Board Advisory Services
Cyber-Risk Oversight
Oversee Cyber Risk in a New Threat Landscape
Escalating threats, new technologies, and a transformed regulatory landscape have created a new cyber-risk reality. Boards must remain vigilant and continuously expand their oversight capabilities to keep pace.
This in-boardroom education program draws on the fifth edition of the NACD-ISA Director's Handbook on Cyber-Risk Oversight (2026). The handbook provides an independently validated framework built on six oversight principles, along with 15 boardroom tools, to give the full board the frameworks and strategies it needs to manage cyber risk effectively. Boards that complete the program receive a certificate of completion in the organization's name that can be referenced in proxy statements.
Learning Objectives
Apply enterprise oversight across all six principles:
Principles 1 & 2
- Evaluate decisions on emerging technologies.
- Clarify the board's role in preparedness and response.
Principles 3 & 4
- Evaluate the board's cyber-risk expertise and establish access to necessary expertise.
- Formalize cyber oversight responsibilities across committees.
- Understand the division of responsibilities between the board and management in addressing cyber risk.
- Evaluate common enterprise cyber risks, including cloud services, insider threats, and third-party and supply chain risk.
Principles 5 & 6
- Leverage business metrics and integrated enterprise risk management to promote cross-functional engagement, collaboration, and governance on cyber risk.
- Oversee systemic resilience planning and high-impact risk scenarios.
- Evaluate reporting and response readiness, including potential cyber-incident reports to regulators and law enforcement.
- Establish a business-aligned cyber-risk reporting structure, including reporting cadence, KPIs, and escalation protocols.
- Promote shared responsibility for cyber risk and engagement with public- and private-sector ecosystem partners.
Who Should Attend
- Full boards of directors of public, private, not-for-profit, and PE-backed companies. The program is designed for institutional adoption, with the certificate of completion awarded to the board as a governing body.
- Board chairs, nominating and governance committee chairs, audit committee chairs, general counsel, corporate secretaries, and directors attend together, since they share accountability for the board's governance.
Available Formats
A two-hour, expert-led workshop, either in person or virtual, that aims to help the board strengthen its cyber-risk oversight, including a focus on incident preparedness and response, committee responsibilities, third-party and supply chain risk, and board-level cybersecurity metrics and reporting.
