Report Recommendations

Hi guys,
So can you all suggest some cyber security reports I can create for our upper management? This ask is especially for those of you in cyber management, or those of you who have dealt with the management types regularly?
I now happen to be the only cyber security guy in our organization, a company providing diagnostic services for the healthcare industry. There are about 5000 endpoints in the security space.
Anyways, I'm a senior engineer. One of my buddy managers in another field told me "...you know upper management they eat reports for breakfast and lunch. If you can get them the right you're good to go". So here I am ladies and gentlemen. A million high fives in advance for your comments, suggestions, recommendations, etc.
So can you all suggest some cyber security reports I can create for our upper management? This ask is especially for those of you in cyber management, or those of you who have dealt with the management types regularly?
I now happen to be the only cyber security guy in our organization, a company providing diagnostic services for the healthcare industry. There are about 5000 endpoints in the security space.
Anyways, I'm a senior engineer. One of my buddy managers in another field told me "...you know upper management they eat reports for breakfast and lunch. If you can get them the right you're good to go". So here I am ladies and gentlemen. A million high fives in advance for your comments, suggestions, recommendations, etc.
B.Sc (Info. Systems), CISSP, CCNA, CCNP, Security+
Tagged:
Comments
How does mgmt expect this to be delivered? I have worked in Scrum/Agile environments that delivered this information via a PowerPoint presentation at the end of a sprint and environments that created Splunk dashboards for C-suite. Were you asked to deliver a report or is this your initiative?
I was not asked to deliver a specific report @E Double U. The CTO however made a disturbing remark during our monthly meeting that "None of the executives knows what's going on with security. We don't know where we are"
So I'm simply trying to be proactive to show some type of effort to communicate securitys efforts in doing it's part. I don't want to do this on the reactive side when you get that ominous "we need to see something or else...." type of message from the higher ups if you know what I mean.
Forum Admin at www.techexams.net
--
LinkedIn: www.linkedin.com/in/jamesdmurray
Twitter: www.twitter.com/jdmurray
Forum Admin at www.techexams.net
--
LinkedIn: www.linkedin.com/in/jamesdmurray
Twitter: www.twitter.com/jdmurray