Board Package
What the board asks, the numbers behind the answers, and the exercise it should watch. The director layer plus the two management tools a board actually sees output from. 19% off buying separately.
What this actually gives you
- The questions asked, the numbers presented, and the one time a year the board watches the plan tested rather than described.
- For a vCISO or corporate secretary packaging the whole board layer, not for one director — the oversight kit alone is the single-director purchase.
- Owning all three keeps the questions, the evidence and the rehearsal consistent with each other, which is what a Caremark analysis actually examines.
A board meeting has three moving parts: the questions asked, the numbers presented, and the one time a year the board sees the plan tested rather than described.
Director's Cyber Oversight Kit — twelve questions with good-answer and weak-answer patterns, the evidence log that proves oversight happened, and the charter, calendar and self-assessment that Item 106(c), DFS 500.4 and the UK Code now reach.
Security Metrics & KPI Library — 86 defined metrics with formulas, source systems, starting targets and an anti-gaming note each, plus the twelve to start with at any maturity and a dashboard that rolls one data-entry sheet into board, exec and ops views.
Executive Tabletop Kit — the exercise, with the facilitator material to run it and the readout the board should receive afterwards.
Why the three, and who buys them. This is the pack for a vCISO or corporate secretary packaging the whole board layer rather than for one director. The oversight kit is written for the people asking; the metrics library is where the answers come from and is the fastest way to stop a board being shown patch counts; the tabletop is the annual event that converts a plan into something the board has actually watched work. Owning all three means the questions, the evidence and the rehearsal are consistent with each other — which is exactly what a Caremark analysis is looking at.
Two tiers, because the metrics library and the tabletop kit are sold as practitioner or MSSP licences rather than organisation ones.
What's in this bundle
Director's Cyber Oversight Kit
What a director should ask, and what a good answer looks like. Twelve questions with the good-answer and weak-answer patterns, the evidence log that proves oversight happened, and the charter, calendar and self-assessment regulators, plaintiffs and insurers now expect. No technical background assumed.
Security Metrics & KPI Library
Stop reporting patch counts. 86 defined metrics with formulas, source systems, starting targets and an anti-gaming note each, mapped to CSF 2.0 / ISO 27001 / CIS v8 / SOC 2 and to the regimes that pull them — plus the twelve to start with at any maturity, a protection-level sheet that turns targets into priced decisions the board owns, and a dashboard that rolls one data-entry sheet into board, exec and ops views.
Executive Tabletop Exercise Kit
Eight board-ready scenarios, ninety minutes each — 64 injects that each name the decision they force and the question to ask the room, a decision log that pre-fills and scores itself on time-to-decide, and an after-action report carrying the regulatory evidence statement for NYDFS 500.16(d), DORA Art. 11 and NIS2 Art. 20. A billable engagement in a box.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee