Governance, Risk and Resilience by Kai London
Controls are only half the job. Volume 4 is about accountability — quantifying cyber risk in terms a finance director recognises, running a certification and regulatory programme without drowning in evidence, and giving a board something it can genuinely challenge.
Available on Amazon.
What is inside
The board's role
What directors are actually accountable for, the questions they should be asking, and how to answer them briefly.
Cyber risk quantification
Moving from red-amber-green to loss estimates that can be compared with other business risks.
Management systems that work
ISO/IEC 27001 and NIST CSF 2.0 implemented as an operating rhythm rather than an audit exercise.
Regulation: NIS2 and DORA
Scope, obligations, incident reporting timelines and third-party requirements, translated into owned actions.
Operational resilience
Important business services, impact tolerances, and testing that resilience is real rather than asserted.
Crisis command and assurance
Decision rights under pressure, executive exercising, and the assurance pack that shows controls were operating.
Who it is for: CISOs and heads of technology risk, board members and audit committee chairs, compliance and internal audit teams, and resilience leads in regulated sectors.
A control you cannot evidence is an opinion. Governance is the discipline of turning opinion into proof.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.