Aboutwhy sjkplawyerspracticesInsightsCase StudyNewsLocations
Digital Evidence

Cybersecurity Governance

Directors are rarely asked to understand firewalls. They are increasingly asked to show that they understood the company's cyber risk well enough to oversee it, and that they acted on what they were told.

Reviewed

01 GUIDE

Cybersecurity Governance: what usually happens

What oversight is expected to look like

Corporate law in Delaware and many other states expects directors to make a good-faith effort to monitor risks central to the business, and for many companies cyber risk now falls in that category. Public companies must describe in their annual reports how the board oversees cybersecurity risk and how management assesses and manages it. In New York, financial services companies supervised by the Department of Financial Services face specific governance requirements, including oversight by the senior governing body and regular reporting from the person responsible for security. None of these frameworks expects directors to run security themselves. They expect a structure in which material information reaches the people accountable for acting on it.

The paper trail that gets read later

After a serious incident, minutes and board materials are among the first documents requested by plaintiffs, regulators, and investigators. A record showing that the board heard about known weaknesses, asked questions, and followed up on remediation reads very differently from one where cyber risk appears as a single line on a crowded agenda. Reports from the security function should describe real risks and progress in plain terms rather than reassurance. It also matters which committee holds the responsibility and whether anyone on it can probe the answers given. Outside briefings help, but they do not replace a regular reporting cadence the company actually follows.

Clarifying roles before they are tested

Many governance gaps are simple ambiguities: nobody is sure whether the security lead reports to technology, legal, or the chief executive, or who can authorize spending in a crisis. We start by reviewing how cyber risk currently reaches management and the board, what the company already discloses about that process, and whether the description matches practice. A mismatch between what a company says publicly about its oversight and what actually happens is itself a source of exposure. From there we recommend changes proportionate to the size of the business and the regulators it answers to.

02 ATTORNEYS

Who you would be working with

Attorneys at our New York and Washington, D.C. offices handle matters like this one.

04 HOW WE WORK

Client-centered service across jurisdictions

Global Coordination & Expertise

We deliver coordinated and effective legal services to our clients, utilizing our extensive legal resources and experienced attorneys in our well-integrated global network. Through our Washington D.C. and New York offices, together with our alliance

Multilingual & Cross-Border Communication

Our attorneys are experienced in both domestic and international matters and, with fluency in various languages, provide clear and consistent communication at every stage of your legal process.

Client-Centered Approach

Client service lies at the heart of our operations. From the initial consultation, we prioritize understanding your situation, listening to your goals, and providing regular updates and strategies tailored to your individual case.

Multidisciplinary & Efficient Solutions

Our multidisciplinary approach and established processes enable us to address cross-border challenges with efficiency.

05 OFFICES

Where we meet clients

Consultations are available in person or remotely.

New York

285 Fulton Street, New York, NY 10007
(855) 529-7557

Washington, D.C.

Suite 985, 1717 K Street NW, Washington, DC 20006
(855) 529-7557

Los Angeles

1901 Avenue of the Stars, Suite 820, Los Angeles, CA 90067
(424) 561-7557

Attorney Advertising. This page is general information about cybersecurity governance and is not legal advice. Reading it does not create an attorney-client relationship. Outcomes depend on the facts of each matter, and prior results do not guarantee a similar outcome. Laws differ by state and change over time.