Welcome to the Board Brief!

Cybersecurity headlines are easy to find. What they require your company to actually do is not.

The InfoSec Board Brief is a free weekly email for founders, executives, security leaders, and board members. Each issue takes one security, privacy, or assurance development and turns it into three things:

  • The decision — what a leadership team actually has to decide, this quarter, because of it

  • The control — the specific operational control to examine, who should own it, and what “working” looks like

  • The evidence — what you should expect to see (and what an auditor, customer, or insurer will ask for) to prove it’s real

Six minutes. No fearmongering. No vendor pitches.

Who it’s for

You’ll get the most out of this brief if you’re a founder, CEO, CFO, general counsel, CISO, or compliance leader at a B2B technology company — especially one selling to enterprise or regulated customers, somewhere between your first security questionnaire and a mature multi-framework compliance program.

Board members are very much part of the audience. “Board-level” here describes the clarity and business relevance of the writing, not a membership requirement.

What a typical issue looks like

Every issue follows the same structure, so you always know what you’re getting: the bottom line up front, what changed, the decision it forces, the control test, the evidence test, three questions you can reuse at your next meeting, and three signals worth watching. Issues rotate across incidents and threats, how controls really work in practice, what audit evidence actually proves, and what boards should measure and challenge — plus penetration testing, cyber insurance, and governance along the way.

Why trust it

This brief exists because most security coverage tells you what happened but not what it requires you to do.

Disclosure: I am the founder of Agency and have a leadership position with AuditSuisse, OnePark Risk, and Auditnex. This publication reflects my analysis and is for educational purposes. It is not legal advice, an audit opinion, or a guarantee of compliance or audit results.

Free subscription

The InfoSec Board Brief is 100% free. If an issue is useful, the best thing you can do is forward it to the person who owns that control at your company — or reply with the question you want covered next.

Free Subscription

100% free to subscribe!

User's avatar

Subscribe to The InfoSec Board Brief

An insider cybersecurity and compliance intelligence briefing for board members about essential GRC frameworks like ISO 27001, GDPR, HIPAA, PCI, SOC2, CMMC, NIST 800-171, and others.

People