Recent incidents including SolarWinds CISO Tim Brown receiving a U.S. Securities and Exchange Commission (SEC)’s Wells Notice (a preliminary determination to recommend filing a civil enforcement action) and the former Uber CSO Joseph Sullivan being found guilty of criminal obstruction have led to a heated debate and personal concerns among security leaders about their legal liability in the aftermath of security breaches. The absence of clear guidance from the governments and industry-wide consensus on what constitutes “basic security” further complicates the discussion.

A recent survey from Salt Security showed nearly half (48%) of CISOs are concerned about potential personal litigation following breaches and 45% of the respondents cited increased personal risk or liability as personal challenges.

These concerns aren't baseless. In recent years, several security leaders had been held accountable or faced legal repercussions for breaches or failures in response.

Cases in point: The SolarWinds and Uber hack aftermaths

The most recent examples are the SEC Wells Notices sent to several SolarWinds’ current and former executive officers and employees including its CISO in the wake of the 2020 Sunburst supply chain attack, which impacted around 100 organizations and at least nine federal agencies.

In a statement, SolarWinds claims it “has acted properly at all times by following long-established best practices for both cyber controls and disclosure.” The vendor also warned, “any potential action will make the entire industry less secure by having a chilling effect on cyber incident disclosure.”

A Wells Notice is not a formal charge of wrongdoing, but a preliminary determination to recommend that the SEC file a civil enforcement action against the recipients alleging violations of certain provisions of the U.S. federal securities laws. “If the SEC were to authorize an action against any of these individuals, it could seek an order enjoining such individuals from engaging in future violations of provisions of the federal securities laws subject to the action, imposing civil monetary penalties and/or a bar from serving as an officer or director of a public company and providing for other equitable relief within the SEC’s authority,” according to the SEC filing.

It is widely agreed that the success of a security program does not solely depend on a CISO or the security team. However, judging CISOs in the aftermath of breaches is instinctive for many, and security experts argue it’s unfair in reality.

“Judging CISOs is kind of an instinctive reaction from a lot of people. Like they say: Oh, dude, you didn't even patch in time,” Anton Chuvakin, security advisor at Office of the CISO of Google Cloud, told SDxCentral, adding for many organizations, security problems are already in there and the cyberattacks revealed those issues.

“I'm also noticing that pointing fingers at security leaders after a breach, especially for ‘failures with basics’ is a very unpopular pursuit in the community,” he added.

George Gerchow, CSO and SVP of IT at Sumo Logic, also noted that “most of the time, CISOs have a good perspective of what needs to be done, but they have to kind of fight to get things prioritized. And there's always a roadmap of things that you have to do and so I think putting the blame on after the fact is super unfair.”

The verdict in the case of ex-Uber CSO Joseph Sullivan also stirred the CISO debate. Sullivan was sentenced to serve a three-year term of probation and ordered to pay a fine of $50,000, after being found guilty of obstruction of proceedings of the Federal Trade Commission (FTC) and misprision of a felony in connection with his attempted cover-up of a 2016 hack of Uber. The data breach involves records on about 57 million Uber users and 600,000 driver license numbers.

The security community had a split in reaction over this case, Chuvakin said. “Half of the security community roughly were thinking that he got what he deserved, and the other half felt like he was treated grossly unfairly.”

As a fellow CSO, Gerchow sided with Sullivan. “I thought it was ridiculous. And what happens is you get into this position of a chain of custody trying to protect the company, and I'd be willing to bet my home that other people knew what was going on, but he's sort of was the scapegoat because of unique circumstances that he was going through with two incidents at one time.”

The lack of clear guidance and standards in 'basic security'

A major concern for CISOs is the absence of clear guidelines from governments on how to handle, respond and disclose cyberattacks.

Current U.S. laws such as the Health Insurance Portability and Accountability Act (HIPAA) and Federal Information Security Management Act (FISMA) focus more on privacy, but there is no global standard.

The SEC in March proposed new cybersecurity risk management rules for all market entities. This proposal, Rule 10, demands at least an annual review and assessment of the design and effectiveness of their cybersecurity policies and procedures, and an immediate written electronic notice to SEC of a significant security incident.

Gerchow pointed out that even in these new cybersecurity guidelines, the timing of disclosure and the penalties for failure to do so are not clear.

Additionally, Chuvakin pointed out that the standards of negligence, liability and responsibilities for security leaders are still uncertain.

Despite decades of evolution in cybersecurity, there remains no consensus on what the basic security is in the field, he noted. “I don't think there's an industry-wide agreement on what it means to do the basics insecurity.”

How can CISOs reduce personal litigation risks?

Gerchow noted CISOs typically put themselves in a position of vulnerability and at risk for litigation when protecting their companies. And they need protective measures such as a mature reporting structure.

“I have a really good reporting structure where everything that we're doing, everything we're leaning into is reported up to an audit committee and a board and so I figured that that's the best way to cover yourself.”

He added if responding to proposed rules such as SEC’s rule 10, he would need a committee of decision-making involved that includes at least three C-level leaders, “because I want there to be a well-documented chain of custody that other people knew what was happening.”

Gerchow argues that security and breach responsibility should not solely rest on the CISOs’ shoulders. “I think it's a much wider range of people that should be held responsible,” including the boards that make the business decisions, security boards, audit committees and cybersecurity working groups.