FreeCISO & CTOManaging Technical and Regulatory Cybersecurity Risks
Panelists cover how cyber threats work and what attackers typically target, then walk through the 2023…
Daniel B. Garrie

Regulators now treat cybersecurity as a board-level strategic issue rather than a purely technical one. This multi-part guidebook walks boards, chief information security officers, and the attorneys who advise them through their evolving regulatory responsibilities, fiduciary duties, and personal exposure. It covers cyber risk governance at the board level, the SEC's cybersecurity observations and proposed amendments, the emerging criminal-liability landscape for CISOs, and best practices for deposing a CISO. Attorneys gain an advisory framework for increasingly strict requirements and potential liability; boards and CISOs get a practical primer on their oversight obligations.
Board members, chief information security officers, and attorneys who counsel boards and security executives on cybersecurity governance and liability.
1. Cybersecurity Legal Issues to Consider at the Board Level Part 1
As cyber threats continue to rise and pose a risk to organizations of all shapes and sizes, developing active and informed cyber risk management strategies has become essential for boards. This tool of good governance is not only essential to attempt to mitigate the fallout from almost certain future cyber-attacks and data breaches, but is increasingly a legal requirement for boards. Today, regulators are looking for board members to be aware of the cybersecurity risks their organization faces and their role in managing them. These issues include data privacy laws, cybersecurity regulations, liability and risk management, incident response planning, third-party risks, cybersecurity governance, training, and top-down awareness. By understanding these issues, boards can help ensure that thei
2. Cybersecurity Legal Issues to Consider at the Board Level Part 2
As cyber threats continue to rise and pose a risk to organizations of all shapes and sizes, developing active and informed cyber risk management strategies has become essential for boards. This tool of good governance is not only essential to attempt to mitigate the fallout from almost certain future cyber-attacks and data breaches, but is increasingly a legal requirement for boards. Today, regulators are looking for board members to be aware of the cybersecurity risks their organization faces and their role in managing them. These issues include data privacy laws, cybersecurity regulations, liability and risk management, incident response planning, third-party risks, cybersecurity governance, training, and top-down awareness. By understanding these issues, boards can help ensure that thei
3. A New Risk For CISOs: Criminal Liability
With cybersecurity risks and incidents rising every year, businesses are increasingly taking active steps in their cyber risk management and instituting a chief information security officer (CISO). CISOs or equivalent positions have been shown to decrease the probability of information security breaches when included in top management and with board access. Yet, in the face of an inevitable data breach or ransomware attack, businesses face consumer class actions and regulatory investigation that may put CISOs and their employers in conflicting legal positions. Today, most regulators and company boards understand that during a cybersecurity incident, CISOs operate with incomplete and rapidly developing information, yet as recent examples have shown, in some cases CISOs may be found to have
4. Best Practices When Deposing a Chief Information Security Officer
As cyber threats and significant cyber incidents become increasingly common, more attorneys are interacting with organizations’ technical representatives in ensuing conflicts and litigations. To be best equipped when deposing Chief Information Security Officers (CISO), it is essential for attorneys to understand this role's scope and be confident in the deposition's goals and best practices. For attorneys, knowing how to ask the right questions regardless of technical knowledge in preparatory research and depositions will give them the best tools to represent their clients. Equally, CISOs and their boards will find it useful to know what the security executives can expect in a deposition and how they can prepare for them. In this seminar, our expert instructors begin with an overview of t
FreeCISO & CTOPanelists cover how cyber threats work and what attackers typically target, then walk through the 2023…
Daniel B. Garrie
CISO & CTOPanelists examine how third-party vendors create cybersecurity and data protection risks for…
Daniel B. Garrie
CISO & CTOPanelists explain cybersecurity fundamentals and define data breaches to show why the topic matters…
Daniel B. Garrie