
Private-equity operating partners do not sit on every portco board, but they inherit the same problem those boards have: cyber shows up as a strategic risk, a disclosure problem, a third-party problem, and a measurement problem, usually in the same quarter, and rarely with a number anyone can challenge. The 2026 Director’s Handbook on Cyber-Risk Oversight, the fifth edition from the National Association of Corporate Directors and the Internet Security Alliance, is one of the few public documents that treats that pile as a governance job rather than a tool category.
This is not a review of the handbook, and it is not a substitute for reading it. NACD and ISA hold the copyright; the public landing page and table of contents are enough to work from. What follows is the operating-partner translation: which of the six published principles change the questions you ask a portco, and which ones the handbook cannot answer for you.
What the handbook actually is
The 2026 edition presents six independently validated cyber-risk oversight principles and a toolkit for incidents, third parties, and law-enforcement coordination. The public table of contents names them in plain language:
- Treat cybersecurity as a strategic risk.
- Monitor legal and disclosure implications.
- Establish board oversight structures and access to expertise.
- Adopt an enterprise framework for managing cyber risk.
- Guide cybersecurity risk measurement and reporting.
- Encourage systemic resilience and collaboration.
Those are board duties. They are not a loss model. They do not produce a P10–P90 range. They do not tell you which finding to fund first at a manufacturer you closed last Tuesday. If you treat the handbook as a product spec, you will ask the CISO for a “NACD score.” There is no such score in the document, and inventing one would be the opposite of what the authors are arguing for.
The hold-period cut
An operating partner can use the six principles as a 30-minute agenda, not a maturity model.
Strategic risk. Ask whether cyber is on the same page as pricing, labor, and integration — or whether it still arrives as a separate “security update.” If the CEO cannot name the two processes whose interruption would hurt the quarter, the rest of the packet is decoration.
Legal and disclosure. Ask what would have to be true for this company to treat an incident as material, and who owns that call. Public-company rules do not automatically apply to a private portco, but lenders, insurers, and a future buyer will ask the same question. The handbook can remind you the question exists. It cannot make the materiality call.
Oversight structure. Ask who on the portco board actually sees raw evidence, and how often. A quarterly slide with a heatmap is not access to expertise. A named owner who can open source tickets is.
Enterprise framework. Ask which framework the company claims — NIST CSF, ISO, CMMC, something homemade — and whether the evidence file matches the claim. A framework without freshness is a poster.
Measurement and reporting. This is the principle that most often gets faked. “We are green” is not measurement. A challengeable range, with assumptions visible, is. The handbook tells directors to guide measurement. It does not specify FAIR, Monte Carlo, or any vendor method. That gap is the operator’s job.
Systemic resilience. Ask which suppliers can stop the plant or the billing file, and whether those names appear in the same packet as the internal controls. Principle six is where third-party theater usually hides.
What you should not do with it
Do not quote the handbook as if Valty wrote it. Do not tell a portco they are “NACD aligned” unless counsel and the board mean that sentence. Do not turn the six principles into a 1–5 score and put it in an IC memo. The document is guidance for directors; it is not a measurement of your portfolio.
It also does not replace a labeled proof artifact. If you want to see how Valty attaches source, confidence, and a loss-exposure range to one company, inspect the labeled sample. If you want that work done on a live portco, apply as a design partner. The offer is a capacity-capped, one-company sprint, not a portfolio rollout.
Sources
- NACD, 2026 Director’s Handbook on Cyber-Risk Oversight (landing page)
- NACD, 2026 Cyber-Risk Handbook toolkit
Limitations
This note uses the public description and table of contents. It does not reproduce handbook body text, and it does not claim NACD or ISA endorse Valty. Board-oversight principles are not a financial estimate. Any dollar range still has to be built from tenant evidence, with method and insurance treatment visible.


