Governing Cyber Risk
in the AI Era

Are your board meetings governing cyber and AI risk — or simply receiving updates?

R.J. MacEoin is the creator of PRISM Assure™ — the operating model for continuous cyber and AI assurance, built for boards, executives, and the risk professionals who support them.

Commissioned through the Royal Military Academy Sandhurst, he served as Global Cyber Regulatory Lead for Western Union and Security Lead at Sumitomo Trust Funds Ltd, having earlier advised clients at PwC. He holds the CISSP and GDSA, and advises boards across financial services, technology, and professional services on cyber governance and risk.

Governing Cyber Risk in the AI Era by R.J MacEoin

Most boards receive cyber reports. Few receive cyber evidence.

Cyber and AI risk are now board-level accountability issues. Yet many organisations still rely on retrospective reports, annual audits, and dashboards that show activity rather than assurance.

For Boards & Directors

A clearer way to govern cyber and AI risk — and build a defensible record that oversight was active, informed, and evidence-based.

For CISOs & Security Leaders

A structured assurance model built around control effectiveness, risk appetite, and evidence — not reporting theatre — and a way to connect cyber and AI security directly to business strategy in the language of boards and executives.

For Governance Practitioners

A way to move up the value chain as AI automates the compliance workflows their careers were built on.
board cyber oversight diagnosticsFREE RESOURCES

The Board Cyber & AI Agenda

The 7+1 Key Risk Indicators set out as a standing agenda for cyber and AI oversight — seven universal threat domains plus a dedicated AI indicator. One page per indicator: what it covers, the question the board asks, what “good” looks like, and what a Red status obliges the board to decide.

  • One page per KRI, ready for the next risk committee
  • A dedicated AI risk indicator — governing AI adoption, not just cyber
  • The question to ask, and the answer that should come back
  • A self-check per indicator — see your own cyber and AI gaps as you read
  • “Red means decision” — the escalation protocol in full

Prep in minutes

Spot AI blind spots

Know Red’s call

kpi-to-control-proof catalogueFREE RESOURCES

KPI-to-Control-Proof Catalogue

The implementation layer for the PRISM Assure model — the workbench for practitioners, the specification for executives. Every indicator, cyber and AI alike, mapped down to the evidence that proves the control is working.

  • All 7+1 KRIs, with KPIs mapped to CIS Controls v8.1 and NIST SP 800-53
  • OWASP GenAI Data Security 2026 mapping for the +1 AI indicator
  • Control Proof formats — what evidence looks like, who produces it, how often
  • Ownership guidance and board-ready threshold language

Every KRI, mapped

AI backed by OWASP

Evidence, not guesswork

Two production-ready tools for governing cyber and AI risk

One for the boardroom, one for the people who have to produce the evidence behind it. Both cover cyber and AI in the same model.

Both tools are free. Your details are used solely to deliver them — you will hear from us again only if you ask to.

Register once. Access both and more for the future.

No cost, no obligation. Unsubscribe at any time.
My mission is to foster open, meaningful conversations with boards and executives around AI and cyber risk, while empowering security teams to focus on what matters most — protecting the organisation.

Available now on Amazon — start building defensible cyber oversight today.

Available-now-on-Amazon-—-start-building-defensible-cyber-oversight-today.-Prism-Assure-by-R.J-MacEoin

The free tools give you the starting point. The book gives you the full operating model — why the chain from board intent to operational proof is missing in most organisations, and how to build it end to end for both cyber and AI risk.

Move beyond theory and implement a governance model that stands up to scrutiny: board-approved risk appetite, the 7+1 indicators, the KPIs beneath them, and the evidence that proves controls are working.

Order on amazon now
The AUthor

R.J. MacEoin

R.J. MacEoin is the creator of PRISM Assure™ — the operating model for continuous cyber and AI assurance, built for boards, executives, and the risk professionals who support them.

Commissioned through the Royal Military Academy Sandhurst, he served as Global Cyber Regulatory Lead for Western Union and Security Lead at Sumitomo Trust Funds Ltd, having earlier advised clients at PwC. He holds the CISSP and GDSA, and advises boards across financial services, technology, and professional services on cyber governance and risk.

Free resources