Back in 2020 Gartner Inc. predicted that liability for cyber-physical security incidents would pierce the corporate veil and that this would result in personal liability for 75% of CEOs by 2024. Now that 2024 has arrived, Bill Mew asks where we all stand in relation to accountability for cybersecurity incidents.
Gartner’s prediction assumed that the nature of cyber-physical systems (CPSs) meant that incidents could quickly lead to physical harm to people, destruction of property or environmental disasters, thus triggering liability.
Previously measures to combat health and safety abuse had been ineffective until corporate manslaughter provisions were introduced that not only held companies to account, but also their directors.
While a few cyberattacks on hospitals have led directly to loss of life, physical harm to people, property and the environment has so far been limited. However, we have seen the frequency and sophistication of attacks increase and consequently the financial impact of incidents escalate exponentially.
Combating financial losses from financial crime had also been ineffective until countries like the UK introduced regulations like Senior Managers and Certification Regime (SMCR) to make company directors liable.
There have been isolated cases like Uber, where its CSO Joe Sullivan faced personal charges after a data breach, and SolarWinds, where its CISO Timothy Brown encountered financial penalties. However, few CISOs or other board level executives have yet been held personally liable for cyber incidents. This does not mean that there isn’t palpable fear among CISOs that they risk in effect becoming Cyber Incident Scapegoat Officers.
New Wave of Regulation and Litigation
Shareholder derivative actions are lawsuits against a company’s directors and officers (including general counsel) that date back to the 1996 Caremark decision, in which the Delaware Chancery Court declared that directors can be held personally liable for failing to “appropriately monitor and supervise the enterprise.”
Thus, directors and officers that demonstrate a “conscious disregard” for their duties or ignore “red flags” can be held personally liable for a corporation’s losses. While the Caremark case did not address information assets and corporate duties to protect them, no good reason exists to distinguish past Caremark decisions on lax legal compliance and accounting controls from potential widespread failures to implement and maintain appropriate risk management policies.
Target Corporation was one of the first to face a number of such lawsuits after its payment system exposed the financial information of 110 million customers in 2013. A class of consumers sought damages for its alleged negligence in exposing their personal financial information, and a group of banks sought reimbursement for the cost of reimbursing fraudulent charges and for replacing credit and debit cards.
More recently, in 2023 the Chairman of the Australian Security and Investment Commission, Mr Longo, was reported to have said: “If boards do not give cybersecurity and cyber resilience sufficient priority, this creates a foreseeable risk of harm to the company and thereby exposes the Directors to potential enforcement action by ASIC based on the Directors not acting with reasonable care and diligence …”
Personal liability for directors, will hinge on two aspects: firstly, if directors turned a blind eye to a security risk, and secondly, if the cyberattack took advantage of the security gap left by the first decision.
Predicting exactly how, where or when an attack will occur is almost impossible – if it were possible then prevention would be easy. Therefore, risk management guru Nassim Taleb suggests that: “You must invest in preparedness and not in prediction.”
Not only will being aware of a vulnerability and failing to take action result in exposure for directors, but it is likely to also nullify any cyber insurance policy.
Conversely adequate preparedness – everything from prevention and detection to training and incident response rehearsal – will likely be sufficient to demonstrate adequately responsible measures had been taken – however unfortunate you are thereafter in suffering cyberattacks.
On the regulatory front, GDPR already mandates that you regularly assess and test systems and processes – which would include testing your backups and you incident response plans. DORA and other new measures are enforcing the need for enhanced measures for critical infrastructure and the SEC has introduced incident reporting requirements.
The more that such regulatory requirements introduce further obligations, the greater the risk is that directors will fail to meet them all. Thus the threshold for what counts as failing to “appropriately monitor and supervise the enterprise,” is increasing all the time.
Any failure to keep pace with these requirements will not only undermine any argument before the regulator that you acted reasonably and responsibly, but also open the door to shareholder derivative actions and personal director-level liability.
Don’t say that you weren’t warned!



