The Template Pack · free

The CISO Board Deck Template

Every slide specified to build-ready detail: exact titles, layouts, fill-in skeletons, a worked example, speaker notes, and the trap on each slide.

Free, no paywall · part of the CISO Interview Template Pack

Part of the CISO Interview Template Pack · cisoprep.com


How to use this document

Rebuild this in Google Slides or PowerPoint: 16:9, one idea per slide, your numbers in the [brackets]. Ten core slides plus a five-slide appendix. Ten minutes presented, rehearsed down to eight, because you will be interrupted.

About the example. Every filled example uses Meridian Health, an illustrative mid-cap healthcare SaaS company invented for this template. It does not exist; every number is made up. Do not copy its numbers; copy its specificity. The setup: patient scheduling and billing SaaS for hospital systems, HIPAA-regulated, pursuing HITRUST, one disclosed incident two years ago, new CISO at their second audit committee meeting.


Slide 1: Executive summary

On-slide title: Security Posture and Priorities: [Quarter, Year]

Layout: No charts. Three bands: posture sentence in large type, three risk rows (name, status color, trend arrow), the ask in a box at the bottom.

Skeleton:

  • Posture: [One honest sentence on where the program stands against the risks that matter.]
  • Risks: [Risk 1: status, direction] / [Risk 2: status, direction] / [Risk 3: status, direction]
  • Ask: [Decision or dollar amount, or "No ask this quarter," stated explicitly either way.]

Example (Meridian Health, illustrative):

  • Posture: "Resilient against commodity attacks, materially exposed to a ransomware event in the production platform, on plan against last quarter's commitments."
  • Risks: Ransomware in production (red, improving) / Third-party data exposure (amber, flat) / Privileged access sprawl (amber, improving)
  • Ask: $1.8M over two quarters to close the privileged access gap. Detail on slide 9.

Speaker notes: "This slide is the whole story; the next nine are the reasoning. Posture, the three risks I manage you through, and the one decision I need."

Trap: A posture sentence that cannot be falsified ("we continue to mature our program"). If it would survive a breach unedited, it says nothing, and skimming directors read only this slide.


Slide 2: Business context

On-slide title: What Security Protects at [Company]

Layout: Three columns, one per revenue or value stream: how the money is made, the systems and data it depends on, what a bad security year does to it. No security terminology anywhere.

Skeleton:

  • Stream 1: [How it earns] → depends on [systems/data] → a bad year means [business consequence]
  • Streams 2 and 3: [same structure]

Example (Meridian Health, illustrative):

  • Subscription revenue → platform uptime and PHI integrity → a multi-day outage triggers SLA credits and termination rights in the top 20 accounts.
  • New bookings → security questionnaires and HITRUST progress → a disclosed incident freezes the pipeline for two quarters, as it did in [year].
  • Renewals → customer trust and audit posture → aged findings surface in customer audits first.

Speaker notes: "Before threats, here is what I believe security exists to protect here, in your terms. If this slide is wrong, I want to know now." Then pause and genuinely invite correction.

Trap: Filling it with your world instead of theirs. A maturity wheel or the word "NIST" on slide 2 says you serve a methodology. This is the credibility slide; it works only if a director could have written it.


Slide 3: The risks that matter

On-slide title: The Three Risks That Matter Most, and Why

Layout: Three boxes: risk name in plain English, business impact in one sentence tied to a slide-2 stream, likelihood in words, why it made the top three. One footer line on what you excluded.

Skeleton:

  • Risk 1: [Plain-English name]. Impact: [effect on which stream]. Why top-three: [reasoning].
  • Risks 2 and 3: [same structure]
  • Footer: [What you deliberately left off, in one sentence.]

Example (Meridian Health, illustrative):

  • Ransomware in the production platform. Impact: multi-day outage across all hospital customers, SLA and termination exposure. Why: production recovery untested at full scale.
  • Third-party data exposure. Impact: PHI breach via one of 340 vendors, notification obligations landing on us. Why: 60 vendors touch PHI; a third never reassessed.
  • Privileged access sprawl. Impact: one compromised admin account reaches production and the warehouse. Why: it amplifies both risks above.
  • Footer: "Deliberately not listed: insider threat and DDoS. I can defend both omissions."

Speaker notes: "Fiduciary duty attaches to material risk, so your oversight attaches to this slide. These are three of forty-plus on the register (appendix 3); my job is the ranking."

Trap: Listing more than four risks. Five is a catalog, not a judgment. The exclusion footer is what proves ranking happened.


Slide 4: Current posture

On-slide title: Where We Stand Against Those Risks

Layout: A three-row table, one row per slide-3 risk. Columns: in place, not in place, residual risk in business terms. One color chip per row; at least one row should not be green.

Skeleton:

  • [Risk 1]: In place: [controls, tested when]. Not in place: [the gap]. Residual: [what could still happen].
  • [Rows 2 and 3: same structure]

Example (Meridian Health, illustrative):

  • Ransomware: EDR at 96% coverage, immutable database backups, March tabletop. Gap: full-scale restore never executed. Residual: recovery time is an estimate, not a fact. Amber.
  • Third-party: assessments at onboarding for PHI vendors. Gap: 34% past reassessment due date. Residual: a vendor breach we learn about from the vendor. Amber.
  • Privileged access: MFA everywhere, vault for domain admins. Gap: 40% of production admin accounts are standing, not just-in-time. Residual: one phished engineer is a platform-level event. Red, improving.

Speaker notes: "I want to be precise about deployed versus proven. Two rows contain gaps, and I would rather you hear them from me with a plan than from an auditor without one."

Trap: A wall of green. Boards distrust all-green posture slides and audit chairs hunt for the contradiction with the audit trail. Honesty here is what makes slides 5 through 9 believable.


Slide 5: What changed

On-slide title: Since We Last Met: Better, Worse, New

Layout: Three labeled rows: one improvement, one degradation, one new item. Each: what changed, why, what you are doing about it. Resist adding a fourth improvement.

Skeleton:

  • Better: [What improved, evidence, which risk it moves]
  • Worse: [What degraded, why, owner and date for the fix]
  • New: [New risk, obligation, or threat pattern]

Example (Meridian Health, illustrative):

  • Better: standing production admin accounts down from 210 to 126 since January.
  • Worse: vendor reassessment backlog grew from 20% to 34% past due; the covering analyst left in April. Backfill starts July 1; under 10% by Q4. Owner: me.
  • New: two large customers added AI features to contracts; the platform starts processing model training data under new obligations in Q3. Assessment underway.

Speaker notes: "You see us four times a year, so trajectory matters more than any snapshot. One better, one worse, one new, and I will report the degradation before anyone else finds it."

Trap: Reporting only improvements. Nobody's quarter contains only improvements and directors know it; a self-reported degradation with a dated fix builds more trust than ten green arrows.


Slide 6: Incident readiness

On-slide title: When It Happens: Detection, Response, Recovery

Layout: One horizontal timeline (detect → contain → recover) with current numbers under each phase, each labeled tested or estimated. Small box: date and scope of the last real exercise, plus the weakest link.

Skeleton:

  • Detect: [time, evidence] / Contain: [time, tested when] / Recover: [expectation for crown-jewel systems: tested or estimated, say which]
  • Last exercised: [date, scenario, participants]
  • Weakest link: [the one thing you trust least]

Example (Meridian Health, illustrative):

  • Detect: median 41 minutes for endpoint threats in the last two live incidents; platform-level detection unproven. Contain: 4 hours in the March tabletop. Recover: databases in a verified 6 hours; full application stack an estimate of 2-3 days, never executed.
  • Last exercised: March 12, ransomware tabletop, engineering and legal present, no executives.
  • Weakest link: full-stack recovery. On the roadmap.

Speaker notes: "The question you actually carry is not whether an incident happens but whether we handle it well. Here is what is tested versus asserted; the estimated number is why the recovery exercise is on the next slide."

Trap: Presenting untested numbers as capabilities. "We can recover in 24 hours" is an assertion until you have done it, and being caught inflating one number poisons the rest of the deck.


Slide 7: Roadmap

On-slide title: The Next Four Quarters, Mapped to Risk

Layout: A table, not a Gantt chart. Maximum six rows: initiative, which slide-3 risk it reduces, what "done" changes, quarter, status.

Skeleton:

  • [Initiative] → reduces [named risk] → done means [observable change] → [quarter] → [status]
  • [Any initiative mapping to no named risk gets cut, or the risk list was wrong.]

Example (Meridian Health, illustrative):

  • Just-in-time production admin access → privileged access → standing admins under 25 → Q3-Q4 → funding requested (slide 9)
  • Full-stack recovery exercise → ransomware → recovery time becomes a tested fact → Q3 → on track
  • Vendor reassessment automation → third-party → past-due under 10%, sustained → Q4 → hiring dependent
  • HITRUST certification → all three, plus bookings → certification in hand → Q1 next year → on track

Speaker notes: "Every row maps to a risk you have already seen; rows that did not were cut. The first row needs your decision today, which is the next slide."

Trap: The wish list: initiatives justified by "maturity" or "best practice" rather than a named risk. The mapping column is the whole slide, and it is your budget defense in cost-cutting season.


Slide 8: Peer and benchmark context

On-slide title: How We Compare

Layout: One simple bar or dot chart: your framework score against sector benchmark, by domain. One honest sentence below on where you lag.

Skeleton:

  • [Framework], assessed [when, by whom]. At or above peers: [domains]. Behind: [domains, and which roadmap rows target them]. Source: [assessor, insurer, or rating-service data].

Example (Meridian Health, illustrative):

  • NIST CSF, external assessor, April. At or above healthcare SaaS peer median in identity, detection, response. Behind in third-party risk and recovery, which are roadmap rows 2 and 3. Sources: assessor portfolio data and our insurer's underwriting review.

Speaker notes: "You would ask anyway, so here it is with structure: above peers in three domains, behind in two, and the roadmap targets those two. Full assessment in appendix 2."

Trap: Waiting to be asked. Directors calibrate across the other boards they sit on; answering preemptively reads as senior, and "it's hard to compare" reads as evasion regardless of how true it is.


Slide 9: The ask

On-slide title: The Decision I Need Today

Layout: One box, large type: the ask in one sentence, what it buys in risk terms, the consequence of declining, stated without drama. If there is no ask, the slide exists and says so.

Skeleton:

  • Ask: [$ or decision], for [specific gap], over [timeframe]
  • Buys: [named risk] moves from [state] to [state] by [date]
  • If declined: [risk stays where it is, in business terms, and when you will re-raise it]

Example (Meridian Health, illustrative):

  • Ask: $1.8M over Q3-Q4 for just-in-time privileged access: licensing, one contract engineer, 20% of two platform engineers.
  • Buys: the red privileged-access risk to amber by year end; standing production admins from 126 to under 25.
  • If declined: the risk stays red through next fiscal year, one phished engineer remains a platform-level event, and I re-raise this in Q1.

Speaker notes: "I am asking for $1.8M against a specific gap, not for general support. If the answer is no, I want the residual risk formally acknowledged." Then stop talking.

Trap: The vague ask ("continued investment in our security journey"). Boards make decisions; give them one. The consequence-of-no line converts your request into their decision.


Slide 10: Summary and discussion

On-slide title: Where We Stand, What I Need, What Do You Need From Me

Layout: Three lines of text, nothing else: posture sentence from slide 1, ask from slide 9, one question directed at the board.

Skeleton:

  • [Posture sentence, verbatim from slide 1]
  • [Ask, one line, verbatim from slide 9]
  • "Is there a risk area you want more depth on next time?"

Example (Meridian Health, illustrative):

  • "Resilient against commodity attacks, exposed to a production ransomware event, on plan against last quarter's commitments."
  • "The decision on the table: $1.8M to close the privileged access gap."
  • "My question for you: what should get more depth in October?"

Speaker notes: "That is the ten minutes; the rest of the time is yours." The closing question converts the session from performance review to working relationship, and it feeds next quarter's delta slide.

Trap: Introducing anything new. A new fact on slide 10 is a fact you failed to place earlier, and it eats the discussion time that is the point of the meeting.


Appendix: five slides you never present

Build these, reference them ("the detail is in appendix 3"), never walk through them. Navigating your own appendix cold under questioning proves the summary sits on real substance.

  • A1: Metrics detail. The scorecard behind the trends: crown-jewel control coverage, detect and recover times with test dates, aged findings. Same metrics every meeting; a scorecard that reinvents itself looks like it is hiding a trend line.
  • A2: Framework mapping. The full assessment behind slide 8.
  • A3: Risk register extract. The ranked list slide 3 was cut from, so the top-three claim is auditable.
  • A4: Audit and regulatory standing. Every open finding with age, owner, date. Reconcile against internal audit's records before each meeting; a mismatch here is how CISOs lose audit chairs.
  • A5: Incident log. Material incidents and near misses since last meeting, one line each.

One discipline for the whole deck: board materials are discoverable. After an incident, plaintiffs' lawyers and regulators read old decks. Write every slide for a hostile reader: accurate, no overpromises, risk acknowledged in writing with a plan attached.


The interview-round version

The prompt is some variant of "present your security strategy for our company," to a panel simulating the board. Same deck, compressed, with three changes.

Compression. Eight slides for a 20-minute slot. Merge slide 4 into slide 3 (each risk box gains a "where I believe you stand" line). Drop slide 5: no prior meeting, no delta. Drop slide 8 unless you have a genuinely defensible public benchmark for their sector. The appendix shrinks to two slides: your assumptions register and your first-90-days validation plan, which is what panels dig into.

Sourcing. Slide 2 comes from the 10-K or S-1 risk factors, earnings calls, and product docs. Slide 3 is your prioritized read of public information. Slide 9 becomes the year-one ask, with honest error bars.

The caveat, delivered once, up front, immediately after slide 1. Use this language verbatim or close to it:

"Everything in this deck is built on public information: your filings, your job postings, your disclosed history. In my first 30 days I would validate these assumptions directly, and I would expect at least one of my three priorities to change. What I'm presenting is my current read and the reasoning behind it, not a finding."

Then never caveat again; one structural caveat reads as senior, a caveat per slide reads as hedging. You are scored on prioritization and business fluency, not coverage: three risks with sharp reasoning beat twelve with none. Expect the planted "are we secure?" question; the answer shape is "no organization is immune: here is what you appear resilient against, here is what would hurt, here is what I would do about the second list."


Pre-wiring the audit chair

One to two weeks out, get 30 minutes with the audit chair; your CFO or general counsel brokers it if the relationship is new. The chair hates surprises more than bad news, will often set up your ask in the meeting itself, and will tell you what other directors are sensitive about.

The email, adapted to your names and dates:

Subject: 30 minutes before the [October] audit committee meeting

[Name], ahead of the [date] meeting I'd like 30 minutes to walk you through the security materials before they go out with the board package. Two things I want you to see before the room does: a gap in our vendor reassessment cycle that I'm reporting along with the fix, and a $1.8M ask on privileged access that I'd value your read on before I bring it to the committee. Happy to work around your calendar; [CFO name] can vouch that I keep these short.

In the session: walk the deck in ten minutes, spend the time on the degradation and the ask, close with "what is the committee not asking me that it should be?" Final materials go through the corporate secretary a week ahead; assume every director has skimmed them, and never read slides verbatim to people who have.


Meridian Health is a fictional company created for this template. All figures attached to it are invented for illustration.

Want the whole pack?

All seven pieces are free to read here, or grab them as one download.

See all seven →Download all (HTML)

More from the pack

Free template

Steal the 90-Day CISO Plan

The exact 90-day plan structure hiring panels expect: the single asset every CISO candidate gets asked for. Free, editable, yours in one click.

Instant access, no confirmation hoops. Occasional emails on landing the seat; unsubscribe anytime.