Writing ·
Why the P&L Works and the Risk Report Doesn't
The same board, on the same morning, receives two kinds of information about the organisation it governs. One of them changes decisions. The other never has.
The same board, on the same morning, receives two kinds of information about the organisation it governs.
The first is financial. Revenue against plan, margin, cash, the shape of the quarter. Nobody in the room treats this as reporting. It is the substance of the meeting. Numbers get challenged, assumptions get tested, and decisions visibly turn on what the figures say. A soft month changes what gets approved. Somebody, at some point in that discussion, changes their mind because of a number.
The second is risk. Cyber, operational, compliance, whatever the organisation's particular exposure happens to be. It is usually well-produced. It has been through more drafting than the financial pack, because it has to be explained rather than merely read. Somebody worked hard on it. It is received attentively, noted, and occasionally probed.
And it has never changed a decision.
I want to be careful here, because the obvious explanation is wrong. The difference is not quality. In many organisations the risk report is the more thoughtful document — more analysis behind it, more expertise, more genuine effort to convey something difficult. If quality determined influence, the risk report would win.
The difference is not seriousness either. Directors are not indifferent to risk. Most of them are more anxious about it than about the numbers, precisely because they understand it less well.
The difference is structural, and it is worth being exact about what the structure is, because once you see it you cannot use the phrase "better reporting" with a straight face again.
Consider what a profit and loss statement actually is, as a signal. It arrives daily, or near enough, against a variable that also moves daily. It is not written by the person whose performance it judges — it is arithmetic, performed against prices set outside the organisation by people with no interest in anyone's career. It cannot be declined; there is no version of a business where the P&L is received, considered, and set aside. And it means one thing. There is no interpretive space in which a bad month can be sincerely presented as a good one.
Four properties. Cadence, independence, inescapability, clarity. None of them is about how good the measure is.
Cadence is the match between the speed of the signal and the speed of the thing it measures. A daily P&L against a daily variable is a closed loop. A quarterly cyber report against a risk that develops over hours is not a loop at all; it is a periodic summary of a process that has already finished several cycles since the last one. You cannot steer with information that arrives after the corner.
Independence is whether the measure is generated outside the reflex arc of the person it judges. The P&L is produced by the market. The cyber report is produced by the function whose competence it evaluates, and there is no dishonesty required for this to matter — the selection of what is worth reporting is a professional judgment, made in good faith, by someone who cannot help knowing what a given selection implies about them. Everything a person chooses to include, frame, aggregate or omit has passed through that.
Inescapability is whether the signal can be routed nowhere. A P&L arrives whether anyone wants it or not. A risk indicator can be received, discussed, minuted and left, and nothing in the structure notices that this has happened. There is no mechanism that registers a warning having been set down.
Clarity is whether the measure admits an interpretation under which nothing needs to change. Revenue down twelve per cent does not. A maturity score of 3.2, an amber status, a heat map with more red in the corner than last time — every one of these can be sincerely read as concerning, or as broadly stable, or as reflecting improved detection rather than deteriorating posture. Where a reading exists under which no action follows, that reading will be the one that survives the meeting. Not through bad faith. Because it is the only one that does not require someone to do something difficult on ambiguous grounds.
Score the risk report against those four and it fails all of them. Not narrowly. Comprehensively, and by construction, because nothing about how it is produced was ever designed to satisfy any of them.
The objection I expect is that this is unfair — that cyber risk simply cannot be reduced to a single number the way financial performance can, and that asking for a P&L of security is a category error. That objection is right about the reduction and wrong about the conclusion. The point is not that you need a number. Aviation does not have a P&L. It has weather minima, and a minimum has all four properties: it applies now, it comes from an instrument rather than from the pilot's assessment of his own judgment, it cannot be waived by anyone in the aircraft, and below the figure you do not depart. A clinical trial's stopping rule is not a number about the whole trial. It is a threshold with a consequence pre-attached, agreed before the data arrived.
That is the general form, and it is worth stating plainly: what makes a measure an input is not what it measures but where it sits and what it is attached to.
Which brings me to the thing underneath all of this, and it is a larger claim than the one I have been making about cyber.
There is a comfortable story in which some organisations are self-correcting and others are not, and the difference is culture, or leadership, or the calibre of the people. Aryeh Bourkoff, who runs an investment bank, has spoken about self-correction as a discipline — and he credits it partly to the daily profit and loss statement, which he describes as one of the external things that keep a person honest about how they are doing. He is right about the mechanism and, I think, generous about the cause. He is also a founder-owner, which means his own clarity and the organisation's clarity are the same object. Nothing he concludes about himself at three in the morning costs him anything at nine.
The executive who reaches the same clarity at three in the morning does not have that. At nine they face a choice that is career-irrational in exactly the way I have written about before: surface an ambiguous concern early and take a personal risk for an uncertain and unattributable benefit. The clarity is available. The correction is not, because the structure does not permit it.
So self-correction is not a virtue. It is a structural property. Organisations that appear to have it are usually organisations with fast, independent, inescapable, unambiguous feedback and someone whose interests are aligned with hearing it. Organisations that lack it are not staffed by less reflective people. They are staffed by people whose reflection has nowhere to go.
This matters because it changes what you would even attempt. If self-correction is a virtue, you recruit for it, train for it, and put it in the values statement, and nothing happens, which is the observed result of thirty years of trying. If it is a structural property, you look at a specific measure and ask which of the four it fails, and you change that.
I said in the previous piece that I would not offer a framework, and I am not offering one now. Three of these are relatively easy to improve and one is very hard, and it is the hard one that matters. You can fix cadence by reporting more often, though most organisations discover that more frequent output is still output. You can improve clarity by attaching a threshold and a consequence in advance, which costs nothing and is done almost nowhere. You can create inescapability by requiring that a declined signal be recorded with its reasoning, so that setting something down leaves a mark.
Independence you cannot fix from inside, because the whole difficulty is that inside is where the filtering happens. Any measure generated by the function it assesses will carry that function's judgment about what is worth surfacing, and no amount of integrity removes the problem, because the problem is not integrity. This is why external observation exists at all, and why an organisation cannot establish from its own evidence whether its quiet is the quiet of nothing being wrong or the quiet of nobody reporting.
So the test I would leave you with is a small extension of the one from last time.
Take the measure in front of you and ask, in order: how fast does it arrive relative to the thing it describes; who produced it and what does its content imply about them; what happens structurally if it is noted and set aside; and is there a reading of it under which nothing needs to change.
If the answers are quarterly, the function being assessed, nothing, and yes — then you are not looking at oversight. You are looking at a document, and you will not know the difference until the day someone asks whether you knew.