Board-Level Cyber & Geopolitical Risk Playbook by Kai London
Boards are not short of cyber reporting; they are short of reporting they can act on. This playbook supplies the missing half: the questions worth asking, the thresholds that trigger a decision, and the decisions worth agreeing before the pressure arrives.
What the book covers
The questions that work
Board questions that surface real exposure rather than reassurance, with guidance on what a good answer looks like.
Risk appetite made concrete
Translating appetite statements into thresholds, tolerances and named owners.
Pre-agreed decisions
Ransom position, disclosure approach, service degradation, market withdrawal — decided in calm conditions, not during an incident.
Reporting that lasts
A stable dashboard of indicators and assurance evidence, with uncertainty stated honestly.
Director duties and evidence
Oversight expectations under NIS2, DORA and comparable regimes, and the minutes and records that demonstrate diligence.
Exercising the board
Short, realistic scenarios designed for directors rather than for technical teams.
This book provides general guidance on governance practice and is not legal advice; directors should take qualified advice on duties in their own jurisdiction. It is independent and carries no endorsement by or affiliation with any regulator or standards body.
Who it is for
Board members and non-executive directors, audit and risk committee chairs, company secretaries, chief risk officers and CISOs preparing board material.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.