For CISOs looking to avoid cybersecurity liability, managing cybersecurity can feel like tensely moving blocks in a tower and hoping it doesn’t fall over. Each move by Chief Information Security Officers (CISOs) must ensure their company’s digital safety without inviting legal trouble. This task is getting more complicated as notable legal cases create new rules for the cybersecurity game, particularly in the US. Recent legal actions against Uber’s former security head, Joseph Sullivan, and an investigation into SolarWinds’ CISO, Timothy G. Brown, highlight the serious legal responsibilities of CISOs. These cases stress the need for honesty, ethical actions, and following the law when dealing with cybersecurity issues.
The Uber conviction
In 2016, Uber faced a significant data breach where hackers accessed millions of users’ data. Joseph Sullivan, the then Chief Security Officer, chose not to report this breach to the authorities or inform the affected users. Instead, he arranged for the hackers to be paid off in exchange for their silence. This action led to legal charges against him in 2023, underscoring the severe consequences of not disclosing data breaches. This case serves as a cautionary tale, emphasising the legal and ethical responsibility of those in charge of data security to be transparent and honest in the wake of security breaches. At least in the US, CISOs may struggle to escape cybersecurity liability.
The SolarWinds investigation
The investigation into SolarWinds revolved around the company’s failure to disclose significant cybersecurity risks to its investors, particularly after a sophisticated cyberattack compromised its software. This omission misled investors about the security of SolarWinds’ systems and the extent of the cyber risks faced by the company. The subsequent legal scrutiny shed light on the imperative for organisations to maintain robust cybersecurity defences and to communicate transparently about cybersecurity vulnerabilities. Again, there is a growing trend for the authorities in the US to hold CISOs responsible for cybersecurity failings, which is a liability for those CISOs.
The broader role of CISO when it comes to cybersecurity liability
CISOs’ roles now go beyond managing breaches to strictly following new laws, such as the US Cyber Incident Critical Infrastructure Act of 2022. They must navigate ethical challenges and build a culture of honesty and prioritisation of security within their companies. They can help protect themselves by including Directors and Officers (D&O) insurance in their employment contracts and promoting a shared responsibility for security with their organisations.
The importance of support and culture for CISOs to manage cybersecurity liability
Support from higher-ups and a culture focused on security are crucial for CISOs to manage risks effectively. The trend of CISOs moving to companies that take security seriously shows the impact of company culture on managing cybersecurity challenges.
Actions you can take next
What should CISOs take from this when it comes to cybersecurity liability? High-profile legal cases like these remind CISOs to review their legal risks and consider having legal protection in their contracts. Being proactive in managing cybersecurity risks, focusing on ethical behaviour, compliance with the law, and clear communication is essential in dealing with cybersecurity threats and regulatory requirements. You can:
- Improve your company’s approach to cybersecurity and reduce your legal risks by adopting strong legal and ethical guidelines in your cybersecurity plans. We can help you with this and other aspects of information security compliance.
- Keep learning and make sure your job contract covers legal assistance or D&O insurance. You can learn more about the Uber conviction on the US Department of Justice website and the SolarWinds investigation on the US Securities and Exchange Commission website.
- Encourage a culture of openness and joint responsibility to handle the challenges of CISO cybersecurity liability effectively. You can learn how to develop this culture and find detailed case studies of these cases and other relevant ones by joining our data protection programme.