Continuing Education Information Sheet
Unlikely Friends: Cybersecurity, the Financial Sector, and the Federal Government
- Provider
- Legal Cyber Academy · Lexeprint Inc.
2100 Park Ave PO Box 681057 Park City UT 84068
info@lawandforensics.com · https://www.lexeprint.com - Delivery method
- On-demand, self-study (online, recorded)
- Instructional time
- 1h 3m
- Assessment
- Graded multiple-choice exam · pass mark 70%
Equivalent credit hours
1.0 on a 60-minute basis (most CLE / general CE) · 1.2 on a 50-minute basis (NASBA CPE). Rounded down to the nearest tenth of an hour; your board may round differently.
Learning objectives
- Understand the cybersecurity risks facing the financial sector
- Break down the Gramm-Leach-Bliley Act and its requirements
- Review the SEC's cybersecurity guidance and proposed rules
- Advise financial-sector clients on federal cybersecurity regulation
Audience & prerequisites
Intended audience: Attorneys advising financial institutions and businesses in the financial sector.
Level: intermediate
Prerequisites: None
Faculty
Daniel B. Garrie, Founder, Law & Forensics; Neutral at JAMS; Faculty at Harvard
Law & Forensics LLC · JAMS · Harvard · Rutgers Law School · Journal of Law & Cyber Warfare
Daniel B. Garrie is the founder and executive managing partner of Law & Forensics LLC, a boutique cybersecurity and forensic engineering firm he co-founded in 2008. He serves as a neutral, arbitrator, and forensic special master at JAMS, focusing on cybersecurity, cryptocurrency, and complex technology disputes, and holds faculty appointments at Harvard and Rutgers Law School. A patented software inventor and prolific author, he is editor-in-chief of the Journal of Law & Cyber Warfare and a widely cited authority on computer forensics, eDiscovery, and cyber litigation.
Brian Levine, Former EY-Parthenon Managing Director, Cybersecurity and Data Privacy, Ernst & Young LLP
Ernst & Young
Brian Levine is a cybersecurity and data privacy lawyer who served as EY-Parthenon Managing Director, Cybersecurity and Data Privacy at Ernst & Young LLP, leading a cybersecurity and data privacy team focused on the strategic application of security in the context of capital transactions, including mergers, acquisitions, divestitures and restructurings. He joined EY from the U.S. Department of Justice, where he served as the National Coordinator for more than 300 federal prosecutors focused on investigating and prosecuting computer crime and intellectual property crime, and served as a federal prosecutor and senior counsel with the DOJ's Computer Crime and Intellectual Property Section. Earlier he served as an Assistant Attorney General for the Internet & Technology Bureau of the New York Attorney General's Office. He earned his BA from the University of Pennsylvania and his JD from New York University School of Law. At Legal Cyber Academy, Brian Levine teaches on vendor and data breach risk, financial-sector cybersecurity, and cyber litigation trends.
Karen Evans, Director, Waste, Fraud and Abuse Task Force, U.S. Department of Homeland Security
U.S. Department of Homeland Security
Karen S. Evans is director of the Department of Homeland Security's waste, fraud and abuse task force, which she took over in 2026 after returning to DHS in January 2025 and spending roughly 18 months at CISA and FEMA, including as CISA's Executive Assistant Director for Cybersecurity. She was the first Assistant Secretary for Cybersecurity, Energy Security and Emergency Response at the Department of Energy, served as DHS Chief Information Officer from 2020 to 2021, and was Administrator for the Office of Electronic Government and Information Technology at OMB. She previously served as Managing Director of the Cyber Readiness Institute and as national director of the U.S. Cyber Challenge, and holds an MBA and a bachelor's degree in chemistry from West Virginia University. At Legal Cyber Academy she teaches on cybersecurity regulation of the financial sector.
David Krebs, Partner and National Leader, Privacy, Data Governance & Cybersecurity, Miller Thomson LLP
Miller Thomson LLP
David Krebs is a partner at Miller Thomson LLP in Saskatoon and national leader of the firm's Privacy, Data Governance & Cybersecurity practice. He acts as cyber breach counsel, advising on incident preparedness and management, privacy and AI compliance, and technology agreements including SaaS and data-sharing contracts, for technology, healthcare and medical device clients. He holds an LL.M. in Law and IT from Stockholm University and a J.D. and B.Comm. from the University of Saskatchewan, and is admitted in Alberta and Saskatchewan. He edits the MT Cybersecurity Blog and was appointed to the International Association of Privacy Professionals' Canadian Advisory Board for 2021-2022. He is listed in The Best Lawyers in Canada for Privacy and Data Security Law and in the Canadian Legal Lexpert Directory for Data Protection & Privacy. At Legal Cyber Academy, David Krebs teaches on cybersecurity regulation of the financial sector and the federal government's role in it.
Nathan Salminen, Partner, Hogan Lovells Cadwalader
Hogan Lovells LLP
Nathan Salminen is a partner in Washington, D.C. with Hogan Lovells Cadwalader, where he helps clients evaluate and manage privacy and cybersecurity risks and obligations. He has led the response to major security incidents at companies in the financial, defense, energy and technology sectors, including incidents involving a nation-state threat actor and incidents affecting critical infrastructure. He also advises companies that build and use artificial intelligence products, and has led the response to more than two dozen regulatory investigations of AI companies globally. Before becoming a lawyer he spent 13 years as a software engineer and manager of technical teams, and he holds the Offensive Security Certified Professional penetration-testing certification. He earned his J.D. from Columbia Law School. At Legal Cyber Academy he teaches on cybersecurity regulation of the financial sector.
Timed agenda
| # | Topic | Minutes |
|---|---|---|
| 1 | Introduction to Cybersecurity | 63 |
| 2 | Gramm Leach Bliley Act (GLBA) | — |
| 3 | Securities and Exchange Commission (SEC) | — |
| 4 | Key Takeaways for Businesses and Their Counsel | — |
| Total instructional time | 63 |
Self-submission by credit type
Legal Cyber Academy is not an accredited provider; the notes below explain how a learner may self-submitthis activity where their board permits. The pathways shown reflect this course’s subject matter. Always confirm your board’s current rules.
- Finance/securities subject matter — may support CPE where your state board accepts non-NASBA-registered activities.
CLE (attorneys)up to 1.0 hr (60-min basis)
Many U.S. jurisdictions let an attorney apply for CLE credit for a non-accredited program (often called individual attorney or self-application). Use this certificate plus the course Information Sheet as your supporting documentation. Your state bar or CLE board decides whether credit is granted, how much, and any self-study cap.
CE / CPD (privacy, insurance, IT)up to 1.0 hr (60-min basis)
Where your professional body recognizes self-reported or self-directed learning (CPD) — for example many privacy (CIPP/CIPM) and security certifications — record this activity using the certificate and Information Sheet. Confirm your program's self-reporting rules and any documentation it requires.
CPE (accountants)up to 1.2 hr (50-min basis)
NASBA CPE uses a 50-minute credit hour and has strict self-study standards (registered sponsors, word-count-per-credit, and qualifying review questions). This course is NOT a NASBA-registered self-study program. Some state boards accept non-registered activities at their discretion — verify with your board before claiming CPE.
Legal Cyber Academy is not an accredited continuing-education provider, and its courses are not pre-approved for CLE, CE, CME, or CPE credit. Each course provides a graded assessment, a verifiable Certificate of Completion, and a Continuing Education Information Sheet documenting instructional time, learning objectives, faculty, and a timed agenda — the records most licensing bodies require when a learner applies for self-submitted or self-study credit. Whether credit is granted, and how much, is determined solely by your licensing board. Confirm your board's rules before claiming credit. Verify certificates at https://www.legalcyberacademy.com/certificate/ <code>.