Cleary Gottlieb
Cybersecurity Governance Reminders for Public Company Boards
Pages
5
Time to read
12 mins
Publication
Language
English
Pages
5
Time to read
12 mins
Publication
Language
English
This alert memorandum discusses the governance responsibilities of public company boards regarding cybersecurity in light of increasing cyber threats, particularly from state-linked actors. It outlines the obligations of directors under Delaware’s Caremark framework, emphasizing the need for reasonable oversight of cybersecurity risks. The document details the importance of establishing reliable reporting systems and responding to red flags to mitigate legal exposure. It also presents best practices for incident preparedness, including the necessity of conducting comprehensive cybersecurity risk assessments that account for politically motivated attacks. The memorandum highlights the significance of operational resilience planning, which supplements traditional risk management by ensuring continued operations during disruptions. Additionally, it advises companies to engage external advisors and establish relationships with law enforcement before incidents occur. The alert concludes with a discussion on the implications of a recent executive order aimed at enhancing federal coordination against cybercrime, underscoring the need for proactive governance in cybersecurity.