As the SEC pursues an unprecedented enforcement action against SolarWinds and its CISO, the CISO community needs clarity and reassurance that their good faith judgments will not subject them to personal liability. We propose a framework for CISO liability that turns on good faith, recognizing that effective cyber risk management requires a whole-of-company approach.
Andrew Ceresney, Charu Chandrasekhar, Luke Dembosky, Erez Liebermann, Julie Riewe, Anna Moody, Andreas Glimenakis, and Melissa Muse outline how #CISOs can avoid #liability from the U.S. Securities and Exchange Commission for #cybersecurity lapses leading to a #databreach in NYU Program on Corporate Compliance and Enforcement's blog: https://lnkd.in/eQec2r_U Jennifer Arlen, Joseph Facciponti, Carolyn R Pautz, PhD, Julius Sim
Senior Counsel at TD
10moThanks for raising an important issue.