Legal Cyber Academy

Unlikely Friends: Cybersecurity, the Financial Sector, and the Federal Government

Taught by Daniel B. Garrie

Securities LawLevel: Intermediate1h 3m

Free preview of this course

A 5-minute excerpt from this course. The full course continues from where this leaves off.

Overview of Unlikely Friends: Cybersecurity, the Financial Sector, and the Federal Government

Unlikely Friends reviews the financial sector's cybersecurity regulatory status. Panelists introduce cybersecurity and the industries at greatest risk, break down the Gramm-Leach-Bliley Act (GLBA) including regulated parties and consequences for non-compliance, review the role of the SEC and its cybersecurity guidance and proposed rules, and conclude with the effect of federal cybersecurity regulation on businesses and their counsel.

What you’ll learn in Unlikely Friends: Cybersecurity, the Financial Sector, and the Federal Government

  • Understand the cybersecurity risks facing the financial sector
  • Break down the Gramm-Leach-Bliley Act and its requirements
  • Review the SEC's cybersecurity guidance and proposed rules
  • Advise financial-sector clients on federal cybersecurity regulation

Audience and prerequisites

Who should take this courseUnlikely Friends: Cybersecurity, the Financial Sector, and the Federal Government

Attorneys advising financial institutions and businesses in the financial sector.

Curriculum

  1. 1. Introduction to Cybersecurity

    Cybersecurity fundamentals and the industries at greatest risk.

    Locked
  2. 2. Gramm Leach Bliley Act (GLBA)

    Regulated parties, the three sections, and non-compliance consequences.

    Video coming soon
  3. 3. Securities and Exchange Commission (SEC)

    The SEC's role, cybersecurity guidelines, and proposed rules.

    Video coming soon
  4. 4. Key Takeaways for Businesses and Their Counsel

    Effect of federal cybersecurity regulation on the financial sector.

    Video coming soon

Your instructors

Portrait of Daniel B. Garrie

Daniel B. Garrie

Founder, Law & Forensics; Neutral at JAMS; Faculty at Harvard

Law & Forensics LLC · JAMS · Harvard · Rutgers Law School · Journal of Law & Cyber Warfare

Daniel B. Garrie is the founder and executive managing partner of Law & Forensics LLC, a boutique cybersecurity and forensic engineering firm he co-founded in 2008. He serves as a neutral, arbitrator, and forensic special master at JAMS, focusing on cybersecurity, cryptocurrency, and complex technology disputes, and holds faculty appointments at Harvard and Rutgers Law School. A patented software inventor and prolific author, he is editor-in-chief of the Journal of Law & Cyber Warfare and a widely cited authority on computer forensics, eDiscovery, and cyber litigation.

Portrait of Brian Levine

Brian Levine

Former EY-Parthenon Managing Director, Cybersecurity and Data Privacy, Ernst & Young LLP

Ernst & Young

Brian Levine is a cybersecurity and data privacy lawyer who served as EY-Parthenon Managing Director, Cybersecurity and Data Privacy at Ernst & Young LLP, leading a cybersecurity and data privacy team focused on the strategic application of security in the context of capital transactions, including mergers, acquisitions, divestitures and restructurings. He joined EY from the U.S. Department of Justice, where he served as the National Coordinator for more than 300 federal prosecutors focused on investigating and prosecuting computer crime and intellectual property crime, and served as a federal prosecutor and senior counsel with the DOJ's Computer Crime and Intellectual Property Section. Earlier he served as an Assistant Attorney General for the Internet & Technology Bureau of the New York Attorney General's Office. He earned his BA from the University of Pennsylvania and his JD from New York University School of Law. At Legal Cyber Academy, Brian Levine teaches on vendor and data breach risk, financial-sector cybersecurity, and cyber litigation trends.

Portrait of Karen Evans

Karen Evans

Director, Waste, Fraud and Abuse Task Force, U.S. Department of Homeland Security

U.S. Department of Homeland Security

Karen S. Evans is director of the Department of Homeland Security's waste, fraud and abuse task force, which she took over in 2026 after returning to DHS in January 2025 and spending roughly 18 months at CISA and FEMA, including as CISA's Executive Assistant Director for Cybersecurity. She was the first Assistant Secretary for Cybersecurity, Energy Security and Emergency Response at the Department of Energy, served as DHS Chief Information Officer from 2020 to 2021, and was Administrator for the Office of Electronic Government and Information Technology at OMB. She previously served as Managing Director of the Cyber Readiness Institute and as national director of the U.S. Cyber Challenge, and holds an MBA and a bachelor's degree in chemistry from West Virginia University. At Legal Cyber Academy she teaches on cybersecurity regulation of the financial sector.

Portrait of David Krebs

David Krebs

Partner and National Leader, Privacy, Data Governance & Cybersecurity, Miller Thomson LLP

Miller Thomson LLP

David Krebs is a partner at Miller Thomson LLP in Saskatoon and national leader of the firm's Privacy, Data Governance & Cybersecurity practice. He acts as cyber breach counsel, advising on incident preparedness and management, privacy and AI compliance, and technology agreements including SaaS and data-sharing contracts, for technology, healthcare and medical device clients. He holds an LL.M. in Law and IT from Stockholm University and a J.D. and B.Comm. from the University of Saskatchewan, and is admitted in Alberta and Saskatchewan. He edits the MT Cybersecurity Blog and was appointed to the International Association of Privacy Professionals' Canadian Advisory Board for 2021-2022. He is listed in The Best Lawyers in Canada for Privacy and Data Security Law and in the Canadian Legal Lexpert Directory for Data Protection & Privacy. At Legal Cyber Academy, David Krebs teaches on cybersecurity regulation of the financial sector and the federal government's role in it.

Portrait of Nathan Salminen

Nathan Salminen

Partner, Hogan Lovells Cadwalader

Hogan Lovells LLP

Nathan Salminen is a partner in Washington, D.C. with Hogan Lovells Cadwalader, where he helps clients evaluate and manage privacy and cybersecurity risks and obligations. He has led the response to major security incidents at companies in the financial, defense, energy and technology sectors, including incidents involving a nation-state threat actor and incidents affecting critical infrastructure. He also advises companies that build and use artificial intelligence products, and has led the response to more than two dozen regulatory investigations of AI companies globally. Before becoming a lawyer he spent 13 years as a software engineer and manager of technical teams, and he holds the Offensive Security Certified Professional penetration-testing certification. He earned his J.D. from Columbia Law School. At Legal Cyber Academy he teaches on cybersecurity regulation of the financial sector.