CISO Liability Concerns Grow with Enhanced Disclosure Rules

Chief Information Security Officers (CISOs) face growing personal liability risks amid increasing cybersecurity threats and stricter regulations. Recent Securities and Exchange Commission (SEC) actions have targeted CISOs individually. For the first time, the SEC charged a CISO with fraud and internal control failures related to cybersecurity. New SEC disclosure rules now require timely reporting of … Read more

SEC Hits Firms with Millions in Fines for Inadequate Cyber Disclosures; Sparks Dissent on Commission

Four companies have settled charges by the Securities and Exchange Commission (SEC) that they made “materially misleading disclosures” after being breached in 2020 by the SolarWinds’ Orion software hack (US public companies have been required to disclose material cyber events since last year, see this.) But two of five SEC commissioners dissented on the charges, … Read more

Ransomware Response Must Evolve: Deputy National Security Adviser Calls for Ban on Ransomware Payments

Anne Neuberger, the U.S. Deputy National Security Adviser for Cyber and Emerging Technology, wrote an opinion piece in the Financial Times on the evolving nature of ransomware attacks and the need for an updated response. This piece revisits the issue of banning ransomware payments, a topic we’ve previously covered as the ransomware crisis continues to … Read more

Cyber Insurance Captives and ILS (Insurance-Linked Securities) Cyber Vehicles Multiply in Bermuda: BMA

We’ve discussed other findings from the recent Bermuda Monetary Authority (BMA) report, but we’re also struck by the increase in cyber insurance captives and cyber ILS vehicles documented by the financial regulator. The growth of Cyber Insurance Captives and Cyber ILS (Insurance-Linked Securities) is all related to the growth of reinsurance in the cyber market; … Read more

AI to the Rescue for Cyber Insurers? Not so Fast, Says New York State

“Artificial intelligence systems” (“AIS”) and “external consumer data and information sources” (“ECDIS”) can help insurers and companies, New York State regulators concede, but the technologies better not hurt “protected classes” or “perpetuate or amplify systemic biases that have resulted in unlawful or unfair discrimination,” warns the state in new regulatory guidance. Given the complexity of … Read more

×