Sample output

This is the report your client's board would get

A quarterly GRC board report for a fictional client, laid out the way NovaGRC assembles it from the live risk register, control status and KRIs. In the product it carries your firm's logo and name.

Quarterly Board Report · Q3 2026

Northwind Dental Group

Information Security & Compliance Programme

YOUR FIRM LOGO

Prepared by: Your Firm · Fractional CISO

Sample report — client, people and figures are fictional.

1. Executive summary

Overall posture score

71▲ 8 vs Q2

Risks above appetite

3▼ 2 vs Q2

Remediation actions closed

27of 34 planned

Security posture improved this quarter, driven by organisation-wide MFA and tested immutable backups, which reduced ransomware exposure from critical to high. HIPAA readiness reached 82%. The main open concern is third-party risk: three critical vendors lack a current security review. A new emerging risk — staff pasting patient data into unapproved AI tools — has been added and needs a policy decision (see section 6).

2. Top risks

RiskOwnerScoreTreatment status
R-014Ransomware disrupts practice-management systemIT Manager20Immutable backups live; EDR rollout 80% complete
R-022Third-party billing vendor data breachOperations Director16SOC 2 report requested; contract security addendum in review
R-009Phishing leads to email account takeoverIT Manager15MFA enforced for all staff; phishing simulations quarterly
R-031Unpatched imaging workstationsClinical Systems Lead12Vendor patch window agreed; network segmentation planned Q4
R-005Staff use of unapproved AI tools with patient dataCompliance Officer12AI acceptable-use policy drafted; approved-tools list pending

Score = likelihood × impact on a 5×5 matrix. Risk appetite threshold: 15.

3. Compliance readiness

HIPAA Security Rule82% (+8) · 9 controls open
SOC 2 Type II (Security)64% (+13) · 22 controls open
ISO 27001:202248% (+8) · 48 controls open

4. Key risk indicators

  • Critical patches overdue > 30 days6 target ≤ 5
  • Phishing simulation click rate4.1% target ≤ 5%
  • Accounts without MFA0 target 0
  • Backup restore test success100% target 100%
  • Critical vendors without current review3 target ≤ 1

5a. Delivered this quarter

  • MFA enforced for 100% of staff accounts
  • Immutable backups deployed and restore-tested
  • Incident response plan updated and table-top exercise run
  • HIPAA risk analysis refreshed for all four clinics

5b. Priorities for Q4

  • Complete security reviews for 3 critical vendors
  • Segment imaging workstations from the clinical network
  • Finish EDR rollout to remaining 20% of endpoints
  • Begin SOC 2 Type II observation window

6. Decisions requested from the board

  1. Approve the AI acceptable-use policy and an approved-tools list, prohibiting patient data in unapproved AI services.
  2. Approve budget for network segmentation of imaging workstations (estimate provided separately).
  3. Confirm risk appetite remains at a score of 15 for FY2027.
Generated with NovaGRC · Confidential — prepared for the Northwind Dental Group board (fictional sample)

Produce this for every client in minutes

NovaGRC builds board packs, gap reports and executive dashboards straight from each client's live data, with your branding.