Internet Security Alliance
The Internet Security Alliance (ISA) is a non-profit trade association, founded in 2000 and headquartered in Arlington, VA, that publishes cyber-risk and AI governance handbooks for corporate boards, CISOs and policymakers, supported by a corporate membership and sponsorship model and a flagship partnership with NACD.
- Company typePrivate
- Founded2014
- HeadquartersArlington, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Internet Security Alliance does
The Internet Security Alliance (ISA) is a non-profit, membership-based trade association founded in 2000 and headquartered in Arlington, Virginia, that convenes corporate boards, CISOs, policymakers and security vendors around cyber-risk governance. The organization operates in the cybersecurity policy and board-advisory segment, publishing governance frameworks and convening stakeholders rather than selling security software or services. Its core product is a portfolio of cyber-risk oversight publications led by the NACD-ISA Director's Handbook on Cyber-Risk Oversight (now in its 5th edition, April 2026), supported by international handbooks covering the US, European, UK, German, Japanese, Portuguese, Spanish and Latin American jurisdictions, books including 'The Cybersecurity Social Contract' and 'Fixing American Cybersecurity', the NACD Consensus Cyber Risk Oversight Principles, a monthly webinar series, and the Stream Fixing Cybersecurity video program. ISA's business model rests on three revenue mechanics: corporate memberships and sponsorships from enterprise sponsors, one-time publication and handbook sales, and free/freemium policy resources that function as member acquisition and brand-building tools. Pricing is not publicly disclosed; customer acquisition is anchored by the longstanding co-branded NACD partnership, which provides distribution access to 20,000+ corporate directors, supplemented by relationships with government bodies (CISA, FBI, U.S. Secret Service, U.S. Chamber of Commerce), international trade associations (ecoDa, OAS, BSI/ACS, KEIDANREN, WEF) and academic institutions (CMU/SEI, Wharton, MIT). The organization's strategic emphasis in 2024-2026 has been the extension of its governance IP from cyber risk into AI oversight, and the geographic deepening of its handbook franchise through revised European and Latin American editions.
Internet Security Alliance firmographics
Firmographics- Name
- Internet Security Alliance
- Legal name
- Internet Security Alliance
- Website
- https://isalliance.org
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- The Internet Security Alliance (ISA) is a non-profit trade association, founded in 2000 and headquartered in Arlington, VA, that publishes cyber-risk and AI governance handbooks for corporate boards, CISOs and policymakers, supported by a corporate membership and sponsorship model and a flagship partnership with NACD.
- Ownership category
- akta.pro rank
Internet Security Alliance industry classification
Industry- Product category
- Cybersecurity Governance and Policy Advocacy
- NAICS
- National Security (928110)
- SIC
- Services-Membership Organizations (8600)
- akta.pro primary industry
- OT/ICS & Critical Infrastructure Cybersecurity Services (BPAKAHAN)
Keywords
Where Internet Security Alliance is headquartered
LocationHeadquarters
- HQ city
- Arlington
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Internet Security Alliance business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Others
Revenue model
- Corporate Membership and Sponsorship: ISA generates revenue through corporate membership and sponsorship programs. Members include major corporations such as Leidos, AIG, Mastercard, EY, RTX, Centene, Carnegie Mellon, GE Aerospace, L3Harris, McDonald's, GE Vernova, Kyndryl, KBR, and SAP. Sponsors receive access to resources, evaluation tools, and participation in ISA activities.
- Publication Sales: Revenue generated from sale of ISA publications including 'The Cybersecurity Social Contract', 'Cybersecurity for Business', and 'Fixing American Cybersecurity' books available through Amazon and other retail channels.
- Free Resources and Downloads: Core publications including the Director's Handbook on Cyber-Risk Oversight are available free of charge as PDF downloads, supporting the organization's advocacy and thought leadership mission.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free tier - Director's Handbook and toolkit downloads |
| Subscription | Annual | Corporate Membership/Sponsorship |
Go-to-market motion2 records
Distribution channels6 records
Marketing channels8 records
Internet Security Alliance product offering
Product offeringCore offering
Internet Security Alliance (ISA) is a multi-sector trade association that develops and distributes cybersecurity governance frameworks, handbooks, books, and educational programs for corporate boards, government agencies, and critical infrastructure sectors. Its flagship offering, the NACD-ISA Director's Handbook on Cyber-Risk Oversight, provides six core principles and practical toolkits for board-level cybersecurity oversight, with international editions adapted for European, UK, German, Japanese, and Latin American markets.
Product overview
Internet Security Alliance (ISA) operates as a thought leadership and advocacy organization focused on cybersecurity governance, not a software product company. Its portfolio consists primarily of publications (handbooks, books, white papers), educational programs (webinars, executive courses), and recognition initiatives. The core offerings include the Director's Handbook on Cyber-Risk Oversight (produced with NACD), international editions for European/Latin American/Japanese/UK/German boards, and books including Cybersecurity for Business, Fixing American Cybersecurity, and The Cybersecurity Social Contract. ISA also runs monthly NACD-ISA webinar series, streaming video programs, and awards programs. The organization integrates with government agencies (CISA, DHS), international bodies (OAS, WEF), and corporate board organizations but does not offer technical product integrations, APIs, or AI-powered software products.
Differentiator
Problem solved
Functional benefit
Products and services
- Director's Handbook on Cyber-Risk Oversight (5th Edition) Flagship publication co-produced with NACD providing corporate boards with six core principles and toolkits for cybersecurity governance oversight. Available free as PDF download. Currently in its 5th edition (2026).
- Cybersecurity for Business Comprehensive guide published by Bloomsbury Publishing on organization-wide strategies to manage cybersecurity as a strategic business issue. Includes contributions from global leaders in technology, government, and boardroom governance.
- Fixing American Cybersecurity Policy book published by Georgetown University Press advocating for strategic public-private partnership in cybersecurity across seven key economic sectors: health, defense, financial services, utilities/energy, retail, telecommunications, and information technology.
- The Cybersecurity Social Contract Foundational book providing comprehensive assessment of cybersecurity state and market-based approach recommendations. Includes contributions from former DHS Secretary Michael Chertoff, former Director of National Intelligence Admiral Mike McConnell, and other senior cybersecurity leaders.
- International Cyber Risk Handbooks Localized editions of the Cyber-Risk Oversight Handbook for international boards including Pan-European, Portuguese, Spanish, Japanese, UK, and German editions. Developed through partnerships with ecoDa, OAS, and national cybersecurity agencies.
- NACD-ISA AI Recommendations for Corporate Boards New publication released jointly with NACD addressing AI-related cybersecurity oversight guidance for corporate boards of directors.
- Stream Fixing Cybersecurity Video streaming program featuring interviews with cybersecurity executives including Leidos CISO J.R. Williamson on nation-state attacks, corporate cyber warfare, and emerging threats. Available on ORKA TV and FreebieTV platforms.
- NACD-ISA Monthly Webinar Series Monthly webinar series providing toolkits for corporate boards to oversee AI and cyber risk. Covers topics including cyber risk reporting, personal cybersecurity for directors, emerging technology, third-party risk, AI challenges, board-level metrics, incident response, ransomware, CISO relationships, and cloud security.
- Policy White Papers Technical policy publications addressing cybersecurity regulation, market-based models, and public-private partnership frameworks.
- Cyber Risk Oversight Handbook Six guiding principles for board oversight of cyber risk. Includes tools for M&A due diligence, insider threats, supply chain management, incident response, personal security, metrics, and government engagement. Independently assessed by PwC showing dramatic enterprise cybersecurity improvement.
Quantifiable outcome
- 24% boost in security spending when boards participate in cybersecurity budget discussions following handbook guidance
- +2 more outcomes
Companies that use Internet Security Alliance
Customer profileNamed customers14 records
Segments5 records
Ideal customer profiles4 records
Internet Security Alliance technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability1 record
Feature4 records
Internet Security Alliance partnerships and signals
Strategic signalPartnerships
16 partnerships are on record, tiered core, flagship and minor.
- European Confederation of Directors (ecoDa)corePartnership to publish Pan-European Cyber Risk Handbook for boards of directors in Europe. Second edition published in 2024. Handbook developed through collaborative workshops with European corporate governance leaders.
- World Economic Forum (WEF)flagshipGlobal collaboration on cyber principles for boards of directors announced November 2020. WEF and ISA collaboration demonstrates centrality of economics in cybersecurity. ISA President participates in WEF Cybersecurity Summit and Geneva debates. Research documents effectiveness of consensus cyber risk oversight principles.
- Organization of American States (OAS)corePartnership to develop and publish Cyber Risk Handbook for Latin American Boards in Spanish, Portuguese, and English. Launched at OAS Symposium in Santiago in September 2019 with workshops and webinars to adapt handbooks for Latin American corporate boards.
- KEIDANREN (Japanese Business Federation)corePartnership to promote ISA corporate governance cybersecurity principles in Japan and develop Japanese edition of Managing Cyber Risk handbook for Japanese boards of directors.
- Alliance for Cybersecurity (ACS) / German Federal Office for Information Security (BSI)corePartnership to develop Managing Cyber Risk handbook for German Boards of Directors published in 2018. ACS is an affiliate of BSI (German Federal Office for Information Security) and AIG collaborated on the publication.
- National Association of Corporate Directors (NACD)flagshipPrimary strategic partnership for development and distribution of the Director's Handbook on Cyber-Risk Oversight. NACD distributes handbook to 20,000+ corporate director members. Partnership produces monthly LinkedIn Live webinar series and co-authors international editions. Ongoing collaboration since first handbook edition in 2014 with multiple updates through 2026 fifth edition.
- Cybersecurity and Infrastructure Security Agency (CISA)coreCISA Director Jen Easterly awarded ISA her personal Challenge Coin for excellence in promoting national cyber defense. CISA works with ISA on public-private partnership initiatives and critical infrastructure protection. The NACD-ISA handbook was featured on DHS C3 Voluntary Program website.
- U.S. Chamber of CommercecoreLeading coalition partner in cybersecurity policy advocacy. ISA led U.S. Chamber of Commerce, TechAmerica, BSA, and CDT in 2011 coalition that influenced House Republican Cybersecurity Task Force and President Obama's Executive Order 13636.
- Carnegie Mellon University / Software Engineering InstitutecoreGreg Touhill, Director of Software Engineering Institute at CMU and first US Government CISO, contributes chapter to Director's Handbook. Partnership for board education and thought leadership on cybersecurity governance.
- Wharton School, University of PennsylvaniacoreISA Board of Directors team-teaches cybersecurity executive education course at Wharton School. ISA announces all-star faculty from industry including experts from GE and FIS. Course addresses board governance and executive decision-making on cyber risk.
- MITcoreMIT research documents effectiveness of consensus cyber risk oversight principles developed by ISA. MIT hosted conference where WEF and ISA collaboration was highlighted. Partnership for academic validation of cybersecurity governance frameworks.
- AIGcoreOriginal co-publisher of the Cyber-Risk Handbook in 2014 and partner in developing German and UK editions of Managing Cyber Risk handbooks. AIG collaborated with ISA and Alliance for Cybersecurity on international publications.
- DLA PiperminorPartner organization supporting ISA initiatives and programs as part of the broader ISA partner ecosystem.
- American Bar Association (ABA)minorPartner organization supporting ISA cybersecurity governance initiatives for legal and compliance professionals.
- Federal Bureau of Investigation (FBI)minorPartner organization in cybersecurity public-private partnership efforts, particularly around law enforcement coordination on cyber threats.
- U.S. Secret ServiceminorPartner organization in cybersecurity initiatives and critical infrastructure protection programs.
Scale indicators5 records
Recent moves6 records
Expansion highlights4 records
Internet Security Alliance competitors and assessment
Company assessmentDirect peers
- National Association of Corporate Directors (NACD): NACD is ISA's flagship strategic partner and a peer in the corporate director education and governance space. Both organizations serve U.S. corporate boards with governance resources, and they co-publish the Director's Handbook, making NACD the most directly comparable peer.
Broad incumbents
- ISACA: ISACA is a global professional association for IT governance, risk, and cybersecurity professionals. It is comparable to ISA as a non-profit association producing frameworks, certifications, and thought leadership for governance and security practitioners, though ISACA focuses on practitioners rather than boards.
- (ISC)²: (ISC)² is a global non-profit association of certified cybersecurity professionals, comparable to ISA as a membership-based organization producing governance content, training, and credentials in cybersecurity, with overlapping enterprise audiences.
- ASIS International: ASIS International is a membership association for security management professionals, comparable to ISA in its non-profit, member-driven model and focus on standards and guidance for security decision-makers across enterprises.
Emerging players
- Global Cyber Alliance (GCA): GCA is a non-profit international cybersecurity organization that builds partnerships and practical toolkits to reduce cyber risk. Comparable to ISA in its non-profit, multi-stakeholder partnership model and focus on actionable frameworks.
- IT-ISAC (Information Technology Information Sharing and Analysis Center): IT-ISAC is a member-driven non-profit that facilitates information sharing and collective defense among IT-sector organizations. It is comparable to ISA as a non-profit industry alliance producing guidance for cybersecurity risk management across enterprises.
- Cyber Threat Alliance (CTA): CTA is a non-profit organization of cybersecurity vendors and practitioners that share threat intelligence and produce industry guidance. Comparable to ISA in its non-profit membership-driven model addressing systemic cyber risk, though more technical in focus.
- Cloud Security Alliance (CSA): CSA is a non-profit organization that produces widely used cybersecurity frameworks, research, and certifications, with a membership-driven model similar to ISA. While focused on cloud security rather than board governance, CSA competes for the same enterprise cybersecurity thought-leadership mindshare.
Others
- EC-Council: EC-Council is a global cybersecurity certification body known for credentials like the CEH, comparable to ISA in its non-profit-adjacent role producing governance and training content for the cybersecurity profession.
- National Cybersecurity Alliance (NCA): NCA is a non-profit public-private partnership promoting cybersecurity awareness and education, comparable to ISA as a non-profit, multi-stakeholder organization that publishes frameworks and educational content for broad enterprise and public audiences.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Internet Security Alliance social profiles
Digital presenceInternet Security Alliance financial estimates
Financial estimateRevenue estimate
Valuation estimate
Internet Security Alliance leadership team
Management profileNumber of profiles
Profiles1 record
Internet Security Alliance funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Internet Security Alliance M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Internet Security Alliance
What does Internet Security Alliance do?
Internet Security Alliance (ISA) is a multi-sector trade association that develops and distributes cybersecurity governance frameworks, handbooks, books, and educational programs for corporate boards, government agencies, and critical infrastructure sectors. Its flagship offering, the NACD-ISA Director's Handbook on Cyber-Risk Oversight, provides six core principles and practical toolkits for board-level cybersecurity oversight, with international editions adapted for European, UK, German, Japanese, and Latin American markets.
Is Internet Security Alliance a public or private company?
Internet Security Alliance is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Internet Security Alliance founded?
Internet Security Alliance was founded in 2014. It employs 1 to 10 people.
Where is Internet Security Alliance based?
Internet Security Alliance is headquartered in Arlington, United States, in the North America region.
How does Internet Security Alliance make money?
Three revenue lines are on record. Corporate Membership and Sponsorship is the primary driver. The others are publication Sales and free Resources and Downloads.
Who are Internet Security Alliance's main competitors?
National Association of Corporate Directors (NACD) is listed as a direct peer. Broad incumbents are ISACA, (ISC)² and ASIS International. Emerging players are Global Cyber Alliance (GCA), IT-ISAC (Information Technology Information Sharing and Analysis Center), Cyber Threat Alliance (CTA) and Cloud Security Alliance (CSA). Others are EC-Council and National Cybersecurity Alliance (NCA).
Does Internet Security Alliance have an API?
No public API is recorded for Internet Security Alliance.
What industry is Internet Security Alliance in?
Internet Security Alliance's product category is Cybersecurity Governance and Policy Advocacy. Its primary akta.pro industry code is BPAKAHAN, OT/ICS & Critical Infrastructure Cybersecurity Services. Its NAICS code is 928110 and its SIC code is 8600.