Legal Cyber Academy

Cybersecurity Regulatory Guidebook for Boards, CISOs, and their Counsel

CISO & CTOLevel: Intermediate

Overview of Cybersecurity Regulatory Guidebook for Boards, CISOs, and their Counsel

Regulators now treat cybersecurity as a board-level strategic issue rather than a purely technical one. This multi-part guidebook walks boards, chief information security officers, and the attorneys who advise them through their evolving regulatory responsibilities, fiduciary duties, and personal exposure. It covers cyber risk governance at the board level, the SEC's cybersecurity observations and proposed amendments, the emerging criminal-liability landscape for CISOs, and best practices for deposing a CISO. Attorneys gain an advisory framework for increasingly strict requirements and potential liability; boards and CISOs get a practical primer on their oversight obligations.

What you’ll learn in Cybersecurity Regulatory Guidebook for Boards, CISOs, and their Counsel

  • Define the core elements of the cyber risk landscape and how cyber risk is assessed at the board level
  • Map cybersecurity oversight to board fiduciary and regulatory expectations
  • Apply SEC cybersecurity guidance (2020 observations and 2022 proposed amendments) to a cyber risk assessment
  • Identify criminal-liability exposure for CISOs, including OFAC ransomware-payment and False Claims Act fraud issues
  • Understand deposition strategy for CISOs, including the Apex Doctrine and use of expert consultants

Audience and prerequisites

Who should take this courseCybersecurity Regulatory Guidebook for Boards, CISOs, and their Counsel

Board members, chief information security officers, and attorneys who counsel boards and security executives on cybersecurity governance and liability.

Curriculum

  1. 1. Cybersecurity Legal Issues to Consider at the Board Level Part 1

    As cyber threats continue to rise and pose a risk to organizations of all shapes and sizes, developing active and informed cyber risk management strategies has become essential for boards. This tool of good governance is not only essential to attempt to mitigate the fallout from almost certain future cyber-attacks and data breaches, but is increasingly a legal requirement for boards. Today, regulators are looking for board members to be aware of the cybersecurity risks their organization faces and their role in managing them. These issues include data privacy laws, cybersecurity regulations, liability and risk management, incident response planning, third-party risks, cybersecurity governance, training, and top-down awareness. By understanding these issues, boards can help ensure that thei

    Video coming soon
  2. 2. Cybersecurity Legal Issues to Consider at the Board Level  Part 2

    As cyber threats continue to rise and pose a risk to organizations of all shapes and sizes, developing active and informed cyber risk management strategies has become essential for boards. This tool of good governance is not only essential to attempt to mitigate the fallout from almost certain future cyber-attacks and data breaches, but is increasingly a legal requirement for boards. Today, regulators are looking for board members to be aware of the cybersecurity risks their organization faces and their role in managing them. These issues include data privacy laws, cybersecurity regulations, liability and risk management, incident response planning, third-party risks, cybersecurity governance, training, and top-down awareness. By understanding these issues, boards can help ensure that thei

    Video coming soon
  3. 3. A New Risk For CISOs: Criminal Liability

    With cybersecurity risks and incidents rising every year, businesses are increasingly taking active steps in their cyber risk management and instituting a chief information security officer (CISO). CISOs or equivalent positions have been shown to decrease the probability of information security breaches when included in top management and with board access. Yet, in the face of an inevitable data breach or ransomware attack, businesses face consumer class actions and regulatory investigation that may put CISOs and their employers in conflicting legal positions. Today, most regulators and company boards understand that during a cybersecurity incident, CISOs operate with incomplete and rapidly developing information, yet as recent examples have shown, in some cases CISOs may be found to have

    Video coming soon
  4. 4. Best Practices When Deposing a Chief Information Security Officer

    As cyber threats and significant cyber incidents become increasingly common, more attorneys are interacting with organizations’ technical representatives in ensuing conflicts and litigations. To be best equipped when deposing Chief Information Security Officers (CISO), it is essential for attorneys to understand this role's scope and be confident in the deposition's goals and best practices. For attorneys, knowing how to ask the right questions regardless of technical knowledge in preparatory research and depositions will give them the best tools to represent their clients. Equally, CISOs and their boards will find it useful to know what the security executives can expect in a deposition and how they can prepare for them. In this seminar, our expert instructors begin with an overview of t

    Video coming soon