Board Edition
Cyber-Risk Oversight · 2026

The Board'sCyberHandbook

Six principles and fifteen tools — re-argued for the board of a company with hundreds of employees, not tens of thousands.
David S. Levin
& Daniel Ramos CEO & CISO · Intelligent Automation
Board Edition · 2026

Cyber oversight, without the padlock slide.

David S. Levin & Daniel Ramos

A complete rewrite of the NACD / Internet Security Alliance Director's Handbook on Cyber-Risk Oversight — in two voices that disagree in useful places. An MSP operator on the business decisions. The CISO who defends his clients on the threat and control reality. Written for a board that has one IT manager and a provider, not a security department.

Six principles Fifteen tools ~11,000 words No email wall
Derived from NACD/ISA, 5th ed.
Every figure sourced or flagged
Free · no registration
Why rewrite it at all

The best board guide in cyber was written for somebody else's company.

The NACD/ISA handbook earned its reputation, and any serious director should read it. It is also pitched at a Fortune 500 audit committee that already has a full-time CISO and outside counsel on retainer. We kept the six principles. We changed who they're talking to — and we argued back where we thought the original was too careful.

01

Written for your size

Every principle and tool is re-scoped for a company where the security department is one internal IT manager and an outside provider. The governance work is identical. The resources are not.

02

Two voices, on the record

Each chapter has a lead author and a short counterpoint from the other. Where the CEO and the CISO see it differently, you get both reads instead of a committee compromise.

03

Receipts — and refusals

The source note names which figures we carried across on NACD's authority and which we checked ourselves. It also names the one big number we threw out, and why.

What's inside

Six principles. Fifteen tools.

The principles are what a board owes the company. The tools are what you pull off the shelf when one specific thing lands on the agenda — a ransom demand, a quantum question, a deal in diligence.

PRINCIPLE ONE · David
Treat it as a business risk, and price it

Reporting you can't price isn't oversight. What the scenarios cost, in dollars.

PRINCIPLE TWO · Daniel
Know what you owe, and when the clock starts

The four-day SEC clock, NIS2, nineteen state regimes — and who makes the call at 2 a.m.

PRINCIPLE THREE · David
Build the seat, not just the skill

Why one cyber director doesn't fix governance, and the three cheaper things that do.

PRINCIPLE FOUR · Daniel
Run it on a framework, and set your appetite

Pick a framework, score honestly, and write down how much risk you'll accept.

PRINCIPLE FIVE · David
Demand reporting you can actually use

Six numbers, trended quarterly. Everything else is a slide with a padlock on it.

PRINCIPLE SIX · Daniel
You can't be secure alone

A third of breaches now arrive through someone you bought from.

The Toolkit

Fifteen tools for the meeting you're actually in.

A
Ransomware preparednessDaniel
B
Cyber incident responseDaniel
C
Emerging technologyDavid
D
Quantum & Q-DayDaniel
E
Decisions on AIDavid
F
Cloud servicesDavid
G
Insiders & human riskDaniel
H
Third party & supply chainDaniel
I
Mergers & acquisitionsDavid
J
The board and the CISOBoth
K
Metrics that mean somethingDaniel
L
What the board pack looks likeDavid
M
DisclosureDaniel
N
Directors' personal securityDaniel
O
Working with the FBIDaniel
The two voices

One handbook, two sides of the table.

They co-founded the same company and still argue about this. That argument is the book.

David S. Levin, CEO of Intelligent Automation
David S. Levin
CEO · Intelligent Automation
“You're not being asked to become technical. You're being asked to stop accepting comfortable answers.”

Twenty-five years inside the MSP industry — building companies, hiring operators, and watching owners get sold things they didn't need. He wrote The Small Business IT Buyer's Guide for the same reason he wrote his half of this one.

David takes the chapters where the answer is a business decision: pricing the risk, structuring the oversight, and refusing a board pack that can't change a decision.

Principles 1 · 3 · 5 Tools C · E · F · I · L
Daniel Ramos, Founder and Principal vCISO
Daniel Ramos
Founder · Principal vCISO
“The fastest way for a security leader to lose a board is to hand them a number they later discover was marketing.”

He opens his first chapter by taking a statistic away from the reader — the $20 trillion loss projection that circulates in vendor decks, which is a forecast stacked on forecasts and doesn't belong in a document demanding rigor.

Daniel takes the chapters with clocks, controls and consequences: disclosure deadlines, risk appetite, supply chain, and the tools you reach for at 11 p.m.

Principles 2 · 4 · 6 Tools A · B · D · G · H · K · M · N · O
Whatever management tells you about the state of the company's security, there's a second question, and it's almost always the same one: how do we know that's true?
David S. Levin · Closing
On the record

Five places we changed the argument.

A rewrite that agreed with everything wouldn't be worth reading. These are the substantive departures from the original — all of them named in the handbook's own source note, so you can judge them.

We cut the $20 trillion

A projection built on projections. It opens a lot of security decks. It doesn't open ours.

🌱

Verify beats recruiting

The original leaves the “add a cyber director” question open. We rank an independent outside assessment above it — and explain the deference problem one expert can create.

🔗

Suppliers moved up front

Third-party involvement in breaches doubled to 30% in Verizon's 2025 report. That's the spine of a principle here, not one tool among fifteen.

🎥

We named the incentive

Polished board reporting is a rational response to how most boards receive bad news. Fix the incentive and the candor follows.

What this is, and what it isn't

This is original writing and an original argument, derived from the National Association of Corporate Directors and Internet Security Alliance Director's Handbook on Cyber-Risk Oversight, Fifth Edition (2026). It reproduces no text from it. The original is copyright NACD and ISA, it is free to obtain, and we think a serious director should read both.

The handbook's closing source note separates the figures we carried across on NACD's authority from the matters of public record we state on our own reading. It is not legal advice.

Free · No email wall

Read it before your next board meeting.

The whole handbook, on one page, with a contents rail so you can jump straight to the principle or tool you need. No registration, no gate, no follow-up sequence.

6
Principles
15
Board tools
2
Voices
0
Forms to fill
Updated August 2026 · Intelligent Automation, LLC
Secured by IA