Erez Liebermann’s Post

View profile for Erez Liebermann, graphic

Partner at Debevoise & Plimpton, Former Cybercrime Federal Prosecutor, Former Chief Counsel for Cyber, Privacy and Data

CISO’s feel like they are under a spotlight after the recent criminal conviction of a CISO and the charges by the SEC. The good news is that these are two examples out of hundreds of major breaches. That is, CISO liability is still extremely rare. But even these 2 instances are enough to generate very reasonable fear in the CISO community. We propose a framework for the SEC to consider before they act on this again.

View profile for Joseph Facciponti, graphic

Executive Director, NYU Law Program on Corporate Compliance and Enforcement | Former SDNY Federal Prosecutor | Law Professor

  • No alternative text description for this image
Sean L Harrington

privacy attorney, digital forensics examiner, adjunct professor, cybersecurity advisor

9mo

Conviction? I thought he was only charged, just a few weeks ago. Did he plead out?

Like
Reply
Lucie Ellis, SHRM-SCP®, RMP®, PMP®, A-CSM®, M.S.

👑 Highly Accomplished Senior Executive Leader & Portfolio Director 👑 | ⭐ Gifted Senior Change Agent & Coach, Facilitator and Policy Advisor | Culture People Program Expertise | Portfolio Best Practice Gap Analysis 🎯

7mo

Nothing great has ever been accomplished by generating fear among people, regardless of whether it is reasonable or not. Honest mistakes/oversights can happen in any role at any level, and it is the actions taken after such events that really speak to the reasonableness of any subsequent investigation by external entities. Sajed Naseem I believe you have nothing to worry about even though this article is very unsettling.

Like
Reply
Christopher Hetner

Senior Executive Serving the 24,000 Member Boardroom Community | Former Senior Cybersecurity Advisory to the SEC Chair | Former US Treasury Senior Cyber Advisor & G-7 Cyber Expert | Board Director | CISO | Risk Executive

9mo

Thanks Erez Liebermann for your leadership. I advise the #cisos community to shield themselves from liability by aligning their cyber risk reporting to the NACD (National Association of Corporate Directors) boardroom standard and mapping to materiality thresholds . Learn more at https://www.nacdonline.org/nacd-board-advisory-services/cyber-risk-reporting-services/

See more comments

To view or add a comment, sign in

Explore topics