Board governance · Risk oversight

Board-Level Cyber & Geopolitical Risk Playbook by Kai London

Boards are not short of cyber reporting; they are short of reporting they can act on. This playbook supplies the missing half: the questions worth asking, the thresholds that trigger a decision, and the decisions worth agreeing before the pressure arrives.

What the book covers

The questions that work

Board questions that surface real exposure rather than reassurance, with guidance on what a good answer looks like.

Risk appetite made concrete

Translating appetite statements into thresholds, tolerances and named owners.

Pre-agreed decisions

Ransom position, disclosure approach, service degradation, market withdrawal — decided in calm conditions, not during an incident.

Reporting that lasts

A stable dashboard of indicators and assurance evidence, with uncertainty stated honestly.

Director duties and evidence

Oversight expectations under NIS2, DORA and comparable regimes, and the minutes and records that demonstrate diligence.

Exercising the board

Short, realistic scenarios designed for directors rather than for technical teams.

This book provides general guidance on governance practice and is not legal advice; directors should take qualified advice on duties in their own jurisdiction. It is independent and carries no endorsement by or affiliation with any regulator or standards body.

NIS2DORANIST CSF 2.0ISO 31000

Who it is for

Board members and non-executive directors, audit and risk committee chairs, company secretaries, chief risk officers and CISOs preparing board material.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.