Over the past few years, how have you seen the nature of cyber incidents evolve from primarily technology and security issues into broader litigation, regulatory and governance events?
Tenery: Historically, cyber incidents had limited accountability, and aftermath activity was ascribed to just technology teams and practitioners. Now, responsibility and accountability are extended across a much broader population of the enterprise, from IT and security, to human resources (HR), legal, finance and even all the way up to the board. Now when questions are asked about when or where the incident began, and what the company knew, it is not only the chief information security officer (CISO) and IT teams responsible for answering those questions. Furthermore, class actions have taken on new industry level proportions in terms of the size, rigour and maturity of resources pursuing damages from breached firms. This also aligns with the spirit of increased and continually increasing regulation and oversight, such as advancements in California Consumer Privacy Act requirements, and deeper levels of inquiry and scrutiny by states when incidents are reported by victim companies.
What factors are driving the increase in cyber incidents triggering multiple forms of exposure simultaneously, including regulatory investigations, shareholder actions, commercial disputes and class actions?
Fisher: More and more enterprises are interconnected, through supply chain, service providers, customers and product users. An incident is rarely confined to a single victim, and risks transfer into multiple environments and extend to multiple victims. What is more, firms also must balance the risks of an increased attack surface area with often rapid adoption of new technology, or assets newly generated from artificial intelligence (AI). Enterprises are experiencing a rapid sprawl while certain remaining legacy platforms represent significant risk.
How are stakeholder expectations evolving following a significant cyber incident, particularly among regulators, investors, customers and boards?
Tenery: Regulators have increased their demands and expectations as to what the victim company was doing in terms of preparedness and prevention, and the level of detail they would like related to the attack. These details can include information about the threat actor, forensic results, system weaknesses and assurances and methods of containment, among other attributes. During the post-incident investigation, regulators will look for evidence of a well-considered and robust cyber security programme, one which should have been capable of preventing or mitigating most attacks. No programme is perfect, but companies that do not demonstrate sufficient maturity will be heavily penalised and held accountable for not having been properly prepared.
How are expectations around board oversight and executive accountability changing when organisations experience a significant cyber incident?
Fisher: Responsibility and accountability have extended beyond the CISO to other executive leadership and departments of the enterprise. In recent years, boards have made investments to ensure they have cyber and technology expertise among their members. Cyber and security more broadly must be given equal consideration and resource allocation as other more traditionally prioritised areas, and should be part of the discussion pertaining to legal, compliance, finance, HR and more. The old adage that everyone within an organisation is responsible for cyber security is true, and setting the tone the top, from the executive and board level down, is important to that mission.
Where are organisations encountering the greatest challenges when balancing incident disclosure obligations with the need to manage legal, regulatory and reputational risks?
Tenery: The challenge exists in determining the correct timing for making disclosures. When an incident is discovered, time to investigate is a critical need, especially so long as the investigation can avoid alerting the threat actor of discovery. Disclosures can threaten or jeopardise this window of opportunity. However, delayed disclosure can result in further penalty or liabilities. Additional complexities shaping regulatory consideration and the litigation fallout for victim companies include subsequent new findings of third-party liabilities. For example, well after the victim firm’s client and regulatory notification of the incident, the victim learns that the incident occurred due to a previously undisclosed and causal vulnerability in its firewall. It now has to backtrack its original messaging and legal risks with stakeholders. This is increasingly common, particularly in an AI-driven vulnerability discovery state of play.
How is the growth in third-party and supply chain cyber incidents changing the way organisations think about liability, contractual risk and resilience?
Fisher: No target victim can remain an island – there is too much interconnectivity in today’s economy. Organisations can inherit risk and vulnerabilities by extension from their supply chains, clients and even their customers. Likewise, they can pass their own potential risks to them. Enterprises are requiring more from their partners in terms of sufficient security controls and capturing those expectations in contracts and service agreements. This has been evident in the near epidemic scale of zero-day compromise by threat actors of firewalls and virtual private networks, which has left countless enterprises unknowingly vulnerable to cyber attacks and little compensation recovery from firewall manufacturers. As a result, enterprises have found themselves seeking experts and advisers to help regain solid reputational footing with customers and to help capture lost earnings in disputes with players in their supply chain.
Looking ahead to 2027, what developments do you expect will have the greatest impact on cyber-related litigation, regulatory enforcement and corporate governance?
Tenery: AI is the wild card. As more and more companies are navigating this technology and experimenting with its use, more partners and customers are exposed to the potential downstream risks that have not yet been explored or defined. At the same time, organisations will continue to grapple with existing security risks and have to shore up defences that harness new AI technology and are malleable to protect against the full spectrum of vulnerabilities. 2027 will be the year where the industry better understands the new set of exposures and economics of threat defence on a potentially – and exponentially – empowered set of threat actors leveraging AI.
If you have any questions or would like to discuss how StoneTurn can help, reach out to Luke Tenery or Nathan Fisher.
To receive StoneTurn Insights, sign up for our newsletter.
Disclaimer: The views expressed in this article are those of the author and do not necessarily reflect the views of StoneTurn Group, LLP, Province, LLC, or their affiliates. This article is provided for informational purposes only and does not constitute legal, financial, or other professional advice.