The insight behind it
NIST agrees with us — it just took until 2024 to say so
The Cybersecurity Framework ran for a decade on five functions — Identify, Protect, Detect, Respond, Recover — all technical, all silent on who's accountable. In 2024, NIST CSF 2.0 finally added a sixth function, Govern, at the centre of the wheel.
- That's an admission a framework without leadership built in was incomplete the whole time.
- CSISC didn't wait for the standard to catch up — being the "Govern" function is the entire reason an Executive Cyber Leader exists.
- The Command Model doesn't replace NIST, ISO 27001 or Cyber Essentials — it's the operating rhythm that sits around them.
The model
Six Directives, one continuous cycle
Decide and Demonstrate bookend the other four — deliberately. They're the only two directives the board directly touches. Discover, Direct, Defend and Debrief are the engine; Decide and Demonstrate are the steering wheel and the dashboard.
Decide Read more →
Set risk appetite and priorities — what gets funded, what gets accepted.
Discover →
Map the real risk: assets, data, third parties, obligations.
Directive 03Direct →
Turn the decision into a costed, sequenced roadmap and direct its delivery.
Directive 04Defend →
Live monitoring, detection, and incident response.
Directive 05Debrief →
After every incident, real or simulated: what happened, what changes.
Demonstrate Read more →
Package it into evidence: board packs, audit readiness, certification proof.
What each directive is really asking
The question your board should be able to answer at every stage
Who's accountable?
- Who is deciding what level of risk this organisation is willing to accept?
Do we know?
- Do we actually know what needs protecting, and what threatens it?
Is it aimed right?
- Is our roadmap protecting the things that matter most — or just the easiest wins?
Would we know?
- Would we know if a serious attack was happening right now?
Did we learn?
- Did anything actually change after our last incident, or our last test?
Can we prove it?
- Could we evidence our security governance to a regulator, insurer or acquirer tomorrow?
How it maps
Fully compatible with the standards you already report against
The Command Model isn't a replacement for NIST, ISO 27001 or Cyber Essentials — it's the leadership layer wrapped around them. Every directive traces back to a recognised control area.
| Directive | What it means | Standard equivalent |
|---|---|---|
| Decide | The board sets risk appetite and priorities | NIST CSF 2.0 — Govern |
| Discover | Map the real risk: assets, data, third parties, obligations | NIST CSF — Identify |
| Direct | Turn the decision into a costed, sequenced roadmap | NIST CSF — Protect |
| Defend | Live monitoring, detection, and incident response | NIST CSF — Detect + Respond |
| Debrief | Formal review after every incident, real or simulated | NIST CSF — Recover |
| Demonstrate | Evidence: board packs, audit readiness, certification proof | NIST CSF 2.0 — Govern |
Public sector, critical-service and healthcare organisations: the same six directives map cleanly onto the NCSC Cyber Assessment Framework's four objectives too — Decide and Demonstrate sit under CAF Objective A (managing security risk), Direct under Objective B (protecting against attack), and Defend and Debrief span Objectives C and D (detecting events and minimising impact).
Why it's different
This isn't NIST with new labels
Directives, not pillars
Pillars are static — built once, leaned on. Directives are active and ongoing, issued by leadership — language that matches what an Executive Cyber Leader actually does.
A genuinely different shape
Two governance directives bracket four operational ones. That structure is the IP — not a synonym swap for Identify/Protect/Detect/Respond/Recover.
Teachable in one sentence
Decide what matters, discover and direct the response, defend and debrief when something happens, demonstrate it to the board — then decide again.
Coming from the Command Model
The Board Assurance Score™
A short diagnostic across the Six Directives, scored 0–100 — a single, board-ready number for how ready your organisation's leadership, not just its technology, is for a security incident.
How maturity is scored
Three stages, assessed against each directive
The goal isn't maximum security everywhere — it's the right level of maturity for your organisation's actual risk profile.
Foundation
Basic capability exists, but it's informal, undocumented, or dependent on one person.
Managed
Ownership, process and controls are established, documented, and consistently followed.
Advanced
Risk is continuously measured, governed and improved — evidenced, not just believed.