Triage BoardGet the app

Concept · Vulnerability reporting

Executive summary vs technical report

An executive summary tells leadership, in a page or less, what happened or what is at risk, what it means for the business, where things stand and what decision is needed. The technical report holds everything an engineer needs to verify and fix the problem: hosts, indicators, Common Vulnerabilities and Exposures (CVE) IDs, timelines and evidence. CS0-004 names the executive summary in objective 4.2 of the exam objectives, and objective 4.1 covers the vulnerability reports it often condenses.

  • Exam code CS0-004
  • Tickets here 8

Fourteen pages for a two-question audience

After a credential-phishing incident at a fictional insurer, the incident lead forwards the board the document the security operations center (SOC) worked from: fourteen pages of sign-in logs, 31 sender domains under example.net, mailbox-rule changes and a UTC timeline. The board's reply is one line: are customers affected, and what do you need from us?

Every fact in the document was right, and none of it answered the two things the readers wanted to know. The rewrite was five sentences. Customer data in two mailboxes may have been viewed; legal is assessing whether notification is required. The attacker's access was cut off on day one and no further sign-ins have been seen. Multifactor authentication covers 70% of staff. The ask: approve moving the remaining 30% to it this quarter. The fourteen pages became the appendix.

Notice how the rewrite handles what is still unknown. It says customer data may have been viewed and names who is deciding, instead of guessing. Leadership can plan around an open question with an owner; a confident statement that turns out wrong a week later is much harder to undo, especially when the incident may carry notification duties. That is also why legal reads the wording before it goes out.

Same incident, two documents

What belongs in each
PointExecutive summaryTechnical report
ReaderBoard, executives, business ownersAnalysts, engineers, auditors
LengthA page or lessAs long as the evidence needs
Opens withBusiness impact and statusScope, timeline and method
NumbersCustomers, services, deadlines, trend against targetHosts, events, severity scores, timestamps
Indicators of compromiseLeft out, or one line pointing to the appendixFull list, ready to block or hunt
StatusContained or not, in plain wordsEach action with its time and owner
Ends withA decision or approval requestRemediation steps and verification

Both describe the same facts. Selection and order are what change.

Cutting a technical report down to a summary

  1. Write the bottom line first

    One sentence: what happened or what is exposed, in business terms, and whether it is under control.

  2. State impact for this reader

    Customers, operations, legal duties. Check with legal before describing any data exposure.

  3. Give status and the next update

    Contained, eradicated, recovered, in plain words, with the date of the next report.

  4. Make the ask explicit

    Budget, downtime, a risk acceptance, a notification decision: one sentence with a deadline.

  5. Point to the detail

    One line saying where the technical report and appendices live, for anyone who needs them.

The other documents in objective 4.2

The executive summary is one of several reports CS0-004 expects you to tell apart. A shift or incident handover is short and technical, written for the next analyst. The after-action report, with lessons learned and root cause analysis, goes to the team and drives corrective action. An internal threat intelligence report shares what was learned about the adversary. The communication plan decides who hears what: legal, public relations, regulators, law enforcement, customers. The incident communication page walks through each audience.

On the vulnerability side, scan reports, compliance findings and risk scorecards feed the same kind of summary, covered under vulnerability reporting. When a summary quotes a metric, pick the one that answers the reader's question, and name it exactly: MTTD, MTTR and MTTC measure different clocks.

The two-sentence testTip

Cover everything below the first two sentences. If a board member could still say what happened, whether it is under control and what you want from them, the summary works.

Draft it for the board

Write for whoever has to sign off. A board reads a different document from the engineer who patches the server.

Ticket 1 / 8

0 right

INC-001

An analyst prepares a unified security dashboard for a quarterly executive board meeting. Which included metric should be removed because it is inappropriately tiered for an executive audience?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ACompliance against required regulatory frameworks is a board-level governance metric.
  2. BThe share of critical business services meeting availability requirements is a business-outcome metric that executives can act on.
  3. CHigh-severity exposures on internet-facing assets summarize strategic risk in a way executives can understand.
  4. DCorrect: The IDS false-positive rate is an operational tuning metric for the SOC; it doesn't help a board make decisions, so it belongs in a technical report.

INC-002

Review the vulnerability scan data. Which risk statement prioritizes high-level business impact, containment status, and required approvals over raw CVEs?

Exhibit

Affected SystemVulnerabilityBusiness Criticality
Customer DatabaseCVE-2023-XXXX (CVSS 9.8)Mission Critical
Internal WikiCVE-2023-YYYY (CVSS 7.5)Low
Public Web ServerCVE-2023-ZZZZ (CVSS 8.1)High

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AThis leads with CVSS scores, which are technical detail, and gives no business impact or decision to approve.
  2. BCorrect: It puts the business impact (financial loss from a database breach) first and asks for a specific approval (emergency downtime), which is what executives need.
  3. CThis is still framed around CVSS 9.8 and patch tasks rather than business impact and the decision needed.
  4. DThis is an operational order based on 'unpatched critical CVEs' and doesn't state the business impact or ask for an approval.

INC-003

Which metric is most appropriate for a board presentation to accurately convey the organization's cybersecurity posture?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ADropped-packet volume is a firewall operations number that says nothing about business risk.
  2. BA list of malware hashes is raw threat data for analysts and means nothing to a board.
  3. CCorrect: Estimated revenue at risk from critical vulnerabilities turns technical findings into business terms that a board can weigh and fund.
  4. DRaw authentication failures are noisy SIEM data without business context.

INC-004

A security director is preparing an executive summary for an emergency patching request. Based on the vulnerability dataset below, which primary "ask" best aligns technical risk with business outcomes?

Exhibit

Business UnitCritical VulnerabilitiesRevenue at Risk (Est.)Downtime Impact
E-Commerce12$2.5M / dayHigh
Internal HR45$50K / dayLow
R&D Lab8$100K / dayMedium

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AHR has the most vulnerabilities but the lowest revenue at risk and downtime impact, so counting vulnerabilities misleads prioritization.
  2. BCorrect: E-Commerce has $2.5M per day at risk and high downtime impact, so asking for emergency downtime there ties the fix to protecting the most revenue.
  3. CReplacing servers to clear all technical debt is a costly, slow project, not a focused emergency ask.
  4. DWeekend-only patching across all units ignores which unit carries the risk and delays the urgent fix.

INC-005

A security analyst is preparing a board presentation. Which headline statement best utilizes the provided dashboard trend to communicate business urgency to executive leadership?

Exhibit

MonthCompany Vuln AgingIndustry Baseline
January30 days35 days
February45 days34 days
March65 days35 days

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AThe industry baseline being stable is context, not the message; it says nothing about the company's own risk.
  2. BSaying aging rose to 65 days states the data without explaining why it matters or comparing it with a benchmark.
  3. CCorrect: Aging rose from 30 to 65 days while the industry baseline held at about 35, so the headline links the slowdown to higher breach risk, which executives can act on.
  4. DA 14-day remediation rule is a policy detail the table doesn't show, and it misses the trend the board needs to see.

INC-006

A SOC analyst identifies a critical unpatched vulnerability on the customer-facing e-commerce platform with public exploits available. Which one-line risk statement and executive ask should be presented to leadership?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AA CVE ID, CVSS score and IP address are technical detail with no business impact and no decision for leadership.
  2. BVague 'several vulnerabilities' and next quarter's routine patching hide an urgent, exploitable risk on a revenue system.
  3. CCorrect: It states the business risk (critical RCE on the customer-facing store, public exploits) in one line and makes a concrete ask: approve an emergency window this week.
  4. D'Patch consideration soon' is vague, names no business impact and makes no clear request.

INC-007

Given MTTD of 4 hours against a 6-hour target and 92% critical-vulnerability SLA compliance, which executive summary best conveys posture and recommended action?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: It summarizes both metrics in business terms (detection is on target, 8 percent of critical items missed SLA) and points to a specific action on the gap.
  2. BA 25 percent headcount increase isn't supported by these metrics, and detection already looks healthy.
  3. C92 percent compliance means some critical vulnerabilities missed SLA, so this statement is false.
  4. DAlert volume and false-positive counts are operational SOC data and not the metrics given or relevant to executives.

INC-008

A critical patch for a production database cannot be applied until the next maintenance window in 14 days. Which executive summary best communicates the situation?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ASaying no approvals are needed hides the residual risk that someone with authority must formally accept for 14 days.
  2. BCorrect: It names the interim protection (WAF rules and monitoring), the residual risk, the patch date and the approval needed from the CIO, which is a complete executive summary.
  3. CCVE details and plugin IDs belong in the technical report; an executive summary needs risk, timeline and the decision.
  4. DShutting down a production database is out of proportion when compensating controls can reduce the risk until the window.

Shift tally

0 / 0

The technical report proves what happened. The executive summary gets a decision made.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.