Monthly Chapter Release — Starting July 27, 2026
Board Defensible:

The CISO's 12-Step Guide to Building a Board Defensible AI Governance Program

Written by a 3x Fortune 500 CISO, with practical insight from CISO’s of MassMutual, Pure Insurance & More. This book is the practitioner blueprint, built from real CISO conversations, mapped to NIST AI RMF, and structured so every chapter stands up to board scrutiny, auditors and regulators.
Written by a 3x Fortune 500 CISO.
For CISOs & Team Leads
Free
Framework
NIST AI RMF Aligned
Framework
July 27, 2026
A CISO Next Gen™ Publication

The community where security leaders share what actually works.

CISO Next Gen is a curated community and media platform for senior security leaders navigating the most consequential decisions in enterprise security. Founded by Moriah Hara, a 3x CISO who ran some of the largest financial institutions in the world, it bridges the gap between technical practitioners and the boards, auditors, and regulators they report to.
CISO community members
3,000+
CISO's from Fortune 500 to high-growth startups
Matrix framework launch
Q3 '26
AI governance framework launching soon.
AI RMF aligned
NIST
Regulator Aligned Auditor Reviewed
Board Defensible is the first publication from CISO Next Gen a 12-chapter serialized field guide released monthly, pairing practitioner implementation depth with board-ready language, templates, and tools.
The 12-Step Framework

One chapter. Every Month.

Each chapter maps directly to a pillar in the CISO Next Gen AI Security Matrix - practical enough for your security team, credible enough for your board.
To be released July 27, 2026
You Can't Govern What You Can't See
Chapter 01
You Can't Govern What You Can't See
Pillar: Inventory & Visibility
Coming Soon
Not All AI Is Equal
Chapter 02
Not All AI Is Equal
Pillar: Use-Case Risk Classification
Coming Soon
Your Data Is the Real Risk
Chapter 03
Your Data Is the Real Risk
Pillar: Data Security, Lineage & Provenance
Coming Soon
Who — and What — Has Access
Chapter 04
Who — and What — Has Access
Identity, Access & Agent Governance
Coming Soon
Your Vendors Are Your Attack Surface
Chapter 05
Your Vendors Are Your Attack Surface
Third-Party & AI Supply Chain
Coming Soon
The Model Is the Weapon
Chapter 06
The Model Is the Weapon
Model & Agentic Security
Coming Soon
Writing Rules That Actually Work
Chapter 07
Writing Rules That Actually Work
Policy Enforcement & Controls
Coming Soon
Watching the Machine
Chapter 08
Watching the Machine
Model & Agent Behavior Monitoring
Coming Soon
When Things Go Wrong
Chapter 09
When Things Go Wrong
AI Resilience & Incident Response
Coming Soon
The Regulator Is Coming
Chapter 10
The Regulator Is Coming
Legal, Compliance & Regulatory Alignment
Coming Soon
Humans Still Need to Be in the Loop
Chapter 11
Humans Still Need to Be in the Loop
Human Oversight & Accountability
Coming Soon
The Board Deserves the Truth
Chapter 12
The Board Deserves the Truth
Board Reporting & Education
"This book is designed to help every CISO move from AI uncertainty to AI confidence"
Moriah Hara
3x F500 CISO, Founder, CISO Next Gen™
0
CISO community members
0
Chapters
0
Monthly Releases
0
Board Tools

Moriah Hara

3x F500 CISO, Founder, CISO Next Gen™
Moriah is Founder of CISO Next Gen-A Community and Media Platform built by CISO's for CISO's to enable them to thrive, not just survive in their roles. Background: Moriah founded the first threat intelligence team at Bank of America, created the global payment card security program (PCI QSA) and has been a CISO at Wells Fargo and BMO Financial. She is an ISE distinguished CISO Award Winner, co-author of The Perfect Scorecard: Getting an “A” in Cybersecurity from Your Board of Directors' and has been recognized by Cybercrime Magazine as one of the Top 100 Fascinating Women Fighting Cybercrime. She is a frequent speaker at events hosted by Google, FINRA/SIFMA, The Wall Street Journal, and Bloomberg.
Board Defensible is the synthesis of hundreds of CISO conversations, real program implementations, and the hard-won recognition that no vendor solves this end to end.
Active advisor to Fortune 500 security leaders, analyst firms and select providers.
Founder of the CISO Next Gen community, newsletter, and AI Security Matrix
NIST AI RMF practitioner and AI governance framework architect
Regular contributor to enterprise AI security research and PE due diligence
Board-Ready Resources

The tools your board actually needs

Every template, guide, and exercise is designed to be handed directly to a board member, audit committee, or legal counsel — no translation required.
Board-Ready Resources
AI Risk Board Briefing Template
Plug-and-play board presentation covering AI risk exposure, control status, regulatory posture, and decisions needed.
Exercise Guide
AI Tabletop Exercise Guide
A structured 3-hour tabletop walking leadership and the board through an AI incident — model manipulation, agent failure, or data exfiltration.
Dashboard
AI Security KPI Dashboard
The 15 metrics your board should track — AI asset inventory coverage, agent permission hygiene, model drift rates.
Checklist
Regulatory Readiness Checklist
Cross-referenced against EU AI Act, NIST AI RMF, SEC cybersecurity rules, and HIPAA.
Template
AI Vendor Due Diligence Questionnaire
50 questions to ask any vendor whose product uses AI — training data, explainability, retention, subprocessor disclosures.
Assessment
AI Governance Maturity Model
Self-assessment across all 12 pillars from Initial to Optimized. Produces a board-ready maturity heatmap.
Playbook
AI Incident Response Playbook
Step-by-step IR procedures for AI-specific incidents — prompt injection, model manipulation, autonomous agent failure.
Guide
Board AI Literacy Guide
Plain-language explainer for board members. Covers AI risk categories, oversight in practice, and questions every board should ask.
Board-Ready Resources
AI Risk Board Briefing Template
Plug-and-play board presentation covering AI risk exposure, control status, regulatory posture, and decisions needed.
Exercise Guide
AI Tabletop Exercise Guide
A structured 3-hour tabletop walking leadership and the board through an AI incident — model manipulation, agent failure, or data exfiltration.
Dashboard
AI Security KPI Dashboard
The 15 metrics your board should track — AI asset inventory coverage, agent permission hygiene, model drift rates.
Checklist
Regulatory Readiness Checklist
Cross-referenced against EU AI Act, NIST AI RMF, SEC cybersecurity rules, and HIPAA.
Template
AI Vendor Due Diligence Questionnaire
50 questions to ask any vendor whose product uses AI — training data, explainability, retention, subprocessor disclosures.
Assessment
AI Governance Maturity Model
Self-assessment across all 12 pillars from Initial to Optimized. Produces a board-ready maturity heatmap.
Playbook
AI Incident Response Playbook
Step-by-step IR procedures for AI-specific incidents — prompt injection, model manipulation, autonomous agent failure.
Guide
Board AI Literacy Guide
Plain-language explainer for board members. Covers AI risk categories, oversight in practice, and questions every board should ask.