Cybersecurity Governance and Disclosure Toolkit: SEC Rules, Safeguards, and Vendor Risk
By Casey Scott McKay ·
Cybersecurity has become a disclosure and governance obligation as much as a technical one, and the legal exposure now attaches to what a company says about its security as reliably as to what happens to its data. This toolkit works the public company disclosure regime - the four business day incident report, the materiality determination that triggers it, and the annual risk management and governance disclosures. It sets out the safeguards obligations that apply regardless of listing status, including the written information security programme and its required elements. It covers vendor and subprocessor risk, the breach notification landscape, and incident response conducted so that privilege survives. It closes with board oversight duties and the insurance position.
IP and Technology > Privacy Data Security | Toolkit | Published 7 May 2025 - Updated 7 July 2026 | Casey Scott McKay - marksy.us
Summary. Cybersecurity has become a disclosure and governance obligation as much as a technical one, and the legal exposure now attaches to what a company says about its security as reliably as to what happens to its data. This toolkit works the public company disclosure regime — the four business day incident report, the materiality determination that triggers it, and the annual risk management and governance disclosures. It sets out the safeguards obligations that apply regardless of listing status, including the written information security programme and its required elements. It covers vendor and subprocessor risk, the breach notification landscape, and incident response conducted so that privilege survives. It closes with board oversight duties and the insurance position.
Keywords: cybersecurity disclosure · material incident determination · four business day reporting · risk management strategy governance disclosure · board oversight · Caremark duties · safeguards rule · written information security program · risk assessment · access controls · encryption · incident response plan · vendor risk management · subprocessor oversight · breach notification statutes · sector reporting obligations · tabletop exercises · privilege in incident response · insurance
Start Here
A company detects unauthorised access to a customer database on a Friday evening. By Monday the security team has confirmed the intrusion and is still determining what was taken.
The general counsel is asked a question with a four business day clock attached: is this material?
There is no answer yet. The scope is unknown, the data is unclassified, and the affected systems are still being examined. But the clock does not start when the investigation finishes; it starts when the company determines materiality, and a company that defers the determination indefinitely has made a decision of its own.
That tension — between disclosing before you know and knowing before you disclose — is the central problem of modern cybersecurity practice, and it is decided in advance by the process a company built or failed to build.
This toolkit answers three questions.
- What must be disclosed, and when? The incident report, the annual disclosures, and the materiality standard that governs both.
- What must be built regardless? A written information security programme, vendor oversight, and an incident response capability.
- Who is accountable? Board oversight duties, and the individual exposure that has become real.
If you read only one thing, read The First Seventy-Two Hours. It works the notification triggers and the sequencing decisions that have to be made before the facts are settled.
Public Company Disclosure
The incident report. Registrants must disclose a material cybersecurity incident on a current report within four business days of determining that the incident is material — not within four business days of the incident.
What must be described. The material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely material impact on the registrant, including on financial condition and results of operations.
What need not be described. Specific or technical information about planned response, systems, or vulnerabilities that would impede the response or remediation.
The materiality standard. The ordinary securities standard — whether a reasonable investor would consider the information important, or whether it would significantly alter the total mix of information available.
Which is qualitative as well as quantitative. Reputational harm, customer relationships, competitive position, litigation exposure, and regulatory consequences all count, and an incident with modest direct cost can be material.
Without unreasonable delay. The determination itself must be made without unreasonable delay after discovery. Deferring the determination is not a strategy.
Amendment. Where information was unavailable at the time of the original report, an amendment is required once it is determined.
Delay for national security. A narrow provision permits delay where the Attorney General determines that disclosure poses a substantial risk to national security or public safety.
Annual disclosure. 17 C.F.R. § 229.106 requires description of processes for assessing, identifying, and managing material risks from cybersecurity threats; whether risks have materially affected or are reasonably likely to materially affect the registrant; the board's oversight of cybersecurity risks; and management's role and expertise in assessing and managing them.
Which converts the security programme into a disclosure document. What the company says about its processes must be true, and it is read against what the company actually does.
The Liability That Follows Disclosure
Statements about security are statements. 17 C.F.R. § 240.10b-5 reaches material misstatements and omissions in connection with the purchase or sale of securities, and security representations in filings, on websites, and in customer materials are within it.
Which is the development that changed this practice. Enforcement and private litigation now target the gap between a company's security claims and its security reality, independent of any breach.
Risk factors framed as hypothetical. Describing a risk that has already materialised as something that "could" occur is a recognised category of misstatement.
Internal controls. 15 U.S.C. § 7262 requires management assessment of internal control over financial reporting, and disclosure controls must be designed to ensure that information about incidents reaches the people making disclosure decisions.
Which means the escalation path is a disclosure control. An incident known to the security team and not to the disclosure committee is a controls failure before it is a disclosure failure.
Individual exposure. Enforcement has reached individual officers for security representations, which has changed how chief information security officers document risk internally — sometimes in ways that make the record worse rather than better.
The candid internal record problem. A security team that documents known deficiencies creates evidence; one that does not creates a different problem. The answer is to document deficiencies together with the remediation plan and the risk acceptance decision, at the appropriate level of authority.
Customer-facing claims. Security representations in marketing, in certifications, and in contracts are also representations under 15 U.S.C. § 45 and under contract, and inaccurate ones are among the most commonly enforced privacy and security failures.
Practical rule. Every security statement — in a filing, on a website, in a sales deck, in a contract — should be traceable to a control that exists and is tested.
Safeguards Obligations
The rule. 16 C.F.R. § 314.4 requires covered financial institutions to develop, implement, and maintain a written information security programme with specified elements. Its structure is the de facto standard well beyond the institutions it binds.
A qualified individual designated to oversee and implement the programme and enforce it.
A written risk assessment, periodically refreshed, identifying reasonably foreseeable internal and external risks, assessing their sufficiency of controls, and describing how identified risks will be mitigated.
Access controls, including authentication and periodic review of access rights.
A data inventory, identifying what data is collected, where it is stored, and how it flows.
Encryption of customer information in transit and at rest, or compensating controls approved by the qualified individual.
Secure development practices for applications developed in-house and assessment of externally developed applications.
Multi-factor authentication for anyone accessing information systems, subject to approved alternatives.
Secure disposal of customer information no longer needed, with a periodic review of retention.
Change management procedures.
Monitoring and logging of authorised user activity and detection of unauthorised access.
Testing. Continuous monitoring, or annual penetration testing plus semi-annual vulnerability assessments.
Training for personnel, and qualified security personnel with current knowledge.
Vendor oversight, addressed below.
An incident response plan, addressed below.
An annual report to the board on the programme's status, material matters, and recommendations.
Sector rules run alongside. The health security framework at 45 C.F.R. § 164.306 and 45 C.F.R. § 164.308 imposes analogous administrative, physical, and technical safeguards, and financial services regulators impose their own.
Vendor and Third-Party Risk
The obligation. Safeguards frameworks require selecting service providers capable of maintaining appropriate safeguards, requiring them contractually to do so, and periodically assessing them.
Which means three activities, and most programmes do only the second.
Selection. Diligence proportionate to the data and the access. A security questionnaire, evidence of an independent assessment where available, and a review of any recent incidents.
Contracting. Security requirements referencing a defined standard rather than "commercially reasonable." Incident notification within a stated period, short enough to permit the company to meet its own obligations. Audit or assessment rights. Subprocessor approval or notice, with flow-down. Data return and deletion on termination, with certification. Liability terms that are not capped below the exposure the data represents. And insurance requirements.
The notification period is the term to fight for. A company with a four business day disclosure obligation and a vendor with a thirty-day notification term cannot meet its own deadline.
Assessment. Periodic, proportionate, and recorded. Annual for critical vendors, on a cycle for others, with findings tracked to closure.
The register. Every vendor with access to data or systems, with the data categories, the access model, the contract terms, the last assessment date, and the criticality rating. Its absence is the finding that precedes every other finding.
Fourth parties. A vendor's subprocessors carry the same risk, and the contract should require notice, flow-down, and — for critical services — approval.
Concentration risk. Multiple critical functions dependent on a single provider is a governance matter, and it belongs in the board reporting.
Exit. A vendor relationship that cannot be exited is a risk regardless of its security posture. See Software Continuity and Escrow Toolkit.
Incidents at vendors. Most reportable incidents now originate with a third party. The response plan must cover an incident the company learns about from a vendor, with no direct visibility into the affected environment.
Incident Response
The plan. Required by safeguards frameworks and required in practice. It should cover goals, roles and responsibilities, decision authority, internal and external communication, remediation, documentation, and post-incident review.
Roles named, not described. A plan naming functions rather than people fails at three in the morning.
Decision authority. Who decides to disconnect a system, to engage forensics, to notify a regulator, to notify customers, and to make a materiality determination. Written down, with alternates.
The materiality determination process. Who participates, what information is required, how quickly it convenes, and how the determination is documented. This is the single most important process for a public company and it should be rehearsed.
Escalation to disclosure. A defined route from the security team to the disclosure committee, which is itself a disclosure control under 15 U.S.C. § 7262.
Privilege. Counsel engages the forensic firm; the firm reports to counsel; findings reach the business through counsel's advice. The engagement letter should state the anticipation of litigation, and the arrangement should be established before the incident rather than papered afterwards. See Privilege and Work Product Toolkit for IP Matters.
The dual-track problem. A single forensic report serving both remediation and litigation purposes is the fact pattern in which privilege is most often lost. Separate the operational remediation work from the litigation-directed investigation, with different scopes and different reporting lines.
Preservation. A litigation hold issued promptly, with Federal Rule of Civil Procedure 26 work product protection asserted for the investigation and Federal Rule of Evidence 502 protections sought in any resulting litigation.
Notification obligations. State breach notification statutes with varying triggers, content requirements, and timelines. Sector obligations including 45 C.F.R. § 164.404 for health information and, for critical infrastructure, the reporting framework at 6 U.S.C. § 681b. Contractual notification obligations to customers. And, for registrants, the securities disclosure.
Which is a sequencing problem. These obligations have different triggers and different clocks, and a matrix mapping them — trigger, deadline, recipient, content — should exist before it is needed.
Tabletop exercises. Annually at minimum, including a scenario in which the incident originates at a vendor and one in which the materiality determination is genuinely close.
Post-incident review. What failed, what the plan got wrong, and what changes. Documented, and fed into the risk assessment.
Board Oversight
The duty. In re Caremark International establishes that directors may be liable for a sustained or systematic failure to exercise oversight — a failure to implement any reporting system, or a conscious failure to monitor one that exists.
Marchand v. Barnhill sharpened it: where a risk is mission-critical, the board must make a good faith effort to implement a board-level system of monitoring and reporting, and the absence of any board-level process for a central risk is a pleadable claim.
Which reaches cybersecurity for companies whose operations depend on it — which is now most companies.
What the board should have. A designated committee or the full board with responsibility recorded in a charter. Regular reporting on a defined cadence, with a standing agenda item. Minutes reflecting substantive discussion rather than presence. Access to management with the relevant expertise. And a record of decisions on risk acceptance.
The annual report to the board required by safeguards frameworks — programme status, risk assessment results, testing outcomes, material matters, incidents, and recommendations.
Expertise. The annual disclosure under 17 C.F.R. § 229.106 requires description of management's expertise and the board's oversight, which has pushed companies to formalise both.
Minutes matter more than usual. In a derivative claim, board minutes showing substantive engagement with cybersecurity risk are the defence, and minutes recording a presentation with no discussion are not.
Risk acceptance decisions. Where a known deficiency is accepted rather than remediated, the acceptance should be made at an appropriate level, documented with the rationale, and revisited on a schedule. An undocumented acceptance looks like a failure to act.
Which is the practical governance point. The board's job is not to secure the company; it is to have a system that tells it the truth about security and a record showing it engaged with what it was told.
Insurance
Cyber policies typically cover incident response costs, forensic investigation, notification, credit monitoring, business interruption, extortion payments where lawful, regulatory defence and, sometimes, fines where insurable.
Read the exclusions. War and hostile act exclusions have been litigated in the context of state-attributed attacks. Failure-to-maintain-standards exclusions turn on the representations in the application. And unencrypted device exclusions are common.
The application is a representation. Answers about controls become the basis of coverage, and an inaccurate answer is a rescission argument. Have security personnel verify the answers rather than having a broker complete them.
Notice provisions are strict. Late notice is a recurring coverage denial, and the policy's notice trigger — discovery, suspicion, or determination — should be understood before an incident.
Panel counsel and vendors. Most policies require use of approved vendors, which conflicts with a pre-existing privilege arrangement unless negotiated in advance.
Sub-limits. Notification costs, regulatory defence, and business interruption frequently carry sub-limits well below the policy limit.
Contingent business interruption for a vendor outage is the coverage most often absent and most often needed, given where incidents actually originate.
Directors and officers cover responds to securities and derivative claims arising from disclosure failures, and the interaction between the cyber policy and the directors' policy should be mapped.
Contractual requirements. Customers increasingly require cyber cover with stated limits and additional insured status, and the certificates should be tracked.
See IP Insurance and Risk Transfer Toolkit for the broader coverage framework and the tender process.
The Materiality Determination, Worked
The process that a public company should be able to run on a weekend.
Convene quickly. A defined group — general counsel, chief information security officer, chief financial officer, disclosure counsel, and a business leader — with alternates named and a standing bridge.
Establish what is known and what is not. Systems affected, data categories potentially involved, volume estimate with a stated confidence, and whether the intrusion is contained.
Assess quantitative impact. Direct response costs, remediation, business interruption, customer credits, and any revenue at risk, with ranges rather than points.
Assess qualitative impact. Customer and partner reaction. Regulatory consequences. Litigation exposure. Competitive harm from what was taken. Reputational effect. Effect on the company's stated security posture and any certifications.
Consider the total mix. Whether a reasonable investor would consider this important given everything else known about the company. A modest incident at a company whose value rests on trust may be material where a larger one elsewhere is not.
Do not wait for certainty. The determination is made on what is known, with the ability to amend. Deferring pending complete investigation is itself a decision, and an unreasonable delay in determining is a violation independent of the disclosure.
Document the determination. Who participated, what information was available, what factors were weighed, and the conclusion — whether material or not. A documented not-material determination is a defence; an undocumented one is a gap.
Revisit. As the investigation develops, the determination is revisited on a stated cadence, and a change in the answer triggers the clock from the new determination.
Prepare the disclosure in parallel. Drafting begins when the determination is convened, not when it concludes, because four business days is not long.
Watch the trading window. Insider trading exposure is acute where an incident is known internally and not disclosed, and the window should close on the same information that triggers the determination process.
Coordinate with other notifications. State breach notification, sector reporting, customer contractual notice, and law enforcement engagement all run on their own clocks and can conflict on timing and content.
Common Mistakes
Treating the four business days as running from the incident. It runs from the materiality determination — and the determination itself must be made without unreasonable delay.
No documented process for making the determination, so it is made ad hoc by whoever is available.
No documented not-material determination, leaving no record that the question was considered.
Security representations that outrun the controls. Marketing claims, certifications, and filing language describing a posture the company does not have — the exposure that now exists independent of any breach.
Risk factors describing materialised risks as hypothetical.
No escalation route from security to the disclosure committee, which is a disclosure controls failure under 15 U.S.C. § 7262.
A written information security programme that is a policy rather than an index to real controls, with a risk assessment nobody refreshed.
No data inventory, so the scope of any incident is unknowable in the time available.
Vendor notification periods longer than the company's own obligations.
No vendor register, so the company cannot answer which third parties hold its data.
Forensics engaged by the business rather than by counsel, losing privilege at the outset.
A single forensic report serving remediation and litigation, which is where privilege most often fails.
Board minutes that record attendance rather than engagement, against the Marchand v. Barnhill standard.
Undocumented risk acceptance, which looks indistinguishable from a failure to act.
Insurance applications completed without security verification, creating a rescission argument.
No tabletop exercise, so the first time the process runs is under real conditions.
Worked Example: The Vendor Incident
A mid-cap registrant is notified on a Wednesday that a payroll vendor has suffered a ransomware incident affecting an environment containing employee records.
Hour one. The incident response plan activates. The named decision-maker convenes the group. Outside counsel is engaged, and counsel engages a forensic firm under an engagement letter stating the anticipation of litigation.
Hour four. The vendor contract is pulled. Its notification obligation was ten business days; it notified in six, which is compliant with the contract and inadequate for the company's own obligations. That finding goes on the remediation list immediately.
Day one. The company has no direct visibility into the vendor's environment. It requests the vendor's forensic scope, its indicators of compromise, and its data classification for the affected systems. The vendor is cooperative and slow.
Day two. A litigation hold issues. The trading window closes. The data inventory identifies which employee data categories the vendor held, which takes two hours because the inventory exists — a fact the general counsel notes for the board report.
Day three. The materiality group convenes with what is known: employee records for a defined population, no customer data, no operational disruption, direct costs estimated in a range, and the vendor bearing notification costs under the contract.
The determination. Not material, on the quantitative and qualitative factors, with the reasoning documented and a commitment to revisit as the investigation develops.
Days four to fourteen. State breach notification analysis for employee residents across nine states, with varying triggers and content requirements, run against the matrix that already existed. Notifications issued within the shortest applicable deadline.
Week three. The vendor's forensic report indicates a narrower scope than feared. The determination is revisited and unchanged, and that revisitation is documented.
Week six. Post-incident review. Findings: the vendor notification period was inadequate, the vendor register lacked a criticality rating for this provider, and the company had no contingent business interruption cover for vendor outages.
Remediation. Notification periods renegotiated across the critical vendor set. Criticality ratings added to the register. Insurance reviewed. And a tabletop exercise scheduled using precisely this scenario.
What made it work. A plan with named people, a data inventory that answered the scope question in hours, a privilege structure established before the incident, and a notification matrix built in advance. None of that was created during the incident, and none of it could have been.
Diligence Questions
Is there a written information security programme, and does it index real controls or describe aspirations?
When was the risk assessment last performed and refreshed?
Is there a data inventory, and how long would it take to determine what data a given system holds?
Is there a vendor register with data categories, access models, contract terms, criticality ratings, and assessment dates?
What are the vendor incident notification periods, and are they shorter than the company's own obligations?
Is there an incident response plan, and when was it last exercised?
Who makes the materiality determination, and is the process documented?
Is there an escalation route from security to disclosure decision-makers?
What does the company say about its security in filings, on its website, in certifications, and in customer contracts — and is each statement traceable to a control?
How does the board oversee cybersecurity? Charter, cadence, minutes, and the annual report.
Are risk acceptance decisions documented, at what level, and revisited on what schedule?
What incidents have occurred in the last three years, how were they determined, and what was disclosed?
Is forensic work engaged through counsel?
What insurance is in place, with what sub-limits, and were the application answers verified?
Building the Programme
Start with the two registers. The data inventory and the vendor register. Every other obligation in this toolkit depends on one or both, and their absence is why incidents take weeks to scope.
Then the risk assessment, written, covering foreseeable internal and external risks, the sufficiency of current controls, and the mitigation plan — as 16 C.F.R. § 314.4 requires and as every other framework expects.
Then the programme document. Not a policy library: an index mapping each required element to the control that implements it, the owner, and the evidence of testing.
Then the incident response plan, with named people, decision authority, the materiality process, the notification matrix, and the privilege structure.
Then the disclosure controls. The route from security to the disclosure committee, documented as a control and tested.
Then the statement audit. Every security representation the company makes, traced to a control. Filings, website, certifications, sales materials, and contracts. Correct what cannot be traced.
Then vendor remediation. Notification periods, security requirements, audit rights, and deletion obligations, prioritised by criticality.
Then board governance. Charter, cadence, reporting content, and minutes that reflect engagement.
Then testing. Penetration testing and vulnerability assessment on the required cycle, plus an annual tabletop exercise that includes a vendor-origin incident and a close materiality call.
Then insurance. Application verified, exclusions understood, sub-limits mapped, notice trigger understood, and panel vendor conflicts resolved in advance.
And then repeat. The risk assessment refreshed, the registers maintained, the statements re-audited, and the exercise re-run. A programme that is built once decays within a year.
Working With Other Advisers
The chief information security officer, whose relationship with legal determines whether the programme works. The candid internal record problem is best solved together rather than by either function alone.
Disclosure counsel, engaged before an incident, so that the materiality process has been designed rather than improvised.
Outside privacy counsel for the notification matrix across states and sectors, which is detailed and changes.
Forensic providers, selected and engaged through counsel in advance, with a retainer so that engagement is not being negotiated during an incident.
Insurance brokers, on the application accuracy, the sub-limits, the notice trigger, and the panel vendor conflict.
The audit committee or its equivalent, for the reporting cadence and content.
Internal audit, who can test whether the controls the programme describes actually operate.
Procurement, for the vendor contract standard and the register.
Communications, because incident communications are read by regulators as statements and should be reviewed as such.
Human resources, where employee data is involved and where the notification population is the workforce.
Questions Clients Ask
When does the four business day clock start? On the determination that the incident is material, not on discovery — and the determination must be made without unreasonable delay.
Can we wait until the investigation is complete? No. The determination is made on what is known, with the ability to amend as facts develop.
What if we decide it is not material? Document the determination, the participants, the information available, and the reasoning. An undocumented not-material call is the gap.
Do we have to name the attacker or describe the vulnerability? No. Technical detail that would impede response or remediation is expressly outside what must be disclosed.
Our vendor was breached, not us. Do we have obligations? Frequently yes — state breach notification if the data is yours, customer contractual notice, and securities disclosure if the impact on you is material.
Are we exposed even without a breach? Yes. Security representations that outrun the controls are actionable under 17 C.F.R. § 240.10b-5 and 15 U.S.C. § 45 independently of any incident.
Can the CISO be personally exposed? Enforcement has reached individual officers on security representations. The response is accurate internal documentation with risk acceptance decisions made at the right level, not less documentation.
Is our forensic report privileged? Only if it was prepared for counsel in anticipation of litigation, and not if the same report drives operational remediation. Structure the engagement before the incident.
Does the safeguards rule apply to us? 16 C.F.R. § 314.4 binds covered financial institutions, and its structure is what regulators and counterparties expect from everyone else.
What does the board actually have to do? Have a system that reports the truth about security risk, engage with it, and record that engagement. Marchand v. Barnhill is the standard.
Will insurance cover this? Read the exclusions, verify the application answers, understand the notice trigger, and check whether contingent business interruption for vendor outages is included. It usually is not.
Where do we start? The data inventory and the vendor register, because every other answer in this toolkit depends on them.
The One-Page Position
Cybersecurity governance position — [company], [date]. Written information security programme in place since [date], last reviewed [date]; risk assessment refreshed [date]; [N] of [N] required elements evidenced by tested controls. Data inventory: [N] systems, refreshed [date]; time to scope a hypothetical incident [N] hours. Vendor register: [N] vendors with data or system access; [N] rated critical; [N] assessed in the period; [N] with notification periods shorter than the company's own obligations. Incident response plan version [N], last exercised [date], scenario [description]. Materiality determination process documented [date]; participants [roles]; rehearsed [date]. Disclosure controls: escalation route from security to the disclosure committee tested [date]. Security statement audit completed [date]; [N] statements reviewed, [N] corrected. Board oversight: [committee], cadence [frequency], annual programme report delivered [date]; minutes reflect substantive discussion [yes/no]. Risk acceptances open: [N], each documented and next reviewed [dates]. Testing: penetration test [date], vulnerability assessments [dates]. Incidents in the period: [N]; material determinations [N]; disclosures filed [N]; notifications issued in [N] states. Insurance: [carrier], limits [amount], sub-limits [list], application verified [date], contingent business interruption [included / not]. Recommended actions: [build the vendor register / renegotiate notification periods / correct the security claims on the website / run the tabletop].
Sector Notes
Financial services. The safeguards framework at 16 C.F.R. § 314.4 applies directly, and prudential and state regulators impose additional programme, certification, and notification requirements. Reporting timelines for banking organisations are shorter than the securities disclosure clock.
Healthcare. The security standards at 45 C.F.R. § 164.306 and 45 C.F.R. § 164.308 and the notification obligations at 45 C.F.R. § 164.404, with business associate agreements carrying the vendor obligations.
Critical infrastructure. Incident reporting under the framework at 6 U.S.C. § 681b, on timelines that can precede the securities determination, which creates a sequencing problem worth mapping in advance.
Software and cloud providers. Customer contractual notification obligations that are frequently shorter than any statutory one, plus the security representations in contracts and certifications that are themselves the exposure.
Retail and payments. Card network requirements operate contractually alongside the legal obligations, with their own forensic and reporting regimes.
Public companies generally. The disclosure regime plus the securities liability for security representations, which is the development that made this a general counsel matter rather than a security matter.
Private companies with institutional investors. Contractual security representations to investors and customers, and diligence expectations that now include the programme documentation described here.
Any company with a small security function. The obligations do not scale down. A written programme, a risk assessment, a vendor register, and an incident plan are the minimum, and they can be proportionate without being absent.
A Closing Note
The change worth naming is that cybersecurity liability has decoupled from cybersecurity outcomes.
A company can suffer a serious incident, respond well, determine materiality promptly, disclose accurately, and emerge with no legal exposure at all. Another can suffer nothing, and face securities liability because its filings described a security posture it did not have and its risk factors described as hypothetical a risk that had already materialised.
Which reframes the work. The security programme matters, and the legal exposure attaches to the accuracy of what the company says about it, the adequacy of the process that determines what to disclose, and the record showing the board engaged with the risk.
Three documents carry most of that: the data inventory, the vendor register, and a documented materiality determination process. A company with those can answer an incident in hours and a regulator in days. Without them, both take weeks the clock does not allow.
What This Costs
The data inventory. The largest line item, and the one that pays for itself the first time an incident needs scoping. Weeks for a mid-sized company, shared with the privacy programme.
The vendor register. Days to assemble from procurement records, then maintained at the point of vendor onboarding.
The risk assessment. A structured exercise, annually, drawing on the registers and the testing results.
The programme document. Days, once the controls and the registers exist. Impossible before.
The incident response plan and the tabletop. A week to write, a day per year to exercise, and the exercise is where the plan's defects surface at no cost.
The security statement audit. A week, and it is the single item most likely to prevent a securities claim.
Vendor contract remediation. Negotiation time proportional to the vendor count, prioritised by criticality.
Testing. Penetration testing and vulnerability assessment on the required cycle, which most companies already fund.
Board process. Charter, cadence, and reporting content — governance work rather than spend.
Against that: a securities claim arising from an inaccurate description of controls, a derivative claim on oversight, per-record breach notification costs across dozens of state regimes, regulatory penalties, and a coverage denial arising from an application answer nobody verified.
The programme's cost is dominated by the inventories. Its value is dominated by the process documents — the determination process and the response plan — which are cheap and which are what a company actually reaches for at eleven o'clock on a Friday night.
A Suggested Reading Path
For disclosure and governance:
For the privacy overlay:
For the vendor and continuity dimension:
Primary Authorities
| Authority | Proposition | |---|---| | 17 C.F.R. § 229.106 | Cybersecurity risk management, strategy, and governance disclosure | | 17 C.F.R. § 240.10b-5 | Material misstatements and omissions | | 15 U.S.C. § 78j | Manipulative and deceptive devices | | 15 U.S.C. § 78m | Periodic reporting; books and records | | 15 U.S.C. § 7262 | Internal control assessment | | 16 C.F.R. § 314.4 | Safeguards programme elements | | 15 U.S.C. § 6801 | Protection of nonpublic personal information | | 15 U.S.C. § 45 | Unfair or deceptive practices | | 45 C.F.R. § 164.306 | Security standards; general rules | | 45 C.F.R. § 164.308 | Administrative safeguards | | 45 C.F.R. § 164.404 | Breach notification to individuals | | 6 U.S.C. § 681b | Critical infrastructure incident reporting | | 18 U.S.C. § 1030 | Computer fraud and abuse | | 18 U.S.C. § 1836 | Trade secret misappropriation | | In re Caremark International | Oversight duty framework | | Marchand v. Barnhill | Board oversight of mission-critical risk | | TransUnion v. Ramirez | Standing for statutory claims | | Fed. R. Civ. P. 26 | Work product in incident response | | Fed. R. Evid. 502 | Clawback and non-waiver orders | | New York cybersecurity regulation | Sector programme and certification requirements |
Forms and Templates
Cybersecurity governance produces a small number of documents that carry the entire programme, and the first is the written information security programme itself — which, in the structure at 16 C.F.R. § 314.4, is less a policy than an index to the controls that exist, the risk assessment that justifies them, and the testing that verifies them. The Portfolio Inventory Template adapts to the data inventory and the vendor register, both of which the programme requires and neither of which most companies maintain: one row per system or vendor, with the data categories, the access model, the encryption status, the testing date, and the contractual security terms. The License Agreement Template supplies the vendor architecture — security requirements, audit rights, incident notification periods, subprocessor controls, and termination rights — that vendor oversight obligations require, and reading it against an existing vendor agreement usually shows what is missing. The Assignment Agreement Template matters in transactions, where security representations and pre-closing incidents are among the most consequential diligence findings.
Related Toolkits and Checklists
The State Privacy Compliance Toolkit covers the privacy obligations that share the data inventory and the vendor architecture with the security programme, and the two should be built together rather than sequentially. The Incident Response Checklist runs the programme elements and the disclosure triggers in order. The Software Continuity and Escrow Toolkit covers the vendor failure dimension of third-party risk, which is a continuity problem rather than a security one but shares the same register. And the Privilege and Work Product Toolkit for IP Matters covers the engagement structure that keeps forensic investigation protected, which is where incident response most often goes wrong.
Related Documents
Articles
Guides
Checklists
Toolkits
- State Privacy Compliance Toolkit
- Software Continuity and Escrow Toolkit
- Privilege and Work Product Toolkit for IP Matters
Templates & Forms
This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Cybersecurity obligations turn on the sector, the listing status, and the data involved. Marksy is not a law firm.