Legal Cyber Academy

2023 Beta Board Cyber Readiness Certificate

Taught by Daniel B. Garrie

CISO & CTOLevel: Intermediate

Overview of 2023 Beta Board Cyber Readiness Certificate

The 2023 Beta Board Cyber Readiness Certificate was the first cohort of Legal Cyber Academy's board-focused certificate program, delivered live over five weeks in September-October 2023. As delivered, the program comprised six core lectures mapped to four modules (Introduction to Cybersecurity; Regulatory Oversight; Risk Management, Incident Response, and Engaging with Key Actors; and Tools for Exercising Oversight), each with suggested readings. The beta emphasized that the nature of a board seat is changing as regulators establish standards of cybersecurity knowledge and organizational involvement for boards, and it aimed to make board members conversant in core cybersecurity concepts, their individual responsibilities, and the SEC/FTC/NYDFS/GDPR regulatory landscape. The core lesson content, lecture recordings, and slide decks are largely shared with the 2024 edition; the primary differences are the beta's guest-speaker lineup, its live schedule, and additional/exploratory materials (including a seventh confidential lesson on Executive Actions + Cyberwarfare that exists as slides only and was not part of the final six-class syllabus). Planning documents also reference a broader intended scope (e.g., CISO criminal-liability and healthcare-specific modules) that was not delivered in the final six-lecture beta.

What you’ll learn in 2023 Beta Board Cyber Readiness Certificate

  • Understand core cybersecurity concepts (data breaches, tabletops, cyber hygiene, penetration testing) and how they relate
  • Recognize how a board seat is changing as regulators set expectations for board cybersecurity involvement
  • Navigate the fragmented U.S. cyber regulatory landscape (SEC, FTC, NYDFS) and the EU's GDPR
  • Understand the board's role in incident response, risk management, and ransomware mitigation
  • Learn best practices for engaging with law enforcement and understanding cyber insurance
  • Apply an oversight toolkit and the right questions to drive cybersecurity decision-making at the board level

Audience and prerequisites

Who should take this course2023 Beta Board Cyber Readiness Certificate

Corporate board members and directors, C-suite executives, CISOs, and in-house/outside counsel; this beta cohort targeted senior board members and their organizations.

Curriculum

  1. 1. Intro to Cyber

    Introduction to Cybersecurity: Cybersecurity Landscape, Technologies, Tools of the Trade, and Threat Actors. Combines the intro-to-cyber and everyday-threats/social-engineering material, covering the threat landscape, phishing and social engineering, threat actors, and foundational cybersecurity concepts for board members.

    Video coming soon
  2. 2. SEC, FTC, NYDFS

    Regulatory Oversight: Overview of SEC, FTC, and NYDFS Cybersecurity Regulations. Covers the SEC's role and 2023 cybersecurity rules, the FTC's privacy/security rulemaking and Commercial Surveillance ANPR, and the NYDFS 23 NYCRR 500 regulation and its proposed amendments.

    Video coming soon
  3. 3. GDPR

    Breaching Borders: Understanding the General Data Protection Regulation (GDPR). Introduces the GDPR, data-controller vs. data-processor obligations, cross-border data transfers, and GDPR liability, fines, and class actions.

    Video coming soon
  4. 4. Board Handbook for Cyber Risk Management and Incident Response

    Board Handbook to Cyber Risk Management and Incident Response & Limiting Ransomware Risk. Covers the cyber incident-response process, incident response plan anatomy, technical and non-technical risk management, and ransomware mitigation from the board's perspective.

    Video coming soon
  5. 5. Best Practices for Engaging with Law Enforcement and Understanding Cyber Insurance

    Best practices for engaging with law enforcement before and during cyber incidents, and an overview of cyber insurance including the types of coverage, current issues, and best practices for managing financial risk.

    Video coming soon
  6. 6. Exercise Appropriate Oversight Over the Cyber Program

    Toolkit: How to Exercise Appropriate Oversight Over the Cybersecurity Program. Provides practical oversight tools, cybersecurity risk assessments, and key questions for the incident response planning process.

    Video coming soon
  7. 7. CONF. Executive Actions + Cyberwarfare

    Confidential/supplemental lesson on executive actions (the 2023 National Cybersecurity Strategy and related Executive Orders) and cyberwarfare. Present as slide decks only (no lecture recording) and not part of the final six-class beta syllabus; treat as exploratory/bonus material.

    Video coming soon

Your instructors

Portrait of Daniel B. Garrie

Daniel B. Garrie

Founder, Law & Forensics; Neutral at JAMS; Faculty at Harvard

Law & Forensics LLC · JAMS · Harvard · Rutgers Law School · Journal of Law & Cyber Warfare

Daniel B. Garrie is the founder and executive managing partner of Law & Forensics LLC, a boutique cybersecurity and forensic engineering firm he co-founded in 2008. He serves as a neutral, arbitrator, and forensic special master at JAMS, focusing on cybersecurity, cryptocurrency, and complex technology disputes, and holds faculty appointments at Harvard and Rutgers Law School. A patented software inventor and prolific author, he is editor-in-chief of the Journal of Law & Cyber Warfare and a widely cited authority on computer forensics, eDiscovery, and cyber litigation.

Portrait of David A. Cass

David A. Cass

Senior Partner, Law & Forensics; Adjunct Faculty, Harvard & Rutgers Law

Law & Forensics LLC · Harvard · Rutgers Law School · Global Cyber Institute

David A. Cass is a senior partner at Law & Forensics LLC, where he leads the Cryptocurrency and Digital Banking Practice and is a member of the Cybersecurity and Forensics Practice. His background spans financial services regulation, cryptocurrency, digital assets, blockchain, and cloud, including service as a lead regulator at the Federal Reserve Bank of New York and as CISO and Global Partner of IBM's Cloud Security Service unit. He teaches as adjunct faculty at Harvard and Rutgers Law School and is a faculty member at the non-profit Global Cyber Institute.

Portrait of Michael Kleinman

Michael Kleinman

Special Counsel, Fried Frank LLP

Michael A. Kleinman is litigation special counsel in Fried Frank's New York office and a member of the firm's Privacy & Cybersecurity practice. He represents corporations, boards of directors, financial advisors, investment banks, and private equity firms in complex commercial, securities, derivative, and intellectual property litigation, and advises clients on regulatory compliance, transactional, and litigation matters involving cybersecurity and data privacy risk. He handles cases arising under the Computer Fraud and Abuse Act and other claims of unauthorized use of licensed data and technology, and is a Certified Information Privacy Professional (CIPP/US). At Legal Cyber Academy he contributes to the Board Cyber Readiness Certificate.

Portrait of David Shonka

David Shonka

Partner and General Counsel, Redgrave LLP

David C. Shonka is a partner at Redgrave LLP, where he also serves as the firm's General Counsel and advises on data privacy, cybersecurity, eDiscovery, cross-border data transfers, information governance, and government civil law enforcement investigations. He served as Acting General Counsel of the Federal Trade Commission across three separate terms — in 2009, from 2012 to 2013, and from 2016 to 2018 — and spent a decade before that as the agency's Principal Deputy General Counsel, where he oversaw the FTC's Litigation, Legal Counsel, and Opinions & Analysis groups. At Legal Cyber Academy he contributes to the Board Cyber Readiness Certificate.

Portrait of Paul Tiao

Paul Tiao

Partner, Hunton Andrews Kurth LLP

Office of the National Cyber Director

Paul M. Tiao is a partner at Hunton Andrews Kurth LLP in Washington, DC, where he works on cybersecurity law and policy. His practice covers investigations, litigation, regulation, policy and legislation on homeland security and privacy issues, including cyber intrusions, data breaches, electronic surveillance and data privacy, and he co-founded the firm's multi-disciplinary Energy Sector Security Team and served as its co-chair. He was earlier Special Counsel and then Senior Counselor for Cybersecurity and Technology to the Director of the FBI, Judiciary Committee counsel to the Assistant Majority Leader in the U.S. Senate, and an Assistant U.S. Attorney in the District of Maryland. He holds a J.D. from Columbia Law School, an M.P.A. from Princeton and a B.S. from MIT. At Legal Cyber Academy he teaches on the U.S. National Cybersecurity Strategy and board cyber readiness.

Portrait of Jeffrey Caso

Jeffrey Caso

Expert Associate Partner, McKinsey & Company

McKinsey & Company

Jeffrey Caso is an expert associate partner in McKinsey & Company's cybersecurity practice, based in the firm's Washington, DC office. He works on market growth strategy, digital risk and technology strategy, and on business-building in cybersecurity with enterprises, investors and leading cybersecurity providers. He co-leads Cyber Threat Snapshot, McKinsey's deep web threat intelligence offering, and has published on cyberwarfare, privacy regulation and the impact of COVID-19 on cyber markets. He holds a B.S.F.S. in science, technology and international affairs from Georgetown University. At Legal Cyber Academy he teaches on the U.S. National Cybersecurity Strategy, cyber litigation trends, and board cyber readiness.

Portrait of Paul Luehr

Paul Luehr

Partner, Manatt, Phelps & Phillips, LLP

Manatt, Phelps & Phillips, LLP

Paul Luehr is a partner at Manatt, Phelps & Phillips, LLP in Washington, D.C., practising in privacy and data security and co-leading the firm's artificial intelligence practice. He advises companies in retail, healthcare, financial services, technology, higher education and manufacturing on cybersecurity, privacy, AI and data breach response. He previously prosecuted cybercrime as a federal prosecutor at the U.S. Department of Justice, led the Federal Trade Commission's first internet team, and led forensic teams responding to major cyber breaches. He is a CIPP/US, a member of the NIST AI Safety Institute Consortium, and an adviser to the American Law Institute on the Restatement Third, Information Privacy Principles. At Legal Cyber Academy he teaches on the National Cybersecurity Strategy and board cyber readiness.

Portrait of Erez Liebermann

Erez Liebermann

Partner and Co-Chair, Technology Group, Debevoise & Plimpton LLP

Debevoise & Plimpton LLP

Erez Liebermann is a partner at Debevoise & Plimpton LLP in New York, where he co-chairs the Technology Group and is a member of the firm's Data Strategy & Security Group. He advises on cybersecurity and privacy, incident response and crisis management, white collar and regulatory defence, and state attorneys general matters. He was previously Chief Counsel of Cybersecurity and Privacy at Prudential, and before that Deputy Chief of the Criminal Division and Chief of the Computer Hacking and IP Section at the U.S. Attorney's Office for the District of New Jersey. He holds a J.D. from Columbia Law School. At Legal Cyber Academy he teaches on the U.S. National Cybersecurity Strategy and board cyber readiness.

Learning track

Part of a learning trackThe CISO's Legal PlaybookCourse 4 of 8 — see the full path