NACD and ISA Release Updated Cyber-Risk Oversight Guide for Corporate Boards
Event summary
- NACD and ISA released the fifth edition of the Director's Handbook on Cyber-Risk Oversight on April 16, 2026.
- The handbook outlines six core principles for board oversight of cyber risk, including treating cybersecurity as a strategic risk and encouraging systemic resilience.
- More than 600 million cyberattacks are tracked daily, with projected annual cybercrime losses approaching $20 trillion.
- The updated edition includes expanded guidance on emerging technologies, supply chain risk, and incident response coordination.
The big picture
Cyber risk has become a central governance issue for corporate boards, with regulators, investors, and stakeholders raising expectations for oversight. The updated handbook from NACD and ISA provides practical frameworks to help directors navigate a rapidly evolving threat landscape, reflecting the growing importance of cybersecurity in strategic decision-making.
What we're watching
- Governance Dynamics
- How boards will integrate the handbook’s principles into their oversight structures and access to expertise.
- Regulatory Headwinds
- Whether the handbook’s guidance will align with evolving regulatory expectations for cybersecurity disclosure and resilience.
- Execution Risk
- The pace at which organizations adopt the handbook’s practical tools for ransomware preparedness, quantum computing, and third-party risk oversight.
Related topics
