06/15/2026
Join SEI CERT Division director Gregory Touhill Tuesday, June 23, for the LinkedIn Live session "Cybersecurity Oversight: What Boards Should Expect From a Cyber Risk Report."
Boards are getting more cybersecurity information than ever. But volume isn't insight.
Effective cyber-risk oversight depends on reporting that helps directors understand what's actually at risk, how management is responding, where accountability sits, and which decisions truly require board-level attention.
That's the focus of the opening LinkedIn Live session on the 5th Edition of the NACD Director's Handbook on Cyber-Risk Oversight, co-produced by NACD and the Internet Security Alliance.
The conversation zeroes in on one of the Handbook's most practical resources: Tool-Kit L, "Example Cybersecurity Board Reporting"--written by Touhill--and its connection to Principle 1, "Treating Cybersecurity as a Strategic Risk." We'll dig into what effective reporting should include, what directors should expect from security leadership, and how better reporting moves boards from passive updates to active oversight.
Moderated by Dylan Sandlin, Program Manager for Digital and Cybersecurity Content at NACD (National Association of Corporate Directors), the session features:
- Larry Clinton — President of the Internet Security Alliance.
- Brig. Gen. Gregory Touhill, USAF (Ret.) — the first Federal CISO of the United States, Director of the CERT Division at Carnegie Mellon's Software Engineering Institute, and ISA board member.
- Andrea Bonime-Blanc, JD/PhD — Founder and CEO of GEC Risk Advisory, bringing the director's perspective on how boards can ask sharper questions, assess business impact, and strengthen enterprise resilience.
https://www.linkedin.com/events/7467247421270622209/