NACD and ISA Release Updated Cyber-Risk Oversight Guide for Corporate Boards

  • NACD and ISA released the fifth edition of the Director's Handbook on Cyber-Risk Oversight on April 16, 2026.
  • The handbook outlines six core principles for board oversight of cyber risk, including treating cybersecurity as a strategic risk and encouraging systemic resilience.
  • More than 600 million cyberattacks are tracked daily, with projected annual cybercrime losses approaching $20 trillion.
  • The updated edition includes expanded guidance on emerging technologies, supply chain risk, and incident response coordination.

Cyber risk has become a central governance issue for corporate boards, with regulators, investors, and stakeholders raising expectations for oversight. The updated handbook from NACD and ISA provides practical frameworks to help directors navigate a rapidly evolving threat landscape, reflecting the growing importance of cybersecurity in strategic decision-making.

Governance Dynamics
How boards will integrate the handbook’s principles into their oversight structures and access to expertise.
Regulatory Headwinds
Whether the handbook’s guidance will align with evolving regulatory expectations for cybersecurity disclosure and resilience.
Execution Risk
The pace at which organizations adopt the handbook’s practical tools for ransomware preparedness, quantum computing, and third-party risk oversight.