Director's Cyber Oversight Kit
What a director should ask, and what a good answer looks like. Twelve questions with the good-answer and weak-answer patterns, the evidence log that proves oversight happened, and the charter, calendar and self-assessment regulators, plaintiffs and insurers now expect. No technical background assumed.
What this actually gives you
- Management presents, directors nod, nothing is verified or recorded. That is the gap NACD-ISA’s 2026 handbook names — "trust but verify" is its third principle.
- The log is the defence. Delaware dismissed the Caremark claims in SolarWinds and Marriott because a reporting system existed and was used; the same opinions said positive-law violations and misleading security statements heighten exposure.
- Regulators now ask about the board itself — SEC Item 106(c) on how directors are informed and what expertise they hold, DFS 500.4 on the senior governing body, and the UK Code, DORA Article 5 and NIS2 Article 20 making the management body liable.
- Each question ships with a good-answer pattern and a weak-answer pattern — the weak ones are the useful half, because they name what a confident non-answer sounds like.
- Question 10 is the agent question. Fortune 100 boards with an AI committee went from 11% to 40% in a year; AI oversight has converged with cyber oversight rather than sitting beside it.
Management presents, directors nod, nothing is verified or recorded. That is the gap NACD-ISA's 2026 handbook names, and "trust but verify" is its third principle. This kit is written for the other side of that table — for a director, a committee chair or a corporate secretary, with no technical background assumed.
The log is the defence. Delaware dismissed the Caremark claims in both SolarWinds and Marriott because a reporting system existed and was used. The same opinions were explicit that positive-law violations and misleading security statements heighten exposure. A board that asks good questions and keeps no record of having asked them is in a materially worse position than one that does — and the record is cheap to keep and impossible to reconstruct afterwards.
Regulators now ask about the board itself, not just the programme. SEC Item 106(c) asks how the board is informed and what expertise it holds. NYDFS 500.4 examines the senior governing body and requires the CISO's annual report. The UK Cyber Governance Code, DORA Article 5 and NIS2 Article 20 make the management body liable and require training. These are questions about directors, and they are answered with documents directors own.
What you get
01 Director's Question Set (DOCX + PDF) — twelve questions, each with a good-answer pattern, a weak-answer pattern, the evidence to ask for and the follow-up that closes it. Mapped to the NACD principles and to the regulatory hook each one satisfies. The weak-answer patterns are the useful half: they name what a confident non-answer sounds like.
02 Oversight Evidence Log (XLSX) — one row per oversight event: what the board asked, what management answered, what evidence was produced, what was decided, the follow-up, and any red flag with its disposition. Shaped around what a Caremark analysis actually looks for.
03 Committee Charter & Expertise Statement (DOCX) — the charter paragraph assigning cyber, technology and AI oversight with CISO access, the escalation clause, and the proxy / Item 106(c) / DFS expertise statement, plus an expertise inventory, an education plan and counsel notes.
04 Annual Oversight Calendar (XLSX) — fifteen items across the year, each with its forum, presenter, regulatory hook and evidence source. Cadence is most of oversight; this makes it a schedule rather than an intention.
05 Board Self-Assessment (XLSX) — 24 statements across the six NACD principles, averaged by principle, ending in development items.
06 Director's Guide (PDF) — the expert nod, what the law asks, what regulators ask, the questions, the evidence log, structure, cadence, incidents, the AI convergence, self-assessment and disclosure, using the kit, failure patterns and an FAQ.
board01.json — question ids, the principle map, calendar items and self-assessment statements.
Question 10 is the agent question. Boards with an AI committee went from 11% to 40% of the Fortune 100 in a single year, and AI oversight has converged with cyber oversight rather than sitting beside it. The question set treats it that way. If the answer to Q10 concerns you, the Agentic AI Security Program Kit is what management should be running.
This is the board layer, deliberately priced below the management kits it points at. The numbers a director should expect live in the Security Metrics & KPI Library; the materiality process behind an 8-K is the SEC 8-K Materiality Workbook; the CISO's annual report and §500.4 examination sit in the NYDFS Part 500 Kit; the exercise a board should observe is the Executive Tabletop Kit. Those are management's tools. This one is yours, and it is a subset by design — you should not need to buy the programme to oversee it.
(Not to be confused with The Twelve, our free one-page reference on the twelve security metrics examiners ask for first. Different twelve, different audience.)
Pairs with I've Been Breached for what the board is told during an incident, and the Cyber Insurance Application Readiness Kit for the coverage questions that reach the audit committee.
A practitioner's toolset, not legal advice. The charter paragraph, escalation clause and expertise statement in file 03 are drafting aids — have counsel review them before adoption, and note that Item 106, DFS 500.4 and the UK Code are all marked "verify" against their current text.
Also available in 3 bundles
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
Board Package
What the board asks, the numbers behind the answers, and the exercise it should watch. The director layer plus the two management tools a board actually sees output from. 19% off buying separately.
Utility Board Package
The regime calendar an operator is judged against, and the twelve questions a director should be asking about it. What management owes the regulator, and what the board records having asked. 15% off buying separately.
Critical Infrastructure Complete
The plant, the regulators above it, the federal reporting duty, the drill and the board layer — five products covering an operator end to end, from the vendor VPN that should already be off to the evidence log a director keeps. 25% off buying separately.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee