DATA BREACHES: ARE CHIEF INFORMATION SECURITY OFFICERS NOW IN LEGAL PERIL?
| Date | 01 July 2023 |
| Author | Kempton, Natalie |
| Published date | 01 July 2023 |
I. Introduction
Nearly fifteen billion data records have been compromised by cybercriminals in the past decade. (1) Companies' cybersecurity is at an all-time low as a result of advancements in technology and side effects of COVID-19. (2) Cybersecurity is the protection of devices, data, and networks from unlawful use and practice. (3) Cybersecurity is critical because there are many risks that come with poor cybersecurity safeguards, such as data breaches. (4) Data breaches reveal protected or sensitive information and can affect virtually every individual, organization, or corporation who uses any type of technology. (5) According to the 2021 Thales Data Threat Report, 45% of U.S. companies experienced a data breach in 2020. (6) These cybersecurity breaches have a variety of negative repercussions, such as significant financial losses and a lack of trust in essential emerging technology despite technological advancements having the capability to greatly benefit the world we live in. (7)
American Corporations are the most susceptible targets of data breaches and have historically reacted to increasing cyberattacks by creating a stronger emphasis and focus on amplifying cybersecurity as a defense. (8) As a response to breaches, the C-level position of Chief Information Security Officer (CISO) was created and instituted in many companies in the early 2000s. (9) This executive position is designed to hone in on an organization's security operations, cyber risks, data loss investigations, program management, and governance. (10) CISOs are expected to be a strong leader for company protection and mitigation of security risks as they work with other executives to establish and maintain ardent security policies. (11)
Historically, CISOs have not been held legally liable for data breaches or cybersecurity issues that a company sustains. (12) However, this shield of liability appears to be in jeopardy as the federal government prosecuted and convicted a CISO of a company for concealing a data breach for the first time in U.S. v. Sullivan. (13) U.S. v. Sullivan is stirring up the cyber protection community and causing many C-level executives to worry about their potential liability when handling data breaches within their company. (14) U.S. v. Sullivan potentially creates a new precedent that CISOs will be held solely, legally accountable for their company's failure to properly handle a data breach. (15)
There is a strong consternation from many CISOs and other security professionals that U.S. v. Sullivan initiates a new precedent that encourages the criminal prosecution of CISOs for mishandling data breaches in the past, present, and future. (16) This note addresses this apprehension and argues that executives should not be held exclusively liable for data breaches within their companies regardless of when the potential mishandling of the data breach occurred. A company should continue to be the only entity held accountable for data breaches rather than an individual CISO if other executives and employees were aware of the breach. This note will contend that CISOs should especially not be held criminally liable for failing to disclose data breaches because not only do CISOs not have enough control in a company to be held solely accountable for a cybersecurity breach, creating this precedent will also dissuade people from taking CISO roles in the future. (17) The government should rather maintain an open line of communication with CISOs and encourage early reporting instead of emphasizing the unnerving consequences of mishandling complex data breaches.
II. History
A. The Evolution of Data Breaches
Data breaches were first accounted for over a half-century ago in the 1980s when home computers became commonplace for the average American household. (18) Breaches in the 1980s and 1990s were much less sophisticated, consisting mainly of low-technology hacking engendered primarily by human error or relatively simple computer viruses. (19) Substantial breaches remained a scarcity until the early 2000s when mobile devices and portable computers became a commonality to American society with the expansion of this higher technology. (20) The first major data breach that transpired during this new age of technology in the 2000s was at DSW Shoe Warehouse, where over 1.4 million credit card numbers were stolen in 2005. (21) The DSW breach exhibited that the expansion of technology could pose difficulties to companies data security. (22) In spite of DSW's major cybersecurity catastrophe, many corporations still did not understand or acknowledge the full extent of this technological expansion and the repercussions it could pose to their own companies. (23) Therefore, when the largest data breach to date first occurred in 2013, where hackers took records from all three billion Yahoo accounts, many companies were shocked. (24) The Yahoo breach, in addition to sparking a public interest in breaches and cyber security regulations, also increased awareness in corporations of the heightened risk posed by hackers, breaches, and the prospective grim consequences a company could suffer as a result. (25)
At present, technology is expeditiously expanding, continuously imposing new obligations on companies and their security professionals. (26) Though companies have recently commenced efforts to expand their data security to protect from cyberhackers, technology is rapidly modernizing, and the multifaceted nature of this growth is proving grueling to combat. (27) Corporations around the globe saw the aftermath of poor security practices and the diversifying technology field as major companies continue to frequently suffer from cyberattacks despite cyber-defensive actions. (28) A significant reason for this persistence of attacks is that companies are failing to mitigate risks early on before they pose a major threat to an organization. (29) Today, it is not enough to simply have an IT department with security protocols; companies now have to take preventative measures in order to stop data breaches and understand a diversity of technology infrastructures. (30) This can pose complications because a variety of new complex infrastructures have been constructed, such as SaaS applications and cloud environments, which aggravate the likelihood of data breaches even when companies intensify their cybersecurity defenses. (31)
B. The Beginning of the Chief Information Security Officer
In order to solidify internal security within companies, the role of Chief Information Security Officer (CISO) is a position that emerged in 1995 when Citicorp, now Citigroup, hired Steve Katz, the first ever CISO. (32) Katz was originally appointed to be CISO of Citicorp to augment digital defenses from cyberhackers in Russia. (33) The initial responsibilities of CISOs following Katz were mainly technical in nature requiring only some infrastructure and IT expertise. (34) However, this role has continuously expanded, and now CISO responsibilities include maintaining the knowledge of cloud computing, mobile devices, and new technological advancements as cyberattacks escalate. (35) This ongoing cyber development makes the role for CISOs working at major corporations an increasingly difficult job with the intensifying pressure of maintaining sizable defense systems for involute cybersecurity difficulties. (36) CISOs also now sustain many diverse roles on top of cyber defense advocacy such as maintaining relationships, providing leadership for security challenges, and upholding the company's cybersecurity program. (37) In addition to the surging complexity of cybersecurity, CISOs moreover must combat goal-centered executives within their corporations who do not always view bolstering security as a top priority. (38)
CISOs are on the C suite and report to different executives, such as the Chief Information Officer (CIO), Chief Financial Officer (CFO), or Chief Executive Officer (CEO) to ensure cybersecurity compliance within the entirety of the company. (39) There has recently been a shift away from CISOs reporting to the CIO as companies slowly expand the idea that cybersecurity is a company-wide issue, not just an IT issue. (40) Therefore, reporting to the CEO is becoming more commonplace as it is thought to increase coordination of cybersecurity goals within the company. (41) On top of reporting duties, CISOs also have a responsibility to maintain relationships with the employees within the company so that cybersecurity is properly acknowledged and respected by the company as a whole. (42) Therefore, due to the multifaceted nature of the responsibilities of this role, it can be an extremely challenging one to balance. (43)
C. Background on the Federal Trade Commission
The Federal Trade Commission (FTC), otherwise known as the Commission, is the federal agency who has headed investigations on data breaches since 1970. (44) The goal of the FTC is to protect American's privacy and identify the areas of priority to appropriately shield them. (45) The FTC's scope of legal authority is found in multiple places, including, Section 5 of the FTC Act which bans deceptive or unfair commercial acts, as well as within a variety of specified laws in the privacy field. (46) The three prong unfairness test used by the FTC states that an act by a company is considered unfair if it is likely to cause substantial injury to consumers, is not reasonably avoidable by consumers, or is not outweighed by benefits to consumers or competition. (47) An act is considered deceptive when there is a material representation by a company that is likely to mislead a consumer. (48) If there is no deceptive misrepresentation or the act does not fit into the three prong unfairness test, the FTC does not have legal authority to pursue a claim against a company. (49) However, even if the Commission does not pursue a claim against a company, individual offices of the U.S. Department of Justice may still file...
Get this document and AI-powered insights with a free trial of vLex and Vincent AI
Get Started for FreeCOPYRIGHT GALE, Cengage Learning. All rights reserved.
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting