Elnion
No Result
View All Result
Sunday, September 13, 2026
  • Login
  • AI
  • Cloud
  • Data
  • Digital Enterprise
  • Telco & Mobile
  • Cyber Security
  • Infrastructure
  • Automation
  • Supply Chain
Subscribe
Elnion
  • AI
  • Cloud
  • Data
  • Digital Enterprise
  • Telco & Mobile
  • Cyber Security
  • Infrastructure
  • Automation
  • Supply Chain
No Result
View All Result
Elnion
No Result
View All Result
Home Cyber Security

Cyber Incident Scapegoat Officers (CISOs) and Personal Cyber Liability for Directors

by Bill Mew
April 11, 2024
in Cyber Security, Security
0
Share on TwitterShare on LinkedInShare on Facebook

Back in 2020 Gartner Inc. predicted that liability for cyber-physical security incidents would pierce the corporate veil and that this would result in personal liability for 75% of CEOs by 2024. Now that 2024 has arrived, Bill Mew asks where we all stand in relation to accountability for cybersecurity incidents.

Gartner’s prediction assumed that the nature of cyber-physical systems (CPSs) meant that incidents could quickly lead to physical harm to people, destruction of property or environmental disasters, thus triggering liability.

Previously measures to combat health and safety abuse had been ineffective until corporate manslaughter provisions were introduced that not only held companies to account, but also their directors.

While a few cyberattacks on hospitals have led directly to loss of life, physical harm to people, property and the environment has so far been limited. However, we have seen the frequency and sophistication of attacks increase and consequently the financial impact of incidents escalate exponentially.

Combating financial losses from financial crime had also been ineffective until countries like the UK introduced regulations like Senior Managers and Certification Regime (SMCR) to make company directors liable.

There have been isolated cases like Uber, where its CSO Joe Sullivan faced personal charges after a data breach, and SolarWinds, where its CISO Timothy Brown encountered financial penalties. However, few CISOs or other board level executives have yet been held personally liable for cyber incidents. This does not mean that there isn’t palpable fear among CISOs that they risk in effect becoming Cyber Incident Scapegoat Officers.

New Wave of Regulation and Litigation

Shareholder derivative actions are lawsuits against a company’s directors and officers (including general counsel) that date back to the 1996 Caremark decision, in which the Delaware Chancery Court declared that directors can be held personally liable for failing to “appropriately monitor and supervise the enterprise.”

Thus, directors and officers that demonstrate a “conscious disregard” for their duties or ignore “red flags” can be held personally liable for a corporation’s losses. While the Caremark case did not address information assets and corporate duties to protect them, no good reason exists to distinguish past Caremark decisions on lax legal compliance and accounting controls from potential widespread failures to implement and maintain appropriate risk management policies.

Target Corporation was one of the first to face a number of such lawsuits after its payment system exposed the financial information of 110 million customers in 2013. A class of consumers sought damages for its alleged negligence in exposing their personal financial information, and a group of banks sought reimbursement for the cost of reimbursing fraudulent charges and for replacing credit and debit cards.

More recently, in 2023 the Chairman of the Australian Security and Investment Commission, Mr Longo, was reported to have said: “If boards do not give cybersecurity and cyber resilience sufficient priority, this creates a foreseeable risk of harm to the company and thereby exposes the Directors to potential enforcement action by ASIC based on the Directors not acting with reasonable care and diligence …”

Personal liability for directors, will hinge on two aspects: firstly, if directors turned a blind eye to a security risk, and secondly, if the cyberattack took advantage of the security gap left by the first decision.

Predicting exactly how, where or when an attack will occur is almost impossible – if it were possible then prevention would be easy. Therefore, risk management guru Nassim Taleb suggests that: “You must invest in preparedness and not in prediction.”

Not only will being aware of a vulnerability and failing to take action result in exposure for directors, but it is likely to also nullify any cyber insurance policy.

Conversely adequate preparedness – everything from prevention and detection to training and incident response rehearsal – will likely be sufficient to demonstrate adequately responsible measures had been taken – however unfortunate you are thereafter in suffering cyberattacks.

On the regulatory front, GDPR already mandates that you regularly assess and test systems and processes – which would include testing your backups and you incident response plans. DORA and other new measures are enforcing the need for enhanced measures for critical infrastructure and the SEC has introduced incident reporting requirements.

The more that such regulatory requirements introduce further obligations, the greater the risk is that directors will fail to meet them all. Thus the threshold for what counts as failing to “appropriately monitor and supervise the enterprise,” is increasing all the time.

Any failure to keep pace with these requirements will not only undermine any argument before the regulator that you acted reasonably and responsibly, but also open the door to shareholder derivative actions and personal director-level liability.

Don’t say that you weren’t warned!

Bill Mew

Bill Mew

Bill is high profile campaigner for digital ethics and the balance of ‘meaningful protection’ (cybersecurity, privacy, digital ethics, etc.) and ‘maximisation of economic & social value’ (AI, cloud, digital transformation, innovation, etc.). He's a prolific speaker, columnist, author, influencer, analyst and pundit. He has more broadcast airtime than any other technologist in the UK, appearing regularly on TV & Radio (BBC, RT, etc) on a broad range of business & technology topics, and was named as the world’s top expert/influencer for data privacy & security by Onalytica.

Related Posts

Cyber Security

The Quantum Cybersecurity Imperative: Securing the Mining Enterprise for the Future

August 29, 2026
Cyber Security

Open Secure AI Alliance: A Pragmatic Imperative for Digital Defence

July 31, 2026
Cyber Security

Executive Overview of the Notifiable Data Breaches (NDB) scheme

August 5, 2026
No Result
View All Result

Recent Posts

  • The 80% Crisis: UK Data Leaders Warn Our Data Isn’t Ready for AI
  • The AI Illusion: Craig S. Mullins Exposes The Hidden Costs Crippling Modern Data Architectures In His Latest Book
  • The 80% Crisis: America’s Data Leaders Warn Our Data Isn’t Ready for AI
  • Building No-Regret Quantum Readiness in the Mining Sector
  • The Quantum Cybersecurity Imperative: Securing the Mining Enterprise for the Future
Elnion

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Cloud
  • Data
  • Digital Enterprise
  • Telco & Mobile
  • Cyber Security
  • Infrastructure
  • Automation
  • Supply Chain

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In