National Association of Corporate Directors (NACD) and ISA complete 5th edition of the Cyber Risk Oversight Handbook for Corporate Boards.Written primarily by ISA board members, The Journal of Cybersecurity has called the NACD-ISA Handbook the de facto international standard for corporate oversight of cybersecurity.” The NACD board committee review reports this edition as “transformative.”
Senator James Lankford (R-OK) is guest of honor at ISA board of directors fall Salon dinner. Lankford, a member of the Senate Leadership team, senior Member on the Homeland Security and Intelligence Committees, actively participated in a 2-hour discussion of ISA policy priorities and pledged to engage on the ISA agenda.
ISA Submits to the White House Office of the National Cyber Director (ONCD) its “Zero-Cost Plan for Cybersecurity.” Appreciating the existing political climate ISA proposes to ONCD five priority issues that are politically viable, low/no cost and can provide substantial improvements in cybersecurity. Agenda includes eliminating duplicative cybersecurity regulation, placing all remaining regulation on a cost benefit basis, reauthorizing and modernizing the 2015 Information Sharing Act, Modernizing Workforce development via PIVOTT Act and creating a cyber macro-economic model.
Fulfilling a promise House Homeland Security Committee Chairman Mark Green made to ISA board at 2024 Salon dinner, House Homeland Security Committee approves ISA inspired legislation on workforce development bill. The PIVOTT Act is based on ISA’s proposal to create a virtual cybersecurity academy. White House Cybersecurity Director Cairncross promotes academy prospect in public comments on Administration Cyber strategy. ISA is currently working to adjust the bill in response to AI impacts on the cyber workforce.
Acting on ISA’s urging, the Chairs of the House Oversight and Government Reform Committees and the Homeland Security Committee write a joint letter to OMB Director Vought directing them to “act now” on ISA’s top policy, eliminating duplicative cyber regulations. The letter cosigned by several subcommittee chairs states that “eliminating the duplicative framework of cybersecurity regulations is the fastest and most cost effective to materially improve our nation’s cybersecurity.”
ISA leads industry coalition letter to OMB supporting Housse Committee Chair letter. ISA crafts letter endorsing House Chair call for OMB to use its existing authority to eliminate duplicative cyber regulations. Letter is signed by ISA, Information technology Institute (ITI) Consumer Electronics Association (CEA), Business Software Alliance (BSA) and the “Ap Alliance” The letter advocates using advanced technology to identify regulatory duplication and a new industry government process to create a less redundant core regulation buy date certain.
At the behest of Senator Lankford, ISA circulates to US Senate and House study of incidents in all 50 states where duplicative cyber regulation has compromised effective incident response.
ISA leads Congressional Staff briefings in House and Seante on the need to reauthorize and update 2015 Cybersecurity Information Sharing Act. As Chair of ITSCC Congressional Outreach Committee ISA organizes and leads standing room only briefing for House staff and subsequent well attended briefing for Senate staff on the need to update and maintain the information sharing process authorized by 2015 CISA.
Senator Bernie Moreno (R-OH) is guest of honor at ISA Spring Board of Directors Salon dinner. Board meeting also featured meetings with numerous Chairs of House Committees including Oversight Regulatory Chairman Peter Sessions, Armed Services Vice Chairman Rob Whitman, and Armed Services and Intelligence Committee Member Carlos Gimenez. Rep. Carlos Giménez offered ISA’s cost-benefit analysis proposal as a floor amendment setting the stage for meaningful consideration of ISA proposals.
DHS Cybersecurity and Infrastructure Security Agency (CISA) agrees to endorse the NACD-ISA Handbook. DHS has agreed to provide the forward for the NACD-ISA handbook the fifth time, and spanning 4 different Presidential Administrations.
NACD and ISA Develop Comprehensive, Nation-wide strategy to Promote the NACD-ISA Handbook. NACD and ISA have crafted an extensive promotional campaign which will kick off with a press event in April to be followed by NACD Master classes folding in the handbook, concentrated social and traditional media outreach local events built around the handbook at NACD’s local chapter organizations and involving ISA board members as their schedule allows.
House Armed Services Committee engages with ISA on strategy to use the National Defense Authorization Act to engage the ISA’s 5-point policy agenda. Following supportive meetings with bi-partisan Armed Services Committee staff the Chair of the Cybersecurity Subcommittee meets with the ISA board to discuss the possibility of using the “Solarium Commission model” as a potential vehicle for the ISA policy agenda.
House Armed Services Members Express interest in introducing legislation on ISA policy agenda. Following ISA board meetings with Members of the ‘Armed Services Committee several Members have engaged with ISA to introduce legislation to facilitate a process to include the ISA priorities in next year’s National Defense Authorization Act.
US State Department Funds ISA Participation on Regional cybersecurity conference for Central America in the Bahamas. Continuing a relationship that dates back over 20 years and though 5 Presidential Administrations and 4 continents US State Department funds ISA to represent US private sector at inaugural Central American Regional Cybersecurity Summit. ISA also conducts a variety of private briefings for American and Bahamian government and private sector entities.
World Economic Forum Invites ISA to Lead “Spotlight Session” in Paris its Annual Cybersecurity Summit. Based on ISA blog posting, the Forum asks ISA to lead a session entitled “Are Regulators the New threat Actors?” The session focuses on negative impact of international duplicative cyber regulations.
World Economic Forum releases Report on Corporate Resilience. Report cites ISA international handbooks for corporate bords as tools to be used in building Forum invites ISA to lead Spotlight Session on cybersecurity at their first combined Resilience Summit in the United Arab Emirates focused on the use of cost benefit analysis for international cybersecurity regulation.
ISA Teaches Graduate Class at Wharton School. For the eight consecutive year, ISA offeree a spring class on cybersecurity enterprise risk management for the Stonier Executive Education Program cosponsored by the American Banking Association at the University of Pennsylvania campus.
MIT invites ISA to provide guest lecture at their CAMS Cyber Research Program. ISA, which regularly participates in the MIT series was invited to present was asked to lead s session focused on the need to provide economic incentives to fill the gap in funding cybersecurity in the face of increased, and unbudgeted nation state attacks on critical infrastructure.
ISA Winter Board meeting focuses on impact of Supreme Court’s Loper Bright decision and its impact on potential on cybersecurity regulation. The Loper decision fundamentally changes basis for federal regulation. ISA board meeting consists of series of reports from members on potential Loper impact. This provides ISA with basis for over 40 meetings/briefings on Capitol Hill to assess interest in ISA’s regulatory proposals and suggests OMB as a vehicle for enacting ISA policy without resort to legislation.
ISA issues series of 12 reports for targeted congressional committees documenting nation-state cyber-attacks on virtually all US critical infrastructure. Going beyond the well-known “Typhoon” attacks ISA reports illustrate that the nature of the attacks has changed to a focus on debilitating virtually all US critical infrastructure meaning national security has surpassed consumer protection as the top cybersecurity issue.
ISA Uses Advanced Metrics to Guide Advocacy Effort. Working with long-time partner 1631 Digital ISA is able to track metrics on which congressional and Administration offices are opening ISA reports enabling ISA to more effectively target advocacy efforts.
ISA President Appointed to the Advisory Board of the Howard Baker Foundation’s Advanced Technology Forum. Baker Foundation imitative is designed to facilitate research on the impacts of emerging technologies such as AI and Quantum computing.
Sky-Top TV Announces it will begin Streaming ISA’s TV Program Fixing Cybersecurity on 22 Global Platforms (SLING IN US/CANADA) in January 2026. ISA has already recorded 15 episodes of this program which is inspired by ISA’s award-winning book Fixing American Cybersecurity. Shows already recorded include episodes with ISA board members and sponsor representatives including JR Williamson, Kris Lovejoy, Greg Tuhill and John Houser. ISA programs will stream in sequence with each program streaming 22 times, with a target audience of the “Bloomberg TV” audience. Board members are invited to be featured on future shows.
ISA Significantly Upgrades Staff. This year ISA added Seamus Creighton-Kirk, former staff attorney to the Senate Homeland Security Committee and David Badanes, who previously served as ISA board representative from AES. These additions constitute providing ISA members with the most professional and effective staff in the organization’s 25-year history.