that data landed, and the survey is one of four pressures that make Q4 specifically — not any other quarter — the moment the packet has to shift. The other three matter as much and are less visible.

The 2027 D&O renewal is being priced right now. Corporate D&O towers overwhelmingly renew January 1 or April 1, which means the D&O broker's questionnaire is being submitted through Q4. Every carrier writing 2027 D&O is pricing the tower against the specific cyber narrative in the packets the audit committee is reading this quarter. Directors know this. They are reading the Q4 cyber packet with the knowledge that their own personal-liability coverage is being tightened or loosened based on what the packet says about the company's cyber posture. That is a Q4-only pressure. It does not exist in Q3.

The 2027 board agenda gets set in the Q4 board meeting. Most public-company boards set the next year's annual agenda, committee memberships, and charter amendments at the Q4 board meeting or the first meeting of Q1. Cyber-oversight amendments to the audit-committee charter — the specific words that later govern who can be sued for which decisions — come up for a vote right now. Directors reading the Q4 packet are reading it while they are also voting on the charter language that will apply to the packet a year from now. Every claim on this quarter's packet lands against a board that is actively deciding how it wants to be liable for the next four quarters of them.

The plaintiffs' bar now has 24 months of 8-K Item 1.05 comparative filings. Reg S-K Item 106 has been in effect since December 2023. Q4 2026 is the first quarter where two full years of live 8-K filings exist, which means plaintiffs' complaints are increasingly built around the delta between what one company disclosed and what a peer disclosed for a comparable incident. Directors reading the Q4 packet are reading it aware that the SEC disclosure calculus their peers made in 2024 and 2025 is now the reference set their own decisions will be compared against.

Add those three to the Willis / Reed Smith survey landing and the reading lens has shifted, not shifted a little. What earns space on the packet changes when the reader has moved from underwriter to potential defendant — reading a document that is actively pricing their D&O coverage, actively setting the charter language they will be governed by, and actively feeding a comparative dataset the plaintiffs' bar now has.

83%
of directors now rank cyber attack risk as very or extremely important — up 7 points and now #1
Willis / Reed Smith 2026 Global D&O Survey, Sep 17
51%
specifically call out AI-generated errors and misinformation as a top D&O concern
Willis / Reed Smith 2026
4 days
SEC 8-K Item 1.05 disclosure window, now in its third full reporting year
SEC Reg S-K Item 106, effective Dec 2023

The reading lens has shifted, and the packet has to shift with it

In 2025, the audit committee read the cyber section for the same reason it read the finance section — to satisfy oversight obligations and confirm the company was not sitting on something material. In 2026, the audit committee is reading with a second question loaded in the background: if this risk goes wrong, does my name end up in a plaintiffs' complaint, and can I point at the evidence that I asked the right questions on the right date. Not because directors have suddenly become paranoid. Because Willis and Reed Smith just handed them a survey that says their peers are worried about exactly that.

The security team that writes the Q4 packet the same way it wrote the Q3 packet is going to lose ten minutes of the audit committee's time to questions the packet does not answer. The security team that recognizes the shift and adjusts the packet to it will not. The adjustment is not a rebuild. It is three specific additions.

Addition 1: Materiality separation the audit committee can point at

The SEC's four-business-day 8-K Item 1.05 clock only starts on a determination of materiality. That determination is a defensible act, not an automatic one. The Q4 packet has to name what did and did not get classified as material this quarter, and why. Two lines under each incident: "material because [criterion]" or "not material because [criterion]." The criterion is the language from the SEC's own final rule (33-11216) — magnitude, likelihood, mix of qualitative and quantitative factors.

The reason this matters more in Q4 than Q3: this is the third full year of live 8-K Item 1.05 filings. Plaintiffs' firms are now sitting on 24 months of comparative filings, which means their complaints are increasingly built around the delta between what a company disclosed and what a peer disclosed for a comparable incident. The audit committee wants to see the materiality reasoning on the page, so they can point at the reasoning if a comparable incident hits a peer in Q1 2027 and someone asks why the company did not file.

What this looks like on the page

A three-column materiality table. Column one, the incidents this quarter. Column two, the classification (material / not material / pending). Column three, the criterion — a phrase, not a paragraph. The audit committee reads the table in thirty seconds. The general counsel confirms the classifications with a nod. If a plaintiffs' bar subpoena arrives in 2028 asking why an incident was not disclosed, the general counsel points at row four of the Q4 2026 packet.

Addition 2: The CRQ number's methodology on the same slide as the number

Every cyber packet has a number. The number is an expected annual loss, a P90, a dollar exposure — whatever the security team's methodology produces. In 2025, the number was enough. In 2026, the number and the methodology have to share the slide, because directors read the survey and now know that "the security team gave us a number" is not a defense they can quote in a deposition. "The security team gave us a number produced by FAIR-style Monte Carlo aggregation over the following six loss scenarios, sourced from IBM Cost of a Data Breach 2026 for baseline severity and Verizon 2025 DBIR for third-party involvement rates" is a defense they can quote.

The methodology line does not have to be long. It has to be specific. Named framework (FAIR, Loss Distribution Approach, NIST 800-30 tailored). Named source for each input. Named vintage on each source. That is the citation the audit committee circles when the packet is read, because that is the citation their outside counsel will want to see when a shareholder demand letter references the packet in 2028.

Addition 3: An AI risk row broken out from cyber

The 2026 survey named the specific AI-related concerns directors are bringing to the boardroom. AI-generated errors and misinformation (51%). AI-enabled fraud and social engineering (40%). Weak governance and uncontrolled AI use (32%). Poor data quality and bias (26%). Those are not "cyber" concerns in the way a ransomware incident is a cyber concern. They live in a different loss scenario, they sit under a different control set, and the packet that folds them into the general cyber line loses the director's attention exactly where the director wants to see specificity.

The Q4 packet should carry a separate one-row summary for AI-related exposure. Named exposure category (agent-related decision errors, deepfake-driven wire fraud, model output leaking sensitive information into training corpora, sub-processor AI usage the DPA does not cover). Named control (approval scope, authority envelope, audit trail for autonomous actions, sub-processor register with AI-usage attestation). Named dollar exposure using the same methodology as the general CRQ number, with the same source discipline. One row. Directors who spent twenty minutes on the last earnings call defending AI usage will read that row first.

What the audit committee is not asking for

More content. The Q4 packet is not longer than the Q3 packet. It is more specific. Additions land against subtractions — the generic "threat landscape update" from Q3, the reheated Verizon DBIR macro slide, the cyber insurance renewal reminder that repeats every quarter. Directors reading with personal-liability lens do not want more. They want cleaner citation on what they are being asked to sign off on.

The two slides that survive intact

The one-page CRQ summary and the incident-versus-disclosure table survive. Everything else earns its place quarter to quarter. Threat intel makes the cut only if it changes the CRQ number this quarter. Tool inventory makes the cut only if a control gap is being remediated with named cost. The heatmap does not make the cut. Colors are opinions in a defensible-packet reading, and directors reading with personal-liability lens have been trained by their own outside counsel to distrust opinions dressed up as data.

What good looks like on the Q4 packet, in five lines

A well-run Q4 2026 packet fits on a single page and answers five questions in order:

  1. What is the number this quarter, sourced from where. Expected annual loss, P90, named methodology, cited inputs with vintage.
  2. What incidents happened, and which are material. Three-column table: incident, classification, criterion cited from Reg S-K Item 106.
  3. What moved the number, in dollars. Three lines of movement, each with a dollar magnitude and a control or exposure that changed.
  4. What the AI exposure row is this quarter. Named AI-specific exposure category, named control, dollar magnitude on the same methodology.
  5. What the board is being asked to approve. Zero, one, or two asks. Not three. The packet with three asks is a working session in disguise.

That is a packet a director can read in three minutes and defend in a deposition three years later. Every line on the page has a source. Every classification has a criterion. Every dollar has a methodology. Nothing on the page is a color.

Where vCISO Lite sits in this

We build the board packet as a repeatable artifact — a FAIR-style CRQ number with named-source discipline, a materiality determination log that survives an SEC subpoena, an AI exposure row broken out separately from general cyber, and an incident-versus-disclosure table the general counsel can defend line by line. Nothing about the Q4 board packet needs to be reinvented every quarter. What needs to be reinvented is the reading-lens the packet is designed for, and that has changed as of September 17, 2026. See quantify cyber risk in dollars for how the CRQ number gets built, and executive reporting for the packet format that survives an audit-committee reading with personal-liability lens loaded.

Where this matters next

Forward risk vs. backward risk: the board report that shows where you're headedthe directly-relevant companion on how forward-looking and backward-looking risk get separated in the board report. The specific framing directors ask about first when the CRQ number moves.PE Portco Security Governance: The Quarterly Board Packet the Fund Actually Needsthe PE-portco-specific quarterly board packet pattern. What changes when the audience is a fund partner sitting on the audit committee, not a public-company director.CFO Q4 Security Budgeting: What to Defend, What to Cutthe Q4 budget defense companion piece. What to defend at the audit committee, what to cut before the CFO does it for you, and the specific 2027 line items that survive scrutiny.The FAIR Model for Cyber Risk Quantification, Explainedthe FAIR methodology the "named methodology on the same slide as the number" section calls for. The specific loss-scenario decomposition and Monte Carlo aggregation that underwrites the CRQ number.Cyber Risk Quantification for Mid-Market: FAIR Without an Enterprise Risk Teamthe mid-market CRQ implementation companion. How the FAIR discipline applies at scales where the enterprise-CRQ tooling is overkill and the security team is ten people.What the SEC Requires for Cyber Disclosure in M&A: Item 1.05, Reg S-K Item 106, and the Deal Team's Playbookthe SEC 8-K disclosure companion piece. The specific materiality-determination question the plaintiffs' bar is now building 24-month comparative cases around.How to Quantify Cybersecurity Risk in Dollar Termsthe dollar-quantification pillar this piece's CRQ methodology section references. How the number is built, and how the methodology fits on the same slide as the number.
Share this article:

Ready to build your security program?

See how easy it can be.