Objective 4.1 · Lesson 2 of 2

Report what is preventing risk reduction

A useful status report explains why risk remains and what decision would change it. Numbers support that explanation only when their scope, definitions, and limitations remain visible.

Make remediation inhibitors explicit

Remediation can be blocked by an unavailable patch, a legacy platform, proprietary software, a supplier contract, or internal approval rules. A change may interrupt a business process or degrade a required function. Name the specific inhibitor and supporting evidence. “The business will not allow it” is too vague to resolve; “the supplier has not approved the replacement driver” points to a concrete dependency.

Assign an owner to remove the blocker and offer a time-bounded interim option where appropriate. Segmentation, access restriction, monitoring, or a service change may reduce exposure while a permanent fix is prepared. State the residual risk and verification method. An exception requires authorised review, an expiry or review date, and a trigger for reconsideration; it should not silently convert a known weakness into a closed finding.

Build scorecards that preserve meaning

A scorecard should show the organisation’s important risks and whether the programme is reducing them. Include scope and coverage alongside open findings, overdue work, recurrence, and risk categories. A lower vulnerability count can result from successful fixes, a smaller scan population, missing credentials, or retired assets. Without those distinctions, a neat downward trend can reward loss of visibility instead of improvement.

Use consistent grouping when comparing periods. Deduplicate observations according to an explicit finding definition, and distinguish newly discovered issues from reopened ones. Explain substantial changes to asset coverage or scoring rules. Summaries should let a decision-maker see which services carry the greatest remaining exposure and what investment, approval, or coordination is needed, rather than merely ranking teams by the largest raw count.

Measure service levels and verified progress

When reporting a remediation SLA, define the population, start event, deadline rule, stop event, and approved exceptions. Show whether closure means an owner’s claim or validated remediation. A mean completion time can hide a long tail of unresolved work, so pair it with overdue counts and age bands. Segment results where different risk levels or service classes have different expectations.

Keep the denominator visible. If ten eligible findings are due and eight are verified within the target, the on-time result is eight of ten, or eighty percent. Do not remove the two overdue items simply because they remain open. Escalate the reason for delay and the decision required, and review whether interim controls actually reduce risk while the permanent work remains outstanding.

Keep these points in mind

  • Name each blocker, its owner, and the decision needed to resolve it.
  • Report exceptions as managed residual risk, not completed remediation.
  • Interpret trends and SLA percentages using stable scope and explicit denominators.

Pause and practise

Twelve high-priority findings were due this week. Nine were verified fixed, one has a documented exception, and two are overdue. How should the weekly report present this?

Show a worked response

Report all twelve with separate categories: nine verified on time, one approved exception with its review date and residual risk, and two overdue with owners and escalation. State whether the agreed SLA calculation includes or separately reports approved exceptions. Do not silently count the exception as a fix or exclude overdue work from the denominator.

← Previous lesson