Cyber exposure in the language of the decisions you already take.
NIS2 and DORA now name the management body: you approve the measures, you follow the training, you carry the liability. Mindlapse turns the cyber slot into a pack of decisions, accept, fund, defer or transfer, each one click from its evidence.
Accept · Fund · Defer · Transfer · Every figure one click from its evidence
Cyber Cockpit · the quarter’s pack Illustrative data
Critical activities within appetite
6 / 8
Decisions pending
3
Findings past their deadline
2
Exposure by business activity
Appetite
Online sales
Payments
Logistics
Customer care
HR
Decisions pending
MFA on the customer portal Fund
Online sales · Customer care·CIO·next quarter
Residual risk on the legacy warehouse system Accept
Logistics·COO·for two quarters
Cyber insurance renewal scope Transfer
Payments · Online sales·General counsel·in 45 days
The pack reads exposure by business activity against the appetite the board approved; each decision carries the activities at stake, an owner and a deadline, and every line opens on the records behind it.
THE SITUATION
You are asked to decide, and handed a dashboard.
01
Twenty minutes, forty slides
The cyber slot is a tour of dashboards; it ends when the time runs out, without a decision.
02
Liability without a lever
Article 20 of NIS2 and Article 5 of DORA name you; the deck names nothing you could decide.
03
A number nobody can trace
A compliance percentage on a slide, rebuilt by hand, contested the moment someone asks how it was computed.
04
The question you asked last quarter
Nobody can show whether it was closed, by whom, or on what evidence.
A good week for the board is a quiet one; the quarter is where it approves, decides and signs.
Five moments, two of them with nothing on the agenda, and what the platform had done before the question reached you; then the three dates of the quarter that carry your signature.
A board week, then the quarter Illustrative data
Your week
verified: MON 08:00
The posture is within appetite; nothing for you to do.
The daily snapshot said so, activity by activity, before anyone asked.
Surface: Cyber Cockpit
TUE
No cyber item on the agenda.
alert: WED 12:10
A supplier breach in the press.
The answer came from the register, not a phone tree: which activities depend on it, what was assessed, what is still open.
Surface: Value Chain Map
THU
No cyber item on the agenda.
FRI 17:30
The CEO signs a risk acceptance.
In the authority ladder, at the level the residual band required, with an expiry.
Surface: Risk Posture
Your quarter
WEEK 4
The appetite is approved.
With an expiry, and breach alerts wired to the risk owners.
Surface: Risk Posture
WEEK 8
The cyber-risk policy is signed.
Published, versioned, attested by the people it binds.
Surface: Policies
WEEK 12
The pack.
Exposure by activity, indicators against appetite, three decisions, exported from live data.
Surface: Cyber Cockpit
Illustrative week, quiet by design: the moments are fictional, the surfaces are the product’s.
FROM THE FIELD
Built with the people who sit at the table.
CYBER COLLECTIVE LAB · Edition 4
Interview with a former luxury-sector CISO, now a Chief Data & Analytics Officer
The executive reading of cyber: the edition that interviewed a former luxury-sector CISO turned Chief Data & Analytics Officer, on what a board can decide from and what it cannot.
15–30%
cyber-budget optimization
−50–70%
time-to-risk-decision
2–3×
risk visibility across the organization
Measured with our design-partner CISOs, figures under continuous validation.
What exactly does NIS2 ask of the management body?
To approve the cybersecurity risk-management measures, oversee their implementation, follow training and carry the liability for breaches of those duties. NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026.
Do we license Board-Ready Reporting separately?
No. Board-Ready Reporting is the Cyber Cockpit, the transversal layer of the platform; its views light up with the modules you activate. The pack is a reading of your register, not a product beside it.
How current is the pack when we read it?
It is exported from the platform state at the moment you open it, not rebuilt in slides the night before; every figure opens on the records behind it, with their date and their validation state.
Can we read it without a security background?
Yes. Exposure is read by business function and activity, not in CVEs, and the same figures exist at group, entity and activity altitude, so an executive committee and a board read one picture at the level they own.
Does it record what the board decided?
Yes. Accept, fund, defer or transfer is written to the record with its rationale, its owner and its deadline, and the resulting actions are tracked in GRCOps to verified closure, so the question you asked last quarter has a status this quarter.
Our host’s audience measurement (Vercel) uses no cookies and is not covered by this choice. Google Analytics and marketing trackers stay off until you say otherwise. Read the cookie policy