A Handbook in Washington, a Law in Singapore: The Governance Gap PMOs Actually Fill

Two documents delivered in 2026 that both claim to tell a board how to govern cyber risk. One is a handbook. The other is law. The distance between the two is where most PMOs currently sit, translating voluntary best practice into something a director can actually be held to.

The Handbook: Comprehensive, Voluntary, US-Focused

In April 2026, the National Association of Corporate Directors and the Internet Security Alliance released the fifth edition of the Director’s Handbook on Cyber-Risk Oversight. It is thorough. Six principles cover treating cyber security as a strategic risk, monitoring legal and disclosure exposure, building board oversight structures, adopting an enterprise risk framework, guiding measurement and reporting, and encouraging systemic resilience. It cites more than 600 million tracked cyberattacks a day and projected annual cybercrime losses approaching 20 trillion dollars globally. What it does not do, because it is guidance rather than statute, is compel a single board anywhere to act on any of it.

 

The Law: Narrower, Binding, and Personal

Singapore closed that gap for its own critical infrastructure operators in 2026 with an updated Cybersecurity Code of Practice. Boards of operators across eleven sectors, energy, telecommunications, water, healthcare, banking, aviation, maritime, government and more, must now maintain a documented resilience framework covering risk tolerance, mitigation, transfer and recovery, reviewed at least annually. Certification deadlines follow in December 2026 and December 2027. Directors can face personal liability where a company fails to prevent or properly respond to an incident because of a lack of the skill, care or diligence the role required. That is a materially different proposition from reading a handbook. It converts board oversight from a best-practice expectation into a standard a director can be judged against.

 

The Gap Between Them Is Where PMOs Live

Most organisations operating internationally will encounter both models at once, comprehensive American guidance describing what good oversight looks like, and a narrower but binding Asian regulatory standard describing what oversight is legally required to look like. Neither one, on its own, tells a PMO what to actually build. The handbook is too broad to implement directly. The code is too sector-specific to generalise from. The practical work, translating six abstract principles into a working reporting cadence, a named accountable owner, and evidence a board can point to if asked, sits squarely inside the PMO’s remit rather than the CISO’s alone or the board’s alone.

 

What a PMO Should Build From Both

A credible cyber governance structure borrows the handbook’s breadth and the code’s specificity. That means a documented framework reviewed at a fixed interval, not an annual slide nobody revisits, a named board-level owner who can answer for the organisation’s posture in plain language, and evidence, tested and dated, that oversight was real rather than assumed. Boards do not need another handbook to read. They need proof that what the last one said actually happened.