CISO Personal Liability Is No Longer Theoretical: Here’s What Actually Changed

    July 27, 20265 min read
    CISO Personal Liability Is No Longer Theoretical: Here’s What Actually Changed

    For most of cybersecurity’s history, a CISO’s worst-case professional outcome was getting fired after a bad breach. That calculus has shifted. Since the SEC’s cybersecurity disclosure rules took effect, CISOs and other executives now face a real possibility that used to sound like an exaggeration: personal legal liability for how a company handled, and disclosed, a cybersecurity incident.

    Understanding what actually changed, and what didn’t, matters for anyone in or moving toward a security leadership role, not just the people already holding the CISO title.

    Prefer to read the full breakdown? Keep scrolling. Prefer to watch? Full video above.

    What the Rule Actually Requires

    The SEC’s final rule on cybersecurity disclosure, adopted in 2023, requires public companies to disclose a cybersecurity incident within four business days of determining that incident is material to the company’s financial performance. The materiality determination itself has to happen without unreasonable delay once an incident is discovered.

    That timeline sounds simple. In practice, it puts CISOs at the center of a genuinely difficult cross-functional sprint, coordinating with legal, finance, investor relations, and often outside forensics experts, to determine scope, assess financial materiality, and produce disclosure language that’s accurate without being either alarmist or misleading. All within days, often while the incident itself is still being contained.

    Where the Liability Question Actually Sits

    The case most people point to when discussing this is the SEC’s 2023 enforcement action against SolarWinds and its CISO individually, the first time a sitting CISO was named personally in an SEC cybersecurity enforcement action. That case drew enormous attention across the security leadership community, and pushed many CISOs to seek their own liability insurance rather than relying solely on their company’s coverage.

    What’s less widely discussed is what happened next. The SEC dismissed that case in late 2025, and under new agency leadership, has since signaled it intends to focus cybersecurity enforcement specifically on affirmative misrepresentation and deliberate concealment, not on good-faith judgment calls about when an incident became material. That’s a meaningful narrowing. It doesn’t mean CISO liability has disappeared. It means the standard is shifting toward something closer to: did you know something was materially wrong and say otherwise, rather than: did you make a defensible but ultimately incorrect timing call under pressure.

    For anyone building a career toward this level of leadership, that distinction is worth internalizing early. The risk isn’t in making an imperfect judgment call during a genuinely ambiguous incident. The risk is in a security posture that gets described in public filings as stronger than it actually is.

    The Board-Level Dimension

    CISO liability doesn’t exist in isolation. Courts and regulators have increasingly aligned cybersecurity governance with the long-standing Caremark standard for director fiduciary duty, meaning board members themselves can face personal exposure if they fail to implement any real oversight system for cybersecurity risk, or consciously ignore the systems that do exist. This has pushed boards to take cyber governance more seriously than in the past, adding board members with genuine security fluency, and expecting documented, active oversight rather than a once-a-year briefing.

    That shift matters for CISOs directly, because it changes who they’re actually accountable to. A CISO reporting into a board that’s genuinely engaged in cyber governance operates very differently than one reporting into a board that treats security as someone else’s problem to manage quietly.

    What This Means for the Job Itself

    A few concrete things have followed from this shift, worth knowing whether the goal is reaching this role eventually or just understanding how the field is changing.

    Disclosure controls have become a real, ongoing discipline, not a document written once and filed away. Public filings now need to reflect the actual state of a company’s security program, not an aspirational description of it, since enforcement attention has specifically targeted language describing controls a company didn’t actually have in place.

    CISO liability insurance, once rare, has become a genuine point of negotiation when security leaders take a new role, alongside directors and officers coverage that traditionally protected only the C-suite and board.

    And the CISO’s relationship with legal and finance has become considerably tighter. A materiality determination is no longer a purely technical or purely legal call, it’s a joint one, made under real time pressure, with real consequences attached to getting it wrong.

    The Larger Shift

    None of this means cybersecurity leadership has become more dangerous in a way that should discourage anyone from pursuing it. It means the role has matured into something closer to other executive positions that have always carried real accountability, general counsel, chief financial officer, positions where judgment under scrutiny has always been part of the job.

    What’s changed is that security leadership now carries that same weight. For a field that spent years arguing it deserved a seat at the executive table, this is, in an uncomfortable way, exactly what having that seat actually looks like.

    Share this article

    Enjoyed this article?

    Subscribe to Professor Simon's weekly newsletter for practical insights, career guidance, and leadership lessons delivered every Friday.

    A confirmation email will be sent. If you don't receive it, please check your spam or junk folder.

    No spam. Unsubscribe anytime.

    Prefer to Listen?

    Listen to Professor Simon’s IT & Cybersecurity Podcast for practical conversations about cybersecurity careers, certifications, security leadership, and real-world lessons from the field.

    Listen on Spotify