Data Breach Fallout: Do CISOs Need Legal Protection?
Since the security executive is on the hot seat after a data breach, some industry experts suggest CISOs get themselves some form of liability protection. The downside is that such protection could shield those who deserve the blame for an incident.
» View Article
Data Breach Fallout: Do CISOs Need Legal Protection?
Since the security executive is on the hot seat after a data breach, some industry experts suggest CISOs get themselves some form of liability protection. The downside is that such protection could shield those who deserve the blame for an incident.
» View Article
It's a sad state of affairs that its come to this. I'm not sure what the liability will protect from - civil action against the individual, or some sort of monetary protection in case the individual is terminated. http://whistlersear.wordpress.com
Having had to hire an employment lawyer (under retainer), secure a safety deposit box, store encrypted data on a hard drive in the box and in an out of state location in a safe while serving as a CISO for a $3B firm, I'd say that private insurance is warranted to protect CISO's not from outside prosecution but from inside persecution.
Buckeroo Banzai, you should contact me at hate.spam@mac.com. As a former CISO myself, I hear you loud and clear.
This article was good and timely. I have heard from many CSOs and CISO that have been retaliated against after "issues" have occurred in their former organizations. The sad thing about this is the role is turning into a place to focus blame if something happens, kinda like a CIO insurance policy. Insurance should be there for the internal side mostly.
Another sad note is that many law firms have not risen to the challenge in understanding employment, information technology and regulatory law as a whole.
It really goes far deeper than that where we as CISOs or CSOs must think like an attorney to protect ourselves and our companies we work for. I have this coverage much like an errors and omissions policy would cover corporate executive officers and independent practitioners like myself. Some corporations do extend this down to the CSO but many do not, ask your employer's HR department if this is the case.
The challenge with the executive culture is get them to "buy in" to the fact security is a vital and visionary part of the business. Some do not want to sign off on the risk even after you explained to them the consequences if they do not put the effort to mitigate the risk. So you document the fact to cover yourself and lose your job because of it or they make your job more difficult enough to resign. Most think of security as an overhead expense often times the CISO reports to the CIO instead of being a peer. The CISO position becomes nothing more than a figurehead to the company doing everything from soup to nuts. Some cultures are very proactive and embrace and value of our responsibilities within the organization. The point is if the CEO and top management do not embrace information security what makes you think the rest of the organization will also? It is an uphill battle for most that ends up in frustration, a dead end job and I can give you countless organizations this is the case right now where the role of security is buried somewhere within the confines of IT and not at the visible executive forefront where it belongs. And when a breach occurs even with the best iron clad security policies and procedures in place, oh yes the CISO often is the fall guy.
I have studied security breaches that went into litigation and these have had far reaching impact to organizations. Here is one:
Company: Choicepoint
And yet another:
Company: Guidance Software
failing to implement simple, low-cost, and readily available defenses to such attacks.
failing to use readily available security measures to monitor and limit access from the corporate network to the Internet.
The legal cases are replete with security breach litigations costing corporations millions if not billions. This is why I am an advocate for CISOs to protect themselves
Anyone is welcome to contact me.
George Moraetes, CISM
Information Security Executive and Enterprise Architect
Web: http://www.moraetes.com
Linkedin: http://www.linkedin.com/in/moraetes
www.GreatLegalHelp.com/bg3
We had a similar problem in our organization (an association of IT management professionals). Nothing was commercially available to provide our members with any form of protection.
Eventually, we went directly to the insurance carriers and had them create a product specifically for us. Not exactly an easy path for many companies but the need for it definitely exists.
Dirty Tricks: Social Engineers' Favorite Pickup Lines
Tabletop Exercises: 3 Sample Scenarios
19 Ways to Build Physical Security Into Your Data Center
Get instant notifications when whitepapers, webcasts and case studies are added to our library. Sign up for a Resource Alert now!
CSO Corporate Partners
» More blogs
CSO Perspectives
Santa Clara, California
(ISC)2 members can earn up to 24 CPE Credits!
Trend Micro ranked #1 against real-world malware. Read more.
64-page prescriptive guide to security, compliance, and IT operations.
Removing Barriers To Better Server Virtualization Efficiency
Mining for Gold: Cybercrime Prevention and the Role of Log Management
The Executive Guide to Data Loss Prevention
Organizations can spend up to 50% more on compliance efforts than necessary.
White Paper: A Security Blueprint Delivered From within the Network
Read the RSA report: Security for Business Innovation
Upgrading to VMware vSphere with vWire
Explore the increasing importance of log management as cybercrime threats grow.
The Tripwire HIPAA Solution: Meeting the Security Standards Set Forth in Section 164
Implementing Best Practices for Web 2.0 Security
Five Ways to Reduce Your IT Audit Burden
THE IDG NETWORK