Insights
Cybersecurity
65 articles on cybersecurity from the Law & Forensics team.
Breach response, regulatory exposure and the standard of care — analysed from the position of the expert who has to explain an intrusion to a court or a regulator, not from a vendor's. Covers SEC enforcement, incident response, and what a defensible security program looks like after the fact.
June 4, 2026
After SolarWinds: The SEC's Narrowed Cyber Enforcement Posture and What It Really Means for CISO Personal Liability
The SEC's with-prejudice dismissal of its landmark action against SolarWinds and CISO Timothy Brown has reshaped the personal-liability calculus for security executives — but the four-business-day disclosure rules remain operative, private claims are unaffected, and board-level fiduciary exposure is intensifying. This article maps what changed, what did not, and what in-house counsel should do now.
June 2, 2026
AI Without Guardrails Is a Liability: Building the Governance Framework Your Organization Actually Needs
Enterprises racing to deploy AI and machine learning are generating new categories of legal and regulatory risk faster than their governance structures can absorb them. The organizations that get this right are not the ones moving fastest — they are the ones that built the compliance architecture first.
June 2, 2026
Ransomware's Legal Minefield: Why Paying Up Can Be Just the Beginning of Your Problems
Ransomware victims face a layered legal crisis that begins — not ends — with the ransom decision. OFAC sanctions exposure, SEC disclosure obligations, and insurance coverage disputes create a gauntlet that organizations must navigate in hours, not days. Here is the legal playbook.
June 2, 2026
The Board's New Cyber Mandate: SEC Disclosure Rules, the Attestation Chain, and the Case for Independent Audits
The SEC's 2023 cybersecurity rules turned oversight into a documented chain that runs from the security team, through the boardroom, and into a company's public filings. For directors, that chain is now the exposure surface — and independent audits are what make it defensible.
June 2, 2026
Your Vendors Are Your Weakest Link: The Legal Strategy for Third-Party Cyber Risk
Organizations spend billions hardening their own perimeters while their vendors — who hold sensitive customer data, process transactions, and operate inside enterprise networks — often run at a fraction of that security maturity. The legal consequences of that asymmetry land on the organizations that hired them, not the vendors that failed.
February 20, 2026
Deepfake Defense: Securing Real Estate Transactions in the Age of AI
AI voice and video deepfakes are turning real estate closings into prime targets for wire fraud and impersonation. Here is how to verify identity and defend the funds flow.
October 22, 2025
Think Like a Hacker; Plan Like a Lawyer
Cybersecurity is a critical concern for all businesses, including small law firms and solo practitioners.
January 9, 2025
Banks’ Reactive Approach To Fraud Is No Longer Sufficient
Banks today face a formidable challenge in combating fraud amid rapid digital transformation.
December 20, 2024
Arbitrating Smart Contract Disputes: A Comprehensive Approach
However, as with any contractual arrangement, disputes can arise, necessitating effective dispute resolution mechanisms.
September 26, 2024
Inside the Clubhouse: The Growing Cyber Threats Facing Country Clubs
Country clubs have become increasingly attractive targets for cybercriminals.
September 2, 2024
AI: A Shield Against Cybercrime
As we have grown to rely more and more on dependent on digital methods of conducting business, and information is the new currency, cybercrime has become a pervasive threat.
August 14, 2024
Financial Institutions Guide to Cybersecurity and Operational Resilience
The financial industry operates in a complex and dynamic landscape, characterized by increasing digitalization, regulatory scrutiny, and the ever-present threat of cyberattacks.
July 29, 2024
Cybersecurity in Multidistrict Litigation
MDLs can pose unique challenges for cybersecurity litigators as MDLs often involve large volumes of data that may be consolidated from disparate sources.
July 29, 2024
Neom: A Techtopia?
Rising from the Saudi Arabian desert sands, Neom promises to be a futuristic metropolis, a beacon of technological innovation and sustainable living.
May 13, 2024
Navigating personal liability: post data-breach recommendations for CISOs
CISOs can avoid being liable for data breaches by following legal advice, communicating effectively with internal and external stakeholders, and demonstrating commitment to avoid future incidents.
May 9, 2024
Guidance for CISOs After United States v. Sullivan and SEC v. SolarWinds
Two landmark enforcement actions have reshaped CISO personal liability. Here is what Sullivan and SolarWinds mean for disclosure, documentation, and the CISO-counsel relationship.
April 18, 2024
From Niche to Universal: The Broadened Application of NIST Cybersecurity Framework 2.0
NIST CSF 2.0 expands beyond critical infrastructure to every organization and adds a new Govern function—reshaping how legal and compliance teams approach cyber risk.
March 26, 2024
Independent Cybersecurity Audits Are Powerful Tools for Boards
Board members today increasingly face personal liability for their organization’s cyber posture. This has raised the stakes of attestations and created a need to gain insight into cyber programs.
March 19, 2024
Small Law Firms Must Take Action and Address Cybersecurity and Privacy Regulations
Cybersecurity and privacy regulations have become increasingly important in recent years due to the exponential growth of technology and the internet.
November 14, 2023
Between Disclosure and Discretion: The SEC's Cybersecurity Rules and Trade Secret Protection
The SEC's cyber incident-disclosure rules force public companies to describe breaches publicly while protecting trade secrets. Here is how counsel can satisfy both obligations.
August 28, 2023
SEC’s New Cybersecurity Rules and Protection of Trade Secrets
In fact, a stated intent of the SEC in promulgating the new rules is transparency that promotes a culture of accountability and vigilance.
August 21, 2023
SEC Cybersecurity Regulations Impacting Corporate Governance
Corporate cybersecurity has become a non-negotiable priority. In part due to the recent rules promulgated by the Securities and Exchange Commission (SEC).
August 21, 2023
How the SEC is Transforming Corporate Cybersecurity Oversight
Corporate cybersecurity is now a non-negotiable priority.
August 21, 2023
Protecting Against State-Sponsored Cyber Hostilities
State-sponsored cyber hostilities are becoming more common and sophisticated as the world becomes increasingly connected and digital.
December 14, 2022
NYDFS Cybersecurity Regulation: The Second Amendment to 23 NYCRR 500, Now Fully in Force
NYDFS adopted the Second Amendment to its Cybersecurity Regulation 23 NYCRR 500 on November 1, 2023. Every phased compliance deadline has now passed — here is what the amended regulation requires of covered entities today.
November 9, 2022
To Catch a Trade Secret Thief With Forensic Neutrals
Remediating the theft of a trade secret can be likened to a dried red wine stain on your favorite white shirt.
July 15, 2021
Ransomware Payments, OFAC Compliance, and Avoiding Liability
Paying a ransomware demand can expose an organization to sanctions liability. Here is how GCs, CISOs, and incident-response teams reduce OFAC risk.
June 22, 2021
Smart Contracts & Cryptocurrency Made Simple
A senior lawyer asked his colleague “So when did Smart Contracts become “a thing”?
May 26, 2021
Attracting Top Cybersecurity Talent to the Federal Government: A Simple Yet Bold Solution
As one DHS official put it, the challenges with recruiting cybersecurity workers to the government is a “national security issue”.
March 29, 2021
Trade Secrets: Is Litigating Infringement Worth It? What Can Be Done Instead?
However, information deemed a trade secret is not protected by a patent, copyright, or trademark. Such information is protected by keeping it under wraps.
March 10, 2021
Questions to Ask Law Firms to Know if They Were Compromised?
Most law firms practice law. Only a handful operate as global companies and even fewer invest significantly in cybersecurity annually.
February 15, 2021
I Could Be Prosecuted for Paying Ransomware Ransom! How is that Possible?
As our world becomes increasingly technologically driven, the risk of cybercrimes rises exponentially.
November 11, 2020
The COVID-19 Impact on Arbitration & How To Navigate Virtual Proceedings
Legal proceedings have traditionally been in-person activities, with counsel, parties, witnesses, and the judge, arbitrator or mediator all physically present.
September 11, 2020
Arbitration During A Global Pandemic: How to Properly Leverage Zoom and Similar Platforms to Conduct Arbitration Hearings
First, parties must identify a platform (e.g., Zoom) which will be the presumptive platform used for the arbitration hearing, absent any other orders by the arbitrator.
August 31, 2020
Employer Best Practices for Monitoring Remote Devices
All of these exceptions decrease an individual’s privacy rights and reasonable expectation of privacy in work-related matters.
August 6, 2020
Here’s Why Your Employer May Monitor Your Personal Files On Company Devices
It is generally well-known that individuals have a significantly lower expectation of privacy with regard to anything done at or for work than they do with things at home or in their personal lives.
August 4, 2020
Customizing Traditional Models of Mediation to Work in Today’s Covid-19 Environment
Mediation is often viewed by lawyers as a “this” or “that” on the spectrum from facilitative to evaluative.
July 7, 2020
Defining Cyber Threats
Insurance policies often contain so-called war exclusions. These provisions, which can differ significantly in how they are worded, purport to limit coverage for losses arising out of war or warlike actions.
June 30, 2020
Migrating Away From Traditional Models Of Mediation
Mediation is often viewed by lawyers as a “this” or “that” on the spectrum from facilitative to evaluative.
January 1, 2019
Reviewing 2018 And Predicting What’s Ahead In Cybersecurity
CyberInsecurity News: One of the things that you were talking about early last year was vendor vulnerability—that is, vulnerable to cyberattacks. And that was going to be a big issue.
December 28, 2018
Spearfishing Can Be Stopped Once You Remove The Bait
Spearfishing, whaling, fishing, and all other variations of email scam are plaguing law firms, businesses (big and small), and any company or individual who uses email.
October 8, 2018
Why is Cybersecurity Important?
Although it may seem like small businesses aren’t the main targets for cybercrime, they actually are quite appealing because they aren’t as hard to crack.
September 21, 2018
Separate The NSA and Cyber Command Now
Today, U.S. Cyber Command and the National Security Agency operate under one overarching structure.
April 1, 2018
Predictions And Threats For The Year In Cybersecurity
What potential targets strike you as the most important for in-house lawyers to pay attention to? Daniel Garrie: Vendors and supply chains.
March 15, 2018
White Paper: Authenticating Social Media Evidence
Social media evidence in particular presents unique challenges as to authentication because it can be difficult to attribute statements or actions taken via the Internet to a specific person.
July 31, 2017
Cybersecurity Risks In The Courtroom
Because of the level of accessibility of courts, security has traditionally focused on aspects of physical security such as the guidance published by The National Center for State Courts.
May 9, 2017
Can Congress do anything to address SS7 risks? Some say yes
Politicians are becoming increasing aware and concerned about cybersecurity issues.
April 1, 2017
The Evolving Effect of Technology in Litigation
The rise of technical issues in litigation is steadily increasing the time and cost of resolving lawsuits. The average civil litigation in federal court takes upwards of 24 months to reach a resolution on the merits.
March 9, 2017
What Lawyers Are Asking About the New York DFS Cybersecurity Regulation
DFS received varied, but primarily negative feedback on the proposed Regulation, as any commentators condemned the proposed Regulation as being too prescriptive and burdensome on Covered Entities.
January 23, 2017
A New Focus on Law Firm Cybersecurity
Law firms have long held a hallowed position in the corporate world, as the preeminent keeper of confidences.
September 26, 2016
The Panama Papers: How to keep your firm out of the headlines
Law firms have long held the position in our society of being problem solvers. They untangle the mess of business and create rules for society.
September 16, 2016
Looking Beyond Courthouse To Resolve Data Breach Disputes
As the number and severity of data breaches have increased in recent years, there has been a corresponding rise in data breach litigation in courts across the United States.
July 12, 2016
Do the Pokémon Go: Information Security in the Physical World
Additionally, business owners have been able to use the game to develop new business by advertising what Pokémon are available in the shop.
June 2, 2016
Encryption for Lawyers
Why should lawyers be interested in encryption?
June 1, 2016
An Unsatisfactory State of the Law: The Limited Options for a Corporation Dealing with Cyber Hostilities by State Actors
To read the full article, go to Cardozo Law Review.
April 29, 2016
The Voyeur among Us: Navigating Around the Global Spyware Epidemic
Spyware poses a serious threat of privacy infringement to unassuming internet users across the globe.
February 26, 2016
Privacy Vs. Accessibility: Can They Coexist In Cyberspace?
The public safety versus privacy debate regarding cybersecurity and end-to-end encryption has entered the mainstream of society and jurisprudence.
February 24, 2016
‘Ten Commandments’ of Cyber Security Can Enhance Safety
Imagine you are admitted to a hospital for treatment of a serious but treatable illness, and then your records are stolen.
January 1, 2016
The Need for Private-Public Partnerships Against Cyber Threats — Why A Good Offense May be Our Best Defense.
The Internet has delivered on its promise of social and economic progress.
December 17, 2015
So You’re Telling Me There’s a Chance: How the Articles on State Responsibility Could Empower Corporate Responses to State-Sponsored Cyber Attacks
This article begins with a brief summary of the international legal framework that regulates state interactions.
December 2, 2015
The ‘Soft Power’ War ISIS Doesn’t Want
Again, we stand in shock, but not in real surprise. It takes careful planning to inflict indiscriminate violence and bloodshed upon the world — and the confusion, fear and anger that follows.
April 15, 2015
Guarding Against a ‘Cyber 9/11’
The Internet provides an easy, low-cost and low-risk means for nonstate actors or terrorist groups to amplify the impact of any attack.
May 4, 2008
Parasiteware: Unlocking Personal Privacy
Spyware presents a threat of privacy infringement to unassuming internet users irrespective of their country of citizenship.
June 14, 2006
Coddling Spies: Why the Law Doesn’t Adequately Address Computer Spyware
Consumers and businesses have attempted to use the common law of torts as well as federal statutes like the Computer Fraud and Abuse Act, the Stored Wire and Electronic Communications and Transactional Records Act, and the Wiretap Act to address the expanding problem of spyware.
June 14, 2006
Warning: Software May Be Hazardous to Your Privacy!
Spyware poses a serious threat of privacy infringement to unassuming internet users across the globe.
Have a matter that turns on the evidence?
Tell us what you're facing and we'll point you to the right team.

