Legal Cyber Academy

A New Risk for CISOs: Criminal Liability

Taught by Rhea Siers

CISO & CTOLevel: Beginner

Overview of A New Risk for CISOs: Criminal Liability

A small but significant number of criminal prosecutions involving security executives have signaled a shift in how regulators and law enforcement view individual accountability for cybersecurity failures. This course examines the legal theories being applied, the circumstances that have drawn prosecutorial attention, and what distinguishes acceptable security leadership from conduct that has attracted criminal scrutiny. Participants will leave with a clearer picture of their personal exposure and a practical framework for protecting themselves while continuing to do their jobs effectively.

What you’ll learn in A New Risk for CISOs: Criminal Liability

  • Identify the specific conduct patterns that have led to criminal charges against security executives in recent cases
  • Distinguish between organizational liability and personal criminal exposure for CISOs and similar roles
  • Explain how disclosure decisions, board communications, and documentation practices can increase or reduce personal legal risk
  • Apply a practical framework for making and recording security decisions in a way that demonstrates good-faith leadership
  • Recognize when to seek personal legal counsel independent of corporate counsel
  • Evaluate how employment agreements, indemnification clauses, and D&O insurance policies relate to personal criminal exposure

Audience and prerequisites

Who should take this courseA New Risk for CISOs: Criminal Liability

CISOs and security executives, executives, legal advisors, and board members who oversee or interact with the security function will benefit most from this course.

Prerequisites for A New Risk for CISOs: Criminal Liability

No technical background required — the course focuses on legal exposure and risk management practices rather than technical cybersecurity concepts.

Curriculum

  1. 1. A New Risk for CISOs: Criminal Liability 

    In this seminar, our expert panelists begin by reviewing the primary characteristics and responsibilities of the CISO role, highlighting their importance for organizations' cybersecurity and risk management. Our speakers then discuss the potential criminal issues that CISOs face, specifically for ransomware payments under OFAC and fraud claims under the False Claims Act and when facing regulatory inquiries. Our expert panelists conclude by reviewing a recent example of CISO criminal liability, US v. Joseph Sullivan (N.D. Cal. No. 20-cr-00337-WHO), and key takeaways for what it means for CISOs, their employers, and their counsel. Topics covered in this webinar: CISOs' Role in Cybersecurity and Data Privacy Potential Criminal Issues CISOs Face Case Study

    Video coming soon

Your instructor

Portrait of Rhea Siers

Rhea Siers

Senior Advisor, Cybersecurity Risk and Policy Issues, Teneo Risk Advisory

Teneo · National Security Agency (former) · George Washington University

Rhea Siers is a senior advisor on cybersecurity risk and policy issues at Teneo Risk Advisory, where she counsels C-suite executives on cyber issues. She spent three decades at the National Security Agency (1981-2012), serving as an attorney and counsel in its Office of General Counsel, Deputy Associate Director for Policy and Strategic Communications, and NSA's senior representative to the FBI. She later led cyber security defense strategy at Bank of America and was senior counsel in the cybersecurity practice at Zeichner, Ellman and Krause. Siers is adjunct faculty at George Washington University's Elliott School of International Affairs and at Johns Hopkins University, was Scholar in Residence at GW's Center for Cyber and Homeland Security, and co-authored Cyberwarfare: Understanding the Law, Policy and Technology. At Legal Cyber Academy, Rhea Siers teaches on the current state of cyber threats and whether organizations should run tabletop exercises.

Learning track

Part of a learning trackThe CISO's Legal PlaybookCourse 1 of 8 — see the full path