A complete rewrite of the NACD / Internet Security Alliance Director's Handbook on Cyber-Risk Oversight — in two voices that disagree in useful places. An MSP operator on the business decisions. The CISO who defends his clients on the threat and control reality. Written for a board that has one IT manager and a provider, not a security department.
The NACD/ISA handbook earned its reputation, and any serious director should read it. It is also pitched at a Fortune 500 audit committee that already has a full-time CISO and outside counsel on retainer. We kept the six principles. We changed who they're talking to — and we argued back where we thought the original was too careful.
Every principle and tool is re-scoped for a company where the security department is one internal IT manager and an outside provider. The governance work is identical. The resources are not.
Each chapter has a lead author and a short counterpoint from the other. Where the CEO and the CISO see it differently, you get both reads instead of a committee compromise.
The source note names which figures we carried across on NACD's authority and which we checked ourselves. It also names the one big number we threw out, and why.
The principles are what a board owes the company. The tools are what you pull off the shelf when one specific thing lands on the agenda — a ransom demand, a quantum question, a deal in diligence.
Reporting you can't price isn't oversight. What the scenarios cost, in dollars.
The four-day SEC clock, NIS2, nineteen state regimes — and who makes the call at 2 a.m.
Why one cyber director doesn't fix governance, and the three cheaper things that do.
Pick a framework, score honestly, and write down how much risk you'll accept.
Six numbers, trended quarterly. Everything else is a slide with a padlock on it.
A third of breaches now arrive through someone you bought from.
They co-founded the same company and still argue about this. That argument is the book.
Twenty-five years inside the MSP industry — building companies, hiring operators, and watching owners get sold things they didn't need. He wrote The Small Business IT Buyer's Guide for the same reason he wrote his half of this one.
David takes the chapters where the answer is a business decision: pricing the risk, structuring the oversight, and refusing a board pack that can't change a decision.
He opens his first chapter by taking a statistic away from the reader — the $20 trillion loss projection that circulates in vendor decks, which is a forecast stacked on forecasts and doesn't belong in a document demanding rigor.
Daniel takes the chapters with clocks, controls and consequences: disclosure deadlines, risk appetite, supply chain, and the tools you reach for at 11 p.m.
A rewrite that agreed with everything wouldn't be worth reading. These are the substantive departures from the original — all of them named in the handbook's own source note, so you can judge them.
A projection built on projections. It opens a lot of security decks. It doesn't open ours.
The original leaves the “add a cyber director” question open. We rank an independent outside assessment above it — and explain the deference problem one expert can create.
Third-party involvement in breaches doubled to 30% in Verizon's 2025 report. That's the spine of a principle here, not one tool among fifteen.
Polished board reporting is a rational response to how most boards receive bad news. Fix the incentive and the candor follows.
This is original writing and an original argument, derived from the National Association of Corporate Directors and Internet Security Alliance Director's Handbook on Cyber-Risk Oversight, Fifth Edition (2026). It reproduces no text from it. The original is copyright NACD and ISA, it is free to obtain, and we think a serious director should read both.
The handbook's closing source note separates the figures we carried across on NACD's authority from the matters of public record we state on our own reading. It is not legal advice.
The whole handbook, on one page, with a contents rail so you can jump straight to the principle or tool you need. No registration, no gate, no follow-up sequence.