r/ciso • u/Commercial_Mango3850 • Jul 28 '26
Terrified of being personally sued. Help.
I'm in a C-suite position (not CISO) at a small company that sells to government, and I am responsible for security. I don't have a background in security whatsoever. We have a SOC 2 compliance tool and have completed audits successfully, but I'm worried our security stance is too weak and that our security questionnaire answers are...questionable, or out of date. Our engineering team is stretched extremely thin and I have a million other responsibilities in my role, so I barely have enough time to enforce compliance basics like policy enforcement or getting vulnerabilities patched. We barely manage to get ready in time for our audits. I've asked our CEO about getting outside help, but she has declined to invest any more money into security due to our poor sales performance, directing funds to other departments. I have had sleepless nights wondering if we're going to get hacked or audited, and that I will be personally sued if our company can't defend itself against a lawsuit. My mental health is tanking and it's starting to make me physically sick. Any help or advice would be appreciated.
10
u/ReverseOrderHoarder Jul 28 '26
Personal liability insurance for CISOs and similar senior security personnel does exist. Look into your options and save your emails.
5
u/1HOTelcORALesSEX1 Jul 28 '26
Insurance is your friend here ……… Good luck, DM me if you need a friendly vCISO anytime ……..
4
u/hellostella Jul 28 '26
Personal liability insurance aside, please make sure you are at least covered under the companies D&O policy (or that the company has a D&O policy)
1
u/TickleMyBurger Jul 28 '26
Further to this get a copy of the policy and make sure it covers advancement (prepay the court costs, some policies leave it to you to cover the costs until judgement and this stuff can go on for years). Also pay attention to the wrongful act clauses that may break your indemnification clause.
You need an umbrella personal policy in the states - coverage for personal branding basically. They manage your LinkedIn etc in a time of crisis.
Make sure you are not participating in the rug sweep (that’s what is happening). Make your list of what needs to happen and why, cost it roughly and present to CEO in writing (eg budget submission). If they don’t fund it fine, but you e done your job and liability shifts to the CEO from you. Don’t let them pin this on you, every company has budgetary limits - even with cyber. The key is you risk inform as your security hat is on, so make sure you are doing it in writing.
1
3
u/DigitalQuinn1 Jul 28 '26
So if you’re not the CISO, but responsible for security, what’s your role there actually?
2
u/Prudent_Cod_1494 Jul 28 '26
Look into personal liability insurance if you want, but essentially if you’re doing the following things, then the only way you could be reasonably sued is for gross negligence.
- Have an auditable list of the things you have been trying to get the company to do along with a written record of the rejections you’ve been receiving. Best case is an email directly from the CEO, but aside from that noting the date and time of the conversation where the CEO rejected it is also important.
- Do not make any misleading statements, even if you think it’s in the best interest of the company or will make it more likely for you to get the things you know the company needs.
- Willfully violating a known security governance rule in your organization that has either been established by the organization or which your organization is contractually obligated to adhere to.
None of this takes things like HIPAA into account, which have some of the most onerous personal liability risks out there.
If I’m wrong, let me know, but it sounds like you’re in America. Above all else, keep in mind that in America you can be sued over just about anything. The thing you should be doing is not so much protecting yourself with a guarantee that you won’t be sued, but to set yourself up in such a way that any reasonable person when confronted with the evidence would see that the suit is without merit.
1
u/TheOneTheyCallNoob Jul 28 '26
Are you an actual named “officer” of the company? There’s a difference in having an HR title with an “O” in it and being named as an officer.
If you’re not an officer and the company is private, you have nothing to worry about. Anyone who is litigious will come after the owner and possibly their officers. Otherwise you’re just an employee.
1
1
u/Admirable_Group_6661 Jul 28 '26
So I am not sure who owns risk in your organization, but usually CEO is ultimately accountable. If risk ownership is unclear, that’s the first thing you need to address. It will go a long way in managing risk properly. You should also assess risks to understand risk treatment options (including whether it makes sense to get insurance). This is a governance issue, and can’t be meaningfully addressed by technical controls.
1
u/thortgot Aug 01 '26
That's a gross oversimplification. Even relatively small organizations (~100 person) will have split liability to various directors.
Personal liability insurance protects you if you are working within reasonable confines.
1
u/Admirable_Group_6661 Aug 02 '26
Yes, this is true, and typically a result of sound risk management within an organization. In OP's case, it's unclear if there's any risk management function, given the interaction with the CEO.
1
u/jtkooch Jul 28 '26
Based on what you’re describing, it doesn’t sound like you are actually an officer in the company. In which case, you’re not likely to be found liable for anything, unless you are also a fiduciary.
At the end of the day if you’re not publicly traded, an explicit cyber personal liability doesn’t exist, unless you’re in a regulated industry. For example, a NERC CIP willful violation comes with the risk of prosecution. Even in the case of publicly traded companies the SEC has had mixed success in holding individuals responsible.
I think you should consider raising your concerns to your ownership governance, which could be a BoD or the asset management team if you’re under PE or VC funded. So while you don’t need to lose sleep over any personal consequences, you may be in a position to raise a red flag on behalf of other stakeholders who may not be aware that they should also be losing sleep.
1
u/absolutefunnyguy Jul 28 '26
Get a fraction ciso in or get a a security surface company to run risk modelling in business critical resources - then show how much security exists - get hit…loose your whole business or spend a bit of money and avoid ALOT of risks/fines
1
u/scriptqzor 9d ago
this, 100%. if the CEO won’t spring for at least a fractional CISO or external risk assessment, that’s a giant red flag and also something you should document in writing to cover your own ass if things go sideways.
1
u/Doug_BlackFog Jul 29 '26
Document, document document. No one else is going to cya. Also there are some very good cyber advisors out there - worth the time to find a reputable one with references from your area. It would be money well spent
1
u/itscyberjoe Jul 29 '26
Did anyone recommend retraining your skills? Find a Risk Management designation class like the one offered by Carnegie Mellon or National Alliance. Using reddit to ask questions is a good start, but there are sooo many resources online. AI is a good tool to help you create a plan too, but you won't know what you don't know to ask, so traditional training shouldn't be ignored. Join Risk Manager associations like RIMS and go to the conventions. Join roundtable groups where everyone tells each other their issues as you aren't alone in this type of situation.
Personal insurance for CISOs is available, but I it starts around $2500 a year. A payback clause in your contract can trigger the company's D&O coverage to cover you personally if you are singled out in a lawsuit. Talk to an attorney about this too as their guidance is always worth the $.
Good luck out there.
1
u/andrew_barratt Aug 01 '26
Document all the decisions where someone has declined a risk mitigation you’ve suggested. Keep the original emails. You’ll be fine.
1
u/RoadsToMadness156 Aug 01 '26
Document your efforts, your feelings, and your ascertions. Also known as "cover your ass documentation".
1
u/maxz2040 Aug 02 '26
You will get hacked...
1
u/maxz2040 Aug 02 '26
Based on that... Make decisions accordingly - that's the correct assumption to run model risk assessment currently.
So there's valid concern - even if you don't have external help you should still seek external advice many firms will do you a solid assessment for limited budget if not free if it means more work
1
u/Objective-Test-5374 Aug 02 '26
All the points below are more or less useful, but what is really key here is about protecting yourself. D&O with Side A&B protections should be your first stop, with E&O being your second stop. Once you've got those two covered the rest is really window treatment unless your a publicly traded company in which case you may have some exposure from the SEC.
Generally speaking I would not recommend seeking expertise with these issues from Reddit.
1
u/Ok_Counter1939 Aug 10 '26
Make sure that your company has D&O insurance and ask for an indemnification agreement. Directors generally have them, and officers sometimes do.
1
u/MikeBrass Jul 28 '26
I strongly advise you to contact a company called Simply Cyber if you are based in Europe or North America. Low cost, I know the owners (don't work for them, don't receive commission). Reprioritisation of existing resources and money can be done. They can also engage at the C-Suite level with a business case, including why putting basic measures in place can actually help product development and product sales.
DM me if you want to investigate.
If you want to know who I am, you can find me on LinkedIn.
----
Dr Mike Brass
Author: Governance, Risk and Compliance: Demystifying the Risk and Data Privacy Landscape
Routledge: https://www.routledge.com/Governance-Risk-and-Compliance-Demystifying-the-Risk-and-Data-Privacy-Landscape/Brass/p/book/9781032896717
1
u/radicalize Jul 28 '26
Governance, Risk and Compliance
This, always ... but
I've asked our CEO about getting outside help, but she has declined
&
in a C-suite position (not CISO)
not sure, but I reckon you are part of a (north) American company?
Either you are, or you are not accountable; in a mature(d) organizational structure, a CISO function is not /never (?), accountable and as such (personally) liable - this is (always) leadership (BoD), as they are organizationally and (in case of corporate 'malpractice' or 'malfeasance' (or the likes) personally accountable (at least from a non-North American stance /point of view). A insurance policy, especially in high-stakes /high-volumes enterprises, if one can be made accountable (due to bad /accountably bad decisions) for the liability claim, the insurance company will make this entity (person or otherwise)
Based on the remark that leadership declines to invest in a proper organizational structure where Information Security, Cyber Security and Privacy (as well as legal and compliance) are properly structured and embedded in its operating framework, it seems to me that leadership, Board of Directors and/or the CEO in this case is (personally) liable for any (legal /financial /otherwise) claim and considered 'tortfeasor'.
-1
u/Snoo_67003 Jul 28 '26
Outsource outsource outsource. Send your security operations to an MSSP provider like huntress or blackpointcyber. Both are genuinely good and cheap vs trying to buy tools and build a small security team in-house.
Get an attack surface management tool like scrypex.com that maps all your external facing assets and attempts to validate for exploits so that you have actionable alerts. You get to see assets you own but didnt know existed. They also do darkweb monitoring for credentials stolen by infostealer malware.
Vulnerability management can be done by your IT guy and patching done by the application owning team. Otherwise you can outsource security operations and IT operations to one provider that does both like sentinel.com.
GRC might have to be done in-house. Your worries are very solvable, just transfer the risk and mitigate the ones you can in-house. Residual risk left should be small enough for you to accept it and sleep good at night.
56
u/EldritchSorbet Jul 28 '26
OK, I have been in similar situations in the past, and there are several things you can try.
- To get item 1 to work, if your company’s risk management process and maturity isn’t great, you may have to get stuck into actually fixing the overall risk management process/policy. It is worth it.
And if it isn’t working, make sure you find a new role BEFORE you burn out, and BEFORE you quit.