## Purpose

Use this agenda for periodic leadership review of the company’s cybersecurity position.

The objective is to give leadership a short, structured view of significant risks, overdue work, incidents, control gaps, and decisions requiring management attention.

A quarterly review is appropriate for many SMEs, with additional reviews after serious incidents or major business changes.

## Meeting Information

Date: ____________________

Chair: ____________________

Participants: ____________________

Reporting period: ____________________

## 1. Review Previous Actions

Review actions agreed at the previous meeting.

**Confirm:**

- What was completed
- What remains open
- What is overdue
- What is blocked
- What requires leadership support

Record important overdue actions in the Master Action Tracker.

## 2. Review Significant Cybersecurity Risks

Review the highest-priority items in the Risk Register.

**Discuss:**

- New risks
- Risks that have increased
- Risks that have decreased
- Critical control gaps
- Unsupported or high-risk systems
- Major vendor risks
- Risks currently being accepted

Leadership should understand which risks could create the greatest business impact.

## 3. Review Important Security Controls

Review the status of important controls, including:

- MFA coverage
- Privileged access
- Backups and restore testing
- Patch and vulnerability management
- Endpoint protection
- Email security
- Internet-facing systems
- Logging and detection
- Vendor access
- Employee security training
- Focus on material gaps rather than reviewing every technical setting

## 4. Review Incidents and Near Misses

Review significant incidents, suspicious activity, fraud attempts, or near misses since the previous meeting.

**Discuss:**

- What happened
- Business impact
- How quickly it was detected
- Whether response worked
- What lessons were identified
- Whether corrective actions were assigned

## 5. Review Vendors and Major Changes

**Discuss cybersecurity implications of:**

- New vendors
- New SaaS platforms
- New cloud systems
- Major system changes
- Acquisitions or new offices
- Changes in MSP or IT support
- New use of AI tools
- New customer or contractual requirements
- Significant staffing changes

## 6. Review Training and Awareness

**Confirm:**

- Core training completion
- Role-based training completion
- Phishing simulation or exercise results
- Repeated employee issues
- Upcoming training
- Any changes needed after incidents or near misses

## 7. Decisions Required From Leadership

**Record decisions required for:**

- Budget
- Staffing
- Technology replacement
- Vendor changes
- Risk acceptance
- Policy changes
- Incident response support
- Insurance requirements
- Major remediation projects

Decision: ____________________
Owner: ____________________
Due date: ____________________

## 8. Confirm Next Actions

**For every significant action, record:**

- Action
- Owner
- Priority
- Due date
- Evidence required
- Escalation requirement

## Expected Output

**At the end of the meeting, leadership should know:**

- The company’s highest cybersecurity risks
- Which important actions are overdue
- Where important controls remain weak
- What incidents occurred
- What decisions leadership must make
- Who owns the next actions

## Practical Rule

Leadership does not need every technical detail.

Leadership needs enough information to understand the risk, make decisions, and make sure important cybersecurity work gets done.
