Cybersecurity Risk & Compliance · The Practitioner Series

Understand the system. Govern the risk. Make the decision.

A practitioner-led professional library about how cybersecurity governance, risk, controls, assurance and compliance actually work together inside real organizations.

Certifications teach you the framework.
This series teaches you how to actually use it.
Two practitioner volumes · €19.99 each · Protected PDF · Worldwide
Cybersecurity Risk & Compliance — The Practitioner Series, Books I and II

Book I builds the security governance system. Book II turns cybersecurity risk into accountable decisions.

Book I — The Foundations

The foundation before the framework.

Book I begins with the organization itself: what matters, what creates exposure, who owns risk, who has authority to decide, how governance works, what controls are meant to achieve, what evidence proves, and how assurance and feedback keep the system alive.

01

Business & Security Context

Connect objectives, assets, information, services and protection needs.

02

Risk as Decision Logic

Move beyond register administration into ownership, appetite, treatment and accountable decisions.

03

Governance & Accountability

Understand authority, decision rights, escalation, challenge and governance forums.

04

Controls & Operations

See controls as mechanisms that must be designed, implemented, operated, tested and improved.

05

Evidence & Assurance

Distinguish evidence of activity from confidence that the intended outcome is actually achieved.

06

Compliance & Improvement

Place external requirements inside the governance system and close the loop through monitoring and feedback.

Book I — The Foundations front cover
Available now

Book I — The Foundations

First Edition · Version 1.0
For practitioners, aspiring GRC professionals, security leaders, auditors, risk professionals and readers who want to understand the system behind the frameworks.

  • 11 practitioner-focused chapters
  • Original visual governance models
  • Practical toolkits, diagnostics and decision structures
  • Glossary and standards/references
  • Individually protected digital PDF
  • Worldwide direct delivery
Digital Edition · €19.99
View contents
Your protected digital edition: Each completed purchase is intended to receive its own individually protected copy of Book I and a unique cryptographically generated unlock key. The key is issued only for that purchase and is never reused for another customer. Paddle provides the payment confirmation and invoice; the protected book and unlock instructions are delivered separately after successful payment.
Book II — Risk & Decision-Making front cover
Available now
Book II — Risk & Decision-Making

The risk register was never the destination.

First Edition · Version 1.0 · 364 pages
Cybersecurity risk is not a number. A technical finding is not automatically a business risk. A control existing does not prove that it works. Book II follows risk from the first signal through business context, analysis, controls, residual exposure, appetite, authority, challenge and ultimately the accountable decision.

A risk register records risk. Governance decides what to do about it.
  • 63 practitioner-focused chapters across 10 connected parts
  • Risk identification, analysis and business impact
  • Control effectiveness, inherent, current, target and residual risk
  • Risk appetite, tolerance, ownership and decision authority
  • Treatment, acceptance, transfer, avoidance and escalation
  • Challenge, decision quality, governance forums and reporting
  • Real-world scenarios and practitioner application
  • Individually protected digital PDF with unique unlock key
Digital Edition · €19.99
Explore Book II
Your protected digital edition: Each completed purchase receives its own individually protected copy and unique cryptographically generated unlock key. Paddle handles payment, tax calculation and invoicing; the protected book and unlock instructions are delivered separately after successful payment.
Inside Book II

From risk signal to accountable decision.

Ten connected parts move from understanding risk to building a working decision system — then put that system into the practitioner's hands.

I

Understanding Risk

Separate technical findings from business risk and frame the decision that actually matters.

II

Building the Risk Picture

Identify exposure, analyze uncertainty and understand business impact.

III

Controls & Residual Risk

Test what controls really change and challenge unsupported target residual risk.

IV

Appetite, Tolerance & Authority

Connect exposure to ownership, decision rights and organizational boundaries.

V–VI

The Decision & Its Challenge

Treat, accept, transfer, avoid or escalate — and make the decision defensible under challenge.

VII–X

The Operating System

Governance forums, reporting, real-world risk, decision-system design and practitioner application.

Inside Book I

Eleven chapters. One connected system.

Contents

  1. 01 — What Cybersecurity Risk & Compliance Actually Means
  2. 02 — Security Governance vs. Compliance
  3. 03 — Building a GRC Operating Model
  4. 04 — Security Strategy & Objectives
  5. 05 — Roles, Responsibilities & Accountability
  6. 06 — Policies, Standards, Procedures & Guidelines
  7. 07 — Risk Appetite & Risk Tolerance
  8. 08 — Governance Committees & Decision-Making
  9. 09 — Metrics, KPIs & KRIs
  10. 10 — Security Maturity
  11. 11 — Monitoring, Feedback and Continuous Improvement

What makes it different

The book does not treat governance, risk, compliance, controls and assurance as isolated disciplines. It progressively connects them into one feedback-driven security governance system.

The visual models become more interconnected as the reader progresses, culminating in the complete foundational model in Chapter 11.

The Practitioner Series

One system. A growing professional library.

Book I establishes the security governance system. Book II takes that foundation into cybersecurity risk and the accountable decisions that follow. Each volume stands on its own while extending one connected practitioner methodology.

AVAILABLE
Book I

The Foundations

Understand the security governance system and the relationships between context, risk, authority, controls, evidence, assurance, compliance and improvement.

AVAILABLE
Book II

Risk & Decision-Making

Turn cybersecurity risk into accountable decisions — from identification and business impact through controls, residual risk, appetite, authority, challenge and practitioner application.

Limited project availability

Short-Term Security Governance & GRC Engagements

I remain unavailable to the employment market. I am, however, opening limited availability for defined, outcome-based security governance engagements: a clear problem, a clear scope, a usable result, and a clean handover.

01 · 12–16 WEEKS

Security Governance Build

Build or rebuild a security governance environment from the ground up: governance framework, policy architecture, roles and decision rights, risk and exception processes, control requirements, security governance documentation, stakeholder validation and operational handover.

02 · 4–8 WEEKS

GRC / Security Framework Sprint

A focused intervention for a defined governance problem: policy framework, risk governance, ISO 27001 / TISAX / assurance readiness, business continuity and resilience governance, supplier security, control governance or another agreed work package.

03 · 1–3 WEEKS

Independent Security Review

An independent challenge of an existing security governance model, framework or document set, followed by prioritized findings, decision points and a practical remediation path for management.

Delivery model: Define → Build → Validate → Handover → Exit.

Typical deliverables can include policy suites, governance and responsibility models, risk and exception structures, security requirements, audit and assurance readiness, operating-model documentation and final security architecture / governance documentation. Scope is agreed before delivery; engagements are temporary rather than open-ended employment arrangements.

Remote engagements worldwide / Europe. Availability is limited and subject to scope, timing and fit.

The platform

The shop is only the first room.

nadyabiserova.com is designed to grow into a practitioner knowledge platform — not remain a one-book landing page.

📚

Library

Articles, models, practitioner notes and selected public resources.

🎓

Learning

Structured lessons, toolkits, scenarios and teaching material derived from the practitioner methodology.

🎬

Entertainment

Original creative and AI-assisted media projects, clearly separated from the professional learning catalogue.

🌍

Languages

English is live first. Russian and German editions are planned as professionally localized releases.

Nadya Biserova
About the author

Nadya Biserova

Independent Security Governance & GRC Leader and author of Cybersecurity Risk & Compliance — The Practitioner Series.

Her professional work spans security governance, enterprise risk, ISO 27001, TISAX, ISAE 3402, incident and crisis management, business continuity, IAM/PIAM governance, control assurance, audit readiness and security operating models.

The Practitioner Series turns real-world security governance experience into structured methods practitioners can understand and apply.

Connect on LinkedIn
Before you buy

Questions

Is this a certification-preparation book?

No. It explains the security governance system that sits before, behind and around individual frameworks and certifications.

What format do I receive?

A protected digital PDF edition licensed for your personal use. After successful payment, Paddle provides your payment confirmation and invoice, while your protected digital edition and its unlock instructions are delivered separately.

How is my digital copy protected?

Each completed purchase is intended to receive an individually protected copy with a unique, cryptographically generated unlock key. A key is issued for one purchase only and is never reused for another customer.

What if my download link or delivery email is lost?

Legitimate purchasers can request access recovery using their purchase information. The delivery design protects both the author's work and the purchaser's access without relying on intrusive device tracking.

Is a physical edition available?

Physical editions are not part of the standard digital storefront. If there is sufficient demand, printed editions can be considered separately with pricing based on production and fulfillment.

Can organizations or universities buy copies?

Yes. Institutional, educational and multi-copy licensing can be discussed separately from individual digital purchases.

Are Russian and German editions available?

Not yet. English is the canonical first edition. Russian and German localizations are planned and will be released only after full editorial quality review.

Can I redistribute the PDF?

No. Individual digital copies are licensed to the purchaser for personal use. Separate arrangements can be discussed for organizational or educational use.

The Practitioner Series · Secure worldwide checkout

Start with the system. Continue with the decision.

Book I — The Foundations establishes how cybersecurity governance works. Book II — Risk & Decision-Making takes that foundation into the room where exposure must become an accountable decision. Each digital volume is €19.99. Payment, tax calculation and invoicing are handled by Paddle; the protected book copy and unique unlock key are delivered automatically after successful payment.