Answer yes if information security and cyber risk is formally reported to your organisation's board, or equivalent senior governing body if no formal board exists, as part of your regular financial and operational risk reporting cycle (not simply discussed informally or reported to management below board level). Findings and identified risks should be tracked and reviewed at board level over time, not simply presented once. Describe the frequency and format of this reporting in the notes section (e.g. quarterly board risk report), or upload a redacted example/board paper as evidence.