General counsels are increasingly taking a frontline role in companies' response to cyberattacks as the frequency and sophistication of security breaches grows
Kate Beioley / Financial Times :
Context & Ripple Effects
General counsels have historically sat behind the CISO during a breach; what changed is liability. The new US data breach disclosure rules raised legal risks for public companies and their security chiefs, turning incident response into a legal-documentation exercise as much as a technical one.
The shift lands on boards that were already scrambling: research found just 14% of new Fortune 500 directors in 2022 had cybersecurity experience, down year over year even as the SEC finalized its cyber-risk reporting rules — leaving legal teams as the function best positioned to own disclosure decisions.
First-order effects
- Public-company general counsels now direct breach response in real time — deciding what gets disclosed, when, and how — while CISOs face personal legal exposure under the new disclosure regime.
Second-order effects
- Demand shifts toward lawyers with incident-response experience, mirroring the earlier talent squeeze where companies paid premiums for cybersecurity staff amid rising ransomware risk; cyber insurers gain a new gatekeeper, since coverage terms hinge on legally defensible response timelines.
Third-order effects
- If disclosure-driven liability keeps concentrating in legal teams, corporate cyber governance consolidates around GC-CISO pairs rather than standalone security leadership — and regulators' disclosure frameworks become the de facto playbook that state-linked threat activity, like the UK services' deepening work with large companies, tests against.
The trend: Cybersecurity is migrating from a technical function to a governed legal-disclosure discipline, with regulators' reporting rules setting the tempo of corporate response.