Legal Cyber Academy

2024 Board Cyber Readiness Certificate

Taught by Daniel B. Garrie

CISO & CTOLevel: Intermediate

Overview of 2024 Board Cyber Readiness Certificate

The Board Cyber Readiness Certificate is an online, board-tailored program built around six live expert-led lectures organized into four modules: Introduction to Cybersecurity, Regulatory Oversight, Risk Management/Incident Response & Engaging with Key Actors, and Tools for Exercising Oversight. Participants gain a comprehensive understanding of the technical, financial, legal, and regulatory cybersecurity risks their organization faces; the importance of governance frameworks and data-protection compliance; how to identify and prioritize cyber risks; and how evolving regulatory oversight (SEC, FTC, NYDFS, GDPR) is reshaping the role of board members. The program is delivered by a distinguished faculty of former regulators, national cyber directors, senior big-law partners, CISOs, cyber-insurance executives, and law-enforcement officials, and equips board members to demonstrate cybersecurity awareness and risk-management proficiency to regulators, shareholders, and insurers.

What you’ll learn in 2024 Board Cyber Readiness Certificate

  • Gain a comprehensive understanding of the technical, financial, legal, and regulatory cybersecurity risks an organization faces
  • Understand governance frameworks, data-protection compliance, and integrating cybersecurity into business strategy
  • Identify and prioritize cyber risks and foster a culture of cyber awareness across the organization
  • Establish resilient incident response plans and understand ransomware risk from both technical and non-technical perspectives
  • Assess how changing regulatory oversight (SEC 2023 rules, NYDFS 23 NYCRR 500, FTC, GDPR) is changing the board member's role
  • Engage strategically with law enforcement and navigate the cyber-insurance landscape
  • Apply a practical oversight toolkit, including cybersecurity risk assessments and key questions for incident response planning

Audience and prerequisites

Who should take this course2024 Board Cyber Readiness Certificate

Corporate board members and directors, C-suite executives, CISOs, and in-house/outside counsel responsible for cybersecurity governance and oversight.

Curriculum

  1. 1. Intro to Cyber

    Introduction to Cybersecurity: Cybersecurity Landscape, Technologies, and Threat Actors. Explores the cybersecurity landscape through the lens of the 2020 SolarWinds attack, covering threat actors, methods of attack, the financial cost of breaches, how cyber attacks have evolved over the past decade, and why cybersecurity matters as a strategic business concern.

    Video coming soon
  2. 2. SEC, FTC, NYDFS

    Regulatory Oversight: Overview of SEC, FTC, and NYDFS Cybersecurity Regulations. Covers the SEC's 2023 cybersecurity rules and response to SolarWinds, the NYDFS Cybersecurity Regulation (23 NYCRR 500) and its amendments, and the FTC's enforcement capabilities and Commercial Surveillance/Data Security ANPR.

    Video coming soon
  3. 3. GDPR

    Breaching Borders: Understanding the General Data Protection Regulation (GDPR). Introduces the GDPR and its global implications for boards, covering data-controller vs. data-processor obligations, cross-border data transfers, and GDPR liability and fines. (Slides only in the 2024 materials; no lecture recording present.)

    Video coming soon
  4. 4. Board Handbook for Cyber Risk Management and Incident Response

    The Board Handbook: Cyber Incident Plan and Ransomware. Covers the cyber incident-response process, the anatomy of an incident response plan, best practices when a plan has been compromised, understanding ransomware risk, technical risk management, and non-technical considerations for ransomware.

    Video coming soon
  5. 5. Best Practices for Engaging with Law Enforcement and Understanding Cyber Insurance

    Best practices for engaging with law enforcement before and during cyber incidents, plus an overview of cyber insurance: the different types of coverage, current issues with cyber insurance, and best practices for using it to mitigate financial risk.

    Video coming soon
  6. 6. Exercise Appropriate Oversight Over the Cyber Program

    Toolkit for the Board: How to Exercise Appropriate Oversight. Equips participants with practical oversight tools, including cybersecurity risk assessments and key questions to ask during the incident response planning process, to foster a cybersecurity culture and shape organizational outcomes. (Slides only in the 2024 materials; no lecture recording present.)

    Video coming soon

Your instructors

Portrait of Daniel B. Garrie

Daniel B. Garrie

Founder, Law & Forensics; Neutral at JAMS; Faculty at Harvard

Law & Forensics LLC · JAMS · Harvard · Rutgers Law School · Journal of Law & Cyber Warfare

Daniel B. Garrie is the founder and executive managing partner of Law & Forensics LLC, a boutique cybersecurity and forensic engineering firm he co-founded in 2008. He serves as a neutral, arbitrator, and forensic special master at JAMS, focusing on cybersecurity, cryptocurrency, and complex technology disputes, and holds faculty appointments at Harvard and Rutgers Law School. A patented software inventor and prolific author, he is editor-in-chief of the Journal of Law & Cyber Warfare and a widely cited authority on computer forensics, eDiscovery, and cyber litigation.

Portrait of Justin Herring

Justin Herring

Partner, Mayer Brown

Mayer Brown

Justin Herring is a partner at Mayer Brown, practicing in the firm's Cybersecurity & Data Privacy, Financial Services Regulatory & Enforcement, and Global Investigations & White Collar Defense groups. He advises on global incident response, regulatory enforcement and related litigation, including for crypto and fintech clients. He was Executive Deputy Superintendent of the Cybersecurity Division at the New York State Department of Financial Services, the first leader of that division, and previously spent nine years as an Assistant U.S. Attorney, serving as inaugural chief of the Cybercrimes Unit in the District of New Jersey. He holds a J.D. from the University of Chicago Law School. At Legal Cyber Academy he teaches on the New York DFS cybersecurity regulations, blockchain and cryptocurrency, and managing cybersecurity risk.

Portrait of Paul Luehr

Paul Luehr

Partner, Manatt, Phelps & Phillips, LLP

Manatt, Phelps & Phillips, LLP

Paul Luehr is a partner at Manatt, Phelps & Phillips, LLP in Washington, D.C., practising in privacy and data security and co-leading the firm's artificial intelligence practice. He advises companies in retail, healthcare, financial services, technology, higher education and manufacturing on cybersecurity, privacy, AI and data breach response. He previously prosecuted cybercrime as a federal prosecutor at the U.S. Department of Justice, led the Federal Trade Commission's first internet team, and led forensic teams responding to major cyber breaches. He is a CIPP/US, a member of the NIST AI Safety Institute Consortium, and an adviser to the American Law Institute on the Restatement Third, Information Privacy Principles. At Legal Cyber Academy he teaches on the National Cybersecurity Strategy and board cyber readiness.

Portrait of John D'Agostino

John D'Agostino

Head of Strategy, Coinbase Institutional

Dagger Consulting LLC · Coinbase

John D'Agostino is head of strategy at Coinbase Institutional and the founder of Dagger Consulting LLC. He co-founded the Alternative Investment Management Association's Digital Asset Working Group. Earlier in his career he was head of strategy at the New York Mercantile Exchange, where he led the effort to create the Dubai Mercantile Exchange in partnership with the Dubai government. He teaches fintech at Oxford, MIT and Columbia. At Legal Cyber Academy, John D'Agostino teaches on blockchain and cryptocurrency, and on SEC cybersecurity guidance and crypto enforcement.

Portrait of Shannon Yavorsky

Shannon Yavorsky

Partner, Orrick, Herrington & Sutcliffe LLP

Orrick, Herrington & Sutcliffe LLP

Shannon Yavorsky is a partner at Orrick, Herrington & Sutcliffe LLP in San Francisco and London, where she co-leads the firm's global Cyber, Privacy & Data Innovation group and its artificial intelligence practice. She advises on U.S. and European privacy, cybersecurity and AI issues, counselling clients on cross-border data transfers, data breaches and the development of global privacy and AI compliance programs, evaluating privacy, security and AI risk in corporate transactions, and drafting and negotiating data-related contracts. She joined Venable's San Francisco office as a partner in 2017 from Kirkland & Ellis, where she was also a partner. She is admitted to practice in California, Ireland, and England and Wales. At Legal Cyber Academy she teaches on the CCPA, the GDPR and board cyber readiness.

Portrait of David A. Cass

David A. Cass

Senior Partner, Law & Forensics; Adjunct Faculty, Harvard & Rutgers Law

Law & Forensics LLC · Harvard · Rutgers Law School · Global Cyber Institute

David A. Cass is a senior partner at Law & Forensics LLC, where he leads the Cryptocurrency and Digital Banking Practice and is a member of the Cybersecurity and Forensics Practice. His background spans financial services regulation, cryptocurrency, digital assets, blockchain, and cloud, including service as a lead regulator at the Federal Reserve Bank of New York and as CISO and Global Partner of IBM's Cloud Security Service unit. He teaches as adjunct faculty at Harvard and Rutgers Law School and is a faculty member at the non-profit Global Cyber Institute.

Portrait of Amie Rooney

Amie Rooney

Associate General Counsel and Senior Director, Ethics & Compliance, Marvell Technology, Inc.

Marvell Technology, Inc.

Amie Rooney is Associate General Counsel and Senior Director of Ethics and Compliance at Marvell Technology, Inc., the semiconductor company, based in Santa Clara, California. She studied law at Georgetown University Law Center, sits on the board of THE CAMPAIGN for Legal Services, and served as vice president of the Federal Bar Association's Northern California chapter from 2021 to 2024. At Legal Cyber Academy she teaches on cybercrime and enforcement, including the U.S. v. Joe Sullivan trial, and on board cyber readiness.

Portrait of Benjamin Kingsley

Benjamin Kingsley

Partner, Fenwick & West LLP

United States Attorney's Office, Northern District of California

Benjamin S. Kingsley is a litigation partner at Fenwick & West LLP in San Francisco, where his practice focuses on government investigations, regulatory enforcement and complex civil litigation for technology, fintech, life sciences, healthcare, AI and crypto clients. He joined the firm as a partner in September 2024 after more than fifteen years as a government attorney, including over eleven years as an Assistant U.S. Attorney for the Northern District of California, where he served as Chief of the Oakland Branch, Chief of the Special Prosecutions Section, and in the Economic Crimes and Securities Fraud Section. He began his career on the appellate staff of the Justice Department's Civil Division. He clerked for Judge William A. Fletcher of the Ninth Circuit and holds a J.D., summa cum laude, from New York University School of Law. At Legal Cyber Academy he teaches on board cyber readiness.

Portrait of Andrew Dawson

Andrew Dawson

Partner, Keker, Van Nest & Peters LLP

U.S. Department of Justice

Andrew Dawson is a partner at Keker, Van Nest & Peters in San Francisco, where his practice areas include white collar criminal, securities, antitrust, intellectual property, professional liability, and consumer and class actions. He rejoined the firm on 3 September 2024 after nearly ten years as an Assistant U.S. Attorney for the Northern District of California, most recently as chief of the Organized Crime Drug Enforcement Task Force Section and previously as deputy chief of the Special Prosecutions and National Security Unit. He was lead trial counsel in the first-ever prosecution of a corporate executive related to cybersecurity failures and associated obstruction of justice, a matter concerning the coverup of a breach at a major ridesharing company. He holds a J.D. from Stanford Law School, where he was managing editor of the Stanford Law Review, and clerked for Justice Stephen G. Breyer of the U.S. Supreme Court. At Legal Cyber Academy he teaches on board cyber readiness.

Portrait of Donovan McKendrick

Donovan McKendrick

Special Assistant U.S. Attorney, N.D. Cal.; Special Agent, FBI

Department of Justice, Federal Bureau of Investigations

Donovan M. McKendrick is a Special Assistant U.S. Attorney in the U.S. Attorney's Office for the Northern District of California, appearing for the United States in cryptocurrency seizure and civil asset forfeiture matters and in cyber-enabled criminal cases. His filings include forfeiture actions over approximately $23.6 million in assorted cryptocurrencies and over 782,000 Tether, and a seizure warrant application covering 41 domain names. He has also served as a Special Agent with the Federal Bureau of Investigation. At Legal Cyber Academy, Donovan McKendrick teaches on board cyber readiness.

Portrait of Peter Halprin

Peter Halprin

Partner, Haynes Boone

Haynes Boone

Peter A. Halprin is a partner in the insurance recovery practice group at Haynes Boone in New York, where he represents policyholders in high-value insurance claims, including business interruption, cybersecurity and wrongful death matters, through litigation, arbitration and mediation. His listed practice areas also include international arbitration, privacy and cybersecurity, healthcare and life sciences, media, entertainment and sports, and crisis management. He holds a J.D. from the Benjamin N. Cardozo School of Law, a postgraduate diploma in international commercial arbitration from Queen Mary, University of London, and a B.A. from McGill University. He is admitted in New York, is a Fellow of the Chartered Institute of Arbitrators and a member of the AAA National Roster of Arbitrators, and has been ranked by Chambers USA. At Legal Cyber Academy he teaches on cyber insurance policies and board cyber readiness.

Portrait of Bridget Choi

Bridget Choi

Cyber Insurance Executive

Bridget Quinn Choi is a cyber insurance executive, attorney, and consultant with extensive experience guiding clients through cyber incidents. She has served as head of cyber underwriting for North America at a major cyber insurance carrier and as Director of Incident Response for Booz Allen Hamilton, and previously worked as General Counsel and Managing Director of Strategy for an incident response company, where she managed teams that negotiated with attackers and facilitated ransom payments. Earlier in her career she served as cyber claims counsel at several insurance companies and practiced law in New York. She earned her Juris Doctor from New York Law School.

Portrait of Chris Inglis

Chris Inglis

Board Member; former National Cyber Director

Paladin Capital Group · U.S. Air Force and Naval Academies · Office of the National Cyber Director (former)

Chris Inglis is a strategic advisor to Paladin Capital Group and a Visiting Professor at the U.S. Air Force and Naval Academies. From 2021 to 2023 he served in the White House as the first Senate-confirmed U.S. National Cyber Director, building on his earlier service as a Commissioner on the U.S. Cyberspace Solarium Commission and eight years as Deputy Director and Chief Operating Officer of the National Security Agency. A retired U.S. Air Force Brigadier General with 30 years of military service, he holds advanced degrees in engineering and computer science and serves on numerous public and private boards and advisory councils.

Learning track

Part of a learning trackThe CISO's Legal PlaybookCourse 5 of 8 — see the full path