The One-Page Board IT Risk Memo
Put One IT Decision on the First Page of Your Board Packet
Use the template and worked example to state the amount, exposure, options, requested vote, owner, and due date.
Your board needs a vote, amount, owner, and date
The board asked about cyber risk. Your packet contains a tool list, vendor deck, or paragraph saying more investment is recommended. None states what the board must approve.
When the requested decision is missing, the board may approve the amount to clear the agenda or defer it until next quarter. Put the vote on line one. Support it with the exposure, known and unknown cost, real options, recommendation, owner, due date, and completion evidence.
Part 1: Put the requested decision before the background
Twelve rules. They apply to a nonprofit board, a partner group, a finance committee, and an audit committee alike.
1. Open with the decision, in one sentence, in the first line. Not context. Not background. The board should know what you are asking for before they finish the first line. Everything below the first line exists to support or challenge that ask.
2. State the risk as a business consequence, in a unit the board already uses. Days of lost operations. Client obligations you would fail. A regulatory notification you would have to make. An insurance position you would lose. Never state the risk in technical terms. “We have no tested restore capability” means nothing to a board. “If our file systems were encrypted on a Friday, we do not currently know whether we could be operating by Monday, and no one has tested it” means everything.
3. Separate known cost, unknown cost, and modeled cost. Never blend them. A known cost has a quote, a date, and a source. An unknown cost is real but not yet sized, and you say so plainly. A modeled cost is your estimate, labeled as your estimate, with the assumption stated. Boards forgive an unknown. They do not forgive discovering later that a number in the known column was invented.
4. Give two or three genuine options. Genuine means each one could actually be chosen. Two decoys and a preferred option is a common pattern and boards recognize it. If one of your options is obviously indefensible, it is not an option, it is theater, and it costs you credibility on the next memo.
5. Include the smaller option when a smaller option is credible. Frequently the honest answer is that a fraction of the proposed spend addresses most of the exposure. Say so. This is the single fastest way to be believed the next time you ask for the full amount.
6. Include a defer option when deferring is defensible, and attach a trigger to it. “Defer” with no condition attached is not a decision, it is a way to avoid one. Write the condition: what would have to happen, by when, and who watches for it. “Defer to the FY27 budget cycle, reconsider immediately if the insurance renewal in March requires it” is a decision. “Revisit later” is not.
7. Say what happens if the board declines. One line. Not as a threat. As the fourth option, honestly costed. A board that feels pressured stops trusting the memo.
8. Do not name products unless the decision requires it. If the board is choosing between two named platforms, name them. If the board is approving a capability, describe the capability. Product names invite the board to research the product, and you lose the meeting to a laptop.
9. Every number carries a date and a source. “Quote from [firm], dated [date]” or “Internal estimate based on [basis]”. A number without provenance gets challenged, and the challenge eats the meeting.
10. Name the approver, the due date, and the evidence of completion. The memo should specify how the board will know the thing was done. This is the part people skip, and it is why the same item appears three quarters running.
11. One page. If you need supporting detail, it goes in a separate appendix that is optional to read. If the one page cannot stand alone, the thinking is not finished.
12. Do not lead with fear. You can frighten a board once. After that they discount everything you bring, including the thing that genuinely warrants alarm. State the exposure accurately and let it do its own work.
Translate each technical statement into the board’s unit
| Do not write | Write |
|---|---|
| We lack EDR coverage on 40% of endpoints | On roughly four in ten of our computers, we would not detect an intrusion until someone noticed something wrong |
| MFA is not enforced for privileged accounts | Six accounts that can change anything in our systems are protected by a password alone |
| Our RTO is undefined | Nobody has established how long we would be unable to operate, or tested it |
| We need to improve our security posture | We are asking for a decision on one thing: [the thing] |
| Backups are not immutable | Our backups can be deleted by the same account an attacker would take over first |
Part 2: Copy the one-page memo into your board packet
Copy the template. Replace every bracketed field, keep the memo to one page, and delete the parenthetical guidance before the packet goes out.
IT RISK MEMO
To: [Board / Finance Committee / Partner Group] From: [Name, title] Date: [Date] Prepared with: [Internal staff, outside adviser, or both. Note any commercial interest the preparer holds.]
DECISION REQUESTED
(One sentence. What are you asking them to approve, decline, or choose between.)
RISK
(Two to four sentences. The business consequence, in business terms. What would go wrong, to whom, and what it would cost the organization in operations, obligations, or standing.)
Current evidence: (What do we actually know, and how do we know it. Assessment date, test result, incident, audit finding, carrier requirement, or the honest statement that no evidence exists yet.)
COST
| Category | Amount | Basis |
|---|---|---|
| Known | $ | (Quote, invoice, or contract. Name the source and the date.) |
| Known, internal | hours | (Staff time, whose, over what period.) |
| Unknown | (What is real but not yet sized, and what it would take to size it.) | |
| Modeled | $ | (Your estimate. State the assumption it rests on.) |
OPTIONS
| Option | Cost | What it addresses | What it leaves open | |
|---|---|---|---|---|
| A | ||||
| B | ||||
| C | Defer | $0 now | (Trigger: what causes this to return, when, and who watches for it.) |
RECOMMENDATION
(One option. One or two sentences on why. If the recommendation is the smaller or cheaper option, say why the larger one is not warranted yet and what would make it warranted.)
IF DECLINED
(One sentence. What the organization accepts by declining.)
APPROVAL
| Field | Entry |
|---|---|
| Decision owner | |
| Approval date | |
| Implementation owner | |
| Due date | |
| Evidence of completion | (The specific artifact that will prove it was done: a test result, a configuration record, a signed contract, a completion report.) |
| Reported back to board on |
Part 3: Review one completed finance committee memo
The organization below is fictional. The numbers are illustrative and are not benchmarks for any real organization.
IT RISK MEMO
To: Finance Committee From: J. Alvarez, Controller Date: March 14, 2026 Prepared with: Internal IT staff and an outside adviser engaged on a flat fee. The adviser earns no commission, margin, or referral fee on any option below.
DECISION REQUESTED
Approve $18,500 to add protected backup retention and establish a tested recovery procedure, and decline the $92,000 backup platform replacement proposed by our IT provider until the recovery test in Option A produces evidence that replacement is necessary.
RISK
If our file systems and accounting system were encrypted in a ransomware event, we do not currently know how long we would be unable to bill, pay, or serve clients. No restore has been tested. Our backups are stored on a system reachable with the same administrative credentials an attacker would take first, which means the backups could be deleted in the same event that makes us need them.
Our largest three client contracts contain service commitments measured in business days. A recovery of more than five business days would put those commitments at issue.
Current evidence: Backup jobs report success nightly. No full restore has been performed or timed in the 26 months of available records. Our IT provider confirmed on February 27, 2026 that backup storage is not configured with deletion protection and that the backup console uses the same directory credentials as production.
COST
| Category | Amount | Basis |
|---|---|---|
| Known | $4,800 / year | Immutable retention add-on to our existing backup subscription. Quoted by current provider, February 27, 2026. |
| Known | $13,700 one time | Fixed-fee recovery test and procedure documentation. Written quote from outside adviser, March 6, 2026. |
| Known, internal | ~40 hours | IT staff and finance staff time across a four-week window. |
| Unknown | Cost of remediation if the recovery test fails. Cannot be sized until the test runs. Sizing it is the purpose of the test. | |
| Modeled | $60,000 to $140,000 | Estimated cost of a five-day operational outage, based on our own average daily billings for FY25 and an assumption of 60% recovery of delayed billing. This is an internal estimate and is not a claim about likelihood. |
OPTIONS
| Option | Cost | What it addresses | What it leaves open | |
|---|---|---|---|---|
| A | Enable protected retention on existing backups. Run and time a full recovery test. Document the procedure and the actual recovery time. | $18,500 + 40 internal hours | Backups can no longer be deleted by a compromised account. We learn our actual recovery time instead of assuming one. | Does not improve detection. Does not address the two end-of-life servers noted separately. |
| B | Option A, plus replace the backup platform as proposed by our IT provider. | $92,000 year one, $34,000 annually thereafter | Everything in A, on newer infrastructure. | Replaces a system we have not yet demonstrated to be inadequate. Our provider earns margin on this option and disclosed that margin on request. |
| C | Defer both. | $0 now | Nothing. | Trigger: our cyber insurance renewal on July 1, 2026 asks whether backups are protected from deletion and whether a restore has been tested within twelve months. On current facts we would answer no to both. Controller to confirm the carrier’s questions by May 1, 2026 and return this memo if deferral is no longer defensible. |
RECOMMENDATION
Option A. The exposure we can name is that our backups are deletable and untested, and Option A fixes both for a fifth of the cost of Option B. Replacement may turn out to be warranted, and the recovery test is what would demonstrate it. If the test shows we cannot meet a five business day recovery on the current platform, this memo returns in Q3 with that evidence and Option B becomes the recommendation.
IF DECLINED
We accept that our backups remain deletable by a compromised administrative account and that our recovery time is unknown, and we answer no to two questions on the July insurance renewal.
APPROVAL
| Field | Entry |
|---|---|
| Decision owner | Finance Committee |
| Approval date | March 14, 2026 |
| Implementation owner | J. Alvarez, Controller |
| Due date | May 15, 2026 |
| Evidence of completion | Written recovery test result showing date, systems restored, elapsed time, and verifier signature. Backup console configuration record showing retention lock enabled and the account permitted to change it. |
| Reported back to board on | June quarterly meeting |
Part 4: Prepare the answer and source for five board questions
Before the meeting, put a sourced answer beside each question below. Keep unknowns labeled unknown.
“How likely is this?” Say what you know. If you have no defensible probability, say that you do not, and pivot to what you do know: whether the control exists, whether it has been tested, and what the consequence would be. Boards accept “I cannot give you a probability, and here is why the exposure still warrants a decision.” They do not accept a probability you made up, and they will ask where it came from.
“What are our peers doing?” Be careful. Peer benchmarks for security spend are widely quoted and rarely sourced properly. If you use one, give the publisher, the date, the peer set, and the denominator. If you do not have one that meets that bar, say that the comparison is not available and answer on your own facts instead.
“Didn’t we already spend money on this?” Frequently yes, and the honest answer helps you. “We bought the capability in 2023. It was licensed and never fully deployed” is a legitimate answer, and it usually reframes the request from new spend to finishing something.
“Can our IT provider just do this?” Sometimes. Ask them, get it in writing, and disclose whether they earn anything on the answer. If the provider recommending the purchase also earns margin on the purchase, the board should know that before it votes, and putting it in the preparer line at the top of the memo handles it without an argument.
“What happens if we do nothing?” That is Option C and the “if declined” line. You have already answered it, which is the point of writing them down.
Part 5: Four errors that keep the board from deciding
The memo that explains instead of asking. Two pages of background and no decision line. The board discusses it and nothing is decided, because nothing was requested.
The memo with one option. A single recommendation with no alternative reads as a demand. Boards push back on demands as a matter of function. Give them a real choice and they will make one.
The memo where the modeled number moved into the known column. Somebody writes “$4.9 million average breach cost” in a cost table. It is a published average across a global population that has no relationship to a 60-person organization in Westchester. The moment a board discovers a headline number is doing work in your analysis, everything else on the page is suspect.
The memo with no evidence of completion. Approved, funded, and never verified. The same item returns two years later with a larger number attached. The evidence-of-completion field exists to prevent exactly this, and it takes ten seconds to fill in.
Keep the signed vote and completion evidence with the memo
This template is general guidance for governance reporting. It is not legal, financial, or insurance advice, and it does not determine what your board, bylaws, funder agreements, or regulators require of you. Where a memo touches a regulatory obligation or a contractual commitment, have counsel review it before it goes in the board packet.
Use this freely. Change the field names to match your organization’s language. The order is the part that matters: decision first, evidence under it, cost separated by certainty, real options including a smaller one, one recommendation, and a named person with a date.
SBK Consulting is a family-run, vendor-neutral IT advisory firm serving the New York, Connecticut, and New Jersey metro area since 2010. Zero vendor partnerships, zero reselling, zero commissions, which means we have no financial interest in which option your board picks. We will sit with one live board decision and help you write it up if that is useful. If you use the template and never call, that is the outcome we designed for.
(718) 407-4169