Don’t Let a Green Cyber Dashboard Give Your Board a False Sense of Security

August 4, 2026

Don't Let a Green Cyber Dashboard Give Your Board a False Sense of Security
  • Sandy Jacolow, Today's General Counsel Columnist

    Sandy Jacolow is the Senior Vice President, Chief Technology Officer at Empire State Realty Trust (ESRT). He oversees technology innovation supporting financial control, leasing, property management, ESG, marketing, and property technology activities. He also runs ESRT’s IT and operational technology (OT) cybersecurity programs working closely with the compliance team to monitor and mitigate risk associated with today’s cyber threats.

Cybersecurity dashboards turn complex evidence into percentages, trends, and traffic-light colors. That clarity is useful, but it can be deceptive, offering a false sense of security. A privileged account may still lack multifactor authentication (MFA). A critical service may never have been restored from backup. A building system outside the reported scope may still interrupt operations.

A green dashboard does not prove cyber risk is low. Every percentage has a denominator, and every denominator reflects a scope decision. Even if the numbers are correct, the final assessment is unreliable because critical systems were left out, controls were never tested, and significant exceptions were omitted. A green cyber dashboard is a conclusion to test, not accept.

For general counsel, the dashboard is not merely an IT report. In a board book, it records what management told directors about the company’s cyber posture. In a regulatory disclosure, insurance application, customer security questionnaire, or contract, its claims may be repeated as representations on which others rely. Legal’s role is not to rerun testing; it is to ensure the claim does not outrun the evidence. If a headline claim does not match its scope, testing, or unresolved exceptions, the mismatch creates legal and governance risk.

General counsel should help executives and the board committee responsible for cyber oversight press management on four questions: What is outside scope? What did testing reveal? Which material exceptions remain unresolved? Can the business recover essential services within approved time frames?

The exposure is not theoretical. Following a 2022 ransomware attack, insurer Travelers alleged that electronics manufacturer International Control Services falsely claimed to use multi-factor authentication (MFA) for administrative and privileged access. In reality, the manufacturer only secured its firewall with MFA, leaving its servers and other digital assets unprotected. The parties stipulated to rescission, and a federal court declared the policy void from inception. Travelers’ theory was simple. The control existed; the representation about its scope did not.

Start with the denominator

Aggregate metrics describe only the systems selected for measurement. Legacy platforms, recent acquisitions, vendor-managed environments, and building systems often sit outside scope even when they underpin core operations. A 95% patching rate can mislead if the denominator disregards systems that run billing, payroll, manufacturing, or facilities.

General counsel and the oversight committee should know what is omitted, why, and when each gap will be brought into scope, protected by compensating controls, or documented through formal risk acceptance. Not every system requires identical controls, but gaps affecting essential operations or sensitive data must be visible.

Legal should compare dashboard analytics, scope, and definitions with public disclosures, insurance applications, customer security questionnaires, and contracts. An enterprise-wide statement should not rely on internal reporting that silently excludes acquired, vendor-managed, or building systems.

Activity is not assurance

Most dashboard metrics measure effort: patches applied, training completed, phishing simulations passed, and tools deployed. These steps are necessary, but they do not show whether the controls will work when needed. The report should distinguish among implementation, coverage, and tested effectiveness.

A dashboard may report that MFA is deployed across privileged accounts. That does not show whether MFA can be bypassed, account recovery is secure, every privileged account is covered, or service accounts have equivalent safeguards. Outcome claims require evidence from testing.

Require management to test the business services most essential to operations, not merely a convenient sample, and document corrective actions. Can network segmentation contain an intrusion? Do alerts reach the right people at all hours? Can the company determine what data was accessed or transferred? Can it quickly disable a compromised vendor connection or service account? If results are repeatedly clean, ask whether the tests probe realistic failure modes or merely confirm that a control exists.

For each critical control, show the date and result of the latest test and the status of corrective action. The useful measure is performance when needed, not mere deployment.

Make material exceptions visible

Every material exception needs an owner, stated business impact, compensating controls, approval date, and review or expiration date. A weakness that persists quarter after quarter is no longer temporary. It is a management decision about timing, resources, or risk acceptance.

Accepted risk and deferred remediation cannot disappear inside an aggregate score. The oversight committee should see which exceptions are overdue, repeatedly renewed, or tied to critical operations. A reassuring headline should not conceal a consequential decision.

Read the latest thought leadership and analysis from legal experts

Measure recovery, not just prevention

Many dashboards emphasize prevention: blocked attacks, patched vulnerabilities, security-tool coverage, and employee training. Those measures matter, but no program eliminates every incident. A meaningful scorecard also demonstrates the ability to restore essential business services within agreed-upon recovery time objectives.

At minimum, show the date and result of the latest recovery test for each critical service; whether the test covered the complete business process, not only the technology; and any unresolved actions from the latest cross-functional exercise.

The key distinction is between backing up data and restoring an operating business. A successful server restoration does not mean employees can serve customers, process payments, access facilities, or meet legal obligations. Prevention reduces the likelihood of an incident. Recovery determines whether it becomes a business crisis.

Turn the dashboard into an oversight tool

The oversight committee does not need a longer technical report. For each critical service, the dashboard should show its scope, the result of the latest control test, open exceptions and their owners, and the result of the latest recovery test. Directors should not have to infer business risk from technical activity.

A dashboard that cannot surface material exposure measures comfort, not assurance.

Critical intelligence for general counsel

Stay on top of the latest news, solutions and best practices by reading Daily Updates from Today's General Counsel.

Daily Updates

Sign up for our free daily newsletter for the latest news and business legal developments.

Scroll to Top