Quarterly Board Report · Q3 2026
Northwind Dental Group
Information Security & Compliance Programme
Prepared by: Your Firm · Fractional CISO
Sample report — client, people and figures are fictional.
1. Executive summary
Overall posture score
71▲ 8 vs Q2
Risks above appetite
3▼ 2 vs Q2
Remediation actions closed
27of 34 planned
Security posture improved this quarter, driven by organisation-wide MFA and tested immutable backups, which reduced ransomware exposure from critical to high. HIPAA readiness reached 82%. The main open concern is third-party risk: three critical vendors lack a current security review. A new emerging risk — staff pasting patient data into unapproved AI tools — has been added and needs a policy decision (see section 6).
2. Top risks
| Risk | Owner | Score | Treatment status |
|---|---|---|---|
| R-014Ransomware disrupts practice-management system | IT Manager | 20 | Immutable backups live; EDR rollout 80% complete |
| R-022Third-party billing vendor data breach | Operations Director | 16 | SOC 2 report requested; contract security addendum in review |
| R-009Phishing leads to email account takeover | IT Manager | 15 | MFA enforced for all staff; phishing simulations quarterly |
| R-031Unpatched imaging workstations | Clinical Systems Lead | 12 | Vendor patch window agreed; network segmentation planned Q4 |
| R-005Staff use of unapproved AI tools with patient data | Compliance Officer | 12 | AI acceptable-use policy drafted; approved-tools list pending |
Score = likelihood × impact on a 5×5 matrix. Risk appetite threshold: 15.
3. Compliance readiness
4. Key risk indicators
- Critical patches overdue > 30 days6 target ≤ 5
- Phishing simulation click rate4.1% target ≤ 5%
- Accounts without MFA0 target 0
- Backup restore test success100% target 100%
- Critical vendors without current review3 target ≤ 1
5a. Delivered this quarter
- MFA enforced for 100% of staff accounts
- Immutable backups deployed and restore-tested
- Incident response plan updated and table-top exercise run
- HIPAA risk analysis refreshed for all four clinics
5b. Priorities for Q4
- Complete security reviews for 3 critical vendors
- Segment imaging workstations from the clinical network
- Finish EDR rollout to remaining 20% of endpoints
- Begin SOC 2 Type II observation window
6. Decisions requested from the board
- Approve the AI acceptable-use policy and an approved-tools list, prohibiting patient data in unapproved AI services.
- Approve budget for network segmentation of imaging workstations (estimate provided separately).
- Confirm risk appetite remains at a score of 15 for FY2027.
