Cybersecurity and Board Oversight

Mayer Brown Free Writings + Perspectives
Contact

Mayer Brown Free Writings + Perspectives

In a recent speech, SEC Commissioner Kara Stein commented on the importance of cybersecurity.  The Commissioner noted that encouraging adoption of written policies and procedures, voluntary frameworks and non-binding guidance was not sufficient.  She noted that boards of directors have a fiduciary duty to shareholders to monitor and oversee risk, including cybersecurity oversight.  She seems to suggest that just as Commission rules require disclosure regarding financial experts, it would be reasonable for there to be some disclosure as to whether boards have an independent director with expert knowledge of technology and cybersecurity.  Otherwise, boards should retain experts to provide advice.  The Commissioner suggests independent directors meet with the company’s chief information security officer at least twice a year in executive session.  She notes that boards should assess company disclosures regarding cyber risks.  Finally, she suggests that the board ought to consider how well prepared the company is to respond to a breach, the resiliency of its infrastructure, and the procedures that will be implemented to recover and resume operations.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Mayer Brown Free Writings + Perspectives | Attorney Advertising

Written by:

Mayer Brown Free Writings + Perspectives
Contact
more
less

Mayer Brown Free Writings + Perspectives on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide