An information security manager is designing the risk reporting package for a multinational organisation in which the board, business unit heads, and operational technology teams all receive the same monthly information security risk update. Several recipients have complained that the report is either too detailed or too high level. What is the MOST effective way to address this?
- AStandardise on a single highly detailed report for every recipient so that all stakeholders see identical data and no group can claim it was given incomplete information.
- BReduce the report to a single overall risk rating for the organisation so that every audience receives a brief, easily understood summary each month.
- CTailor the content and level of aggregation of the risk report to each audience, giving the board appetite and trend summaries while operational teams receive granular indicator detail. Correct
- DSurvey all recipients and adopt whichever single format the majority prefers, then apply that one format uniformly across the whole stakeholder list.
Why A is wrong: It is tempting because one consistent dataset seems fair and defensible, but burying executives in operational detail obscures the decisions they must make and does not solve the complaint that the report is too detailed for some.
Why B is wrong: It is tempting as a way to satisfy those who find the report too long, but collapsing everything to one rating strips out the indicator detail that operational teams need to act, so it fails half the audience.
Why C is correct: Correct: effective risk communication matches the depth, framing, and metrics to each stakeholder group's decision-making needs, so segmenting the report by audience resolves both the too-detailed and too-high-level complaints.
Why D is wrong: It is tempting because consulting recipients sounds stakeholder-centric, but a majority-vote single format still forces one level of detail on groups with genuinely different needs, leaving the minority underserved.