@jerry relaying how their org is doing when compared with their peers. I get asked that on the weekly. Understanding the risk completely and how that impacts the org is really important too, and being able to explain that risk. Don't misspeak either, especially in consulting roles.
Don't be that nervous. They're just people at the end of the day who (hopefully) want to see their org mitigating future attacks. This one I notice a large difference between internal and consulting roles.