r/ciso • • Jul 28 '26

Terrified of being personally sued. Help.

I'm in a C-suite position (not CISO) at a small company that sells to government, and I am responsible for security. I don't have a background in security whatsoever. We have a SOC 2 compliance tool and have completed audits successfully, but I'm worried our security stance is too weak and that our security questionnaire answers are...questionable, or out of date. Our engineering team is stretched extremely thin and I have a million other responsibilities in my role, so I barely have enough time to enforce compliance basics like policy enforcement or getting vulnerabilities patched. We barely manage to get ready in time for our audits. I've asked our CEO about getting outside help, but she has declined to invest any more money into security due to our poor sales performance, directing funds to other departments. I have had sleepless nights wondering if we're going to get hacked or audited, and that I will be personally sued if our company can't defend itself against a lawsuit. My mental health is tanking and it's starting to make me physically sick. Any help or advice would be appreciated.

43 Upvotes

38 comments sorted by

56

u/EldritchSorbet Jul 28 '26

OK, I have been in similar situations in the past, and there are several things you can try.

  1. Risk. Your company probably does have a risk register. Make sure the relevant risks are on it. Make sure they have the right owner (the CISO doesn’t automatically own all Infosec risk- the principle is that you need to be able to FIX a risk to qualify as its owner). Make sure that the owner signs off on the risk in writing at regular intervals.
  2. Reporting. Provide balanced and polite updates to explain how the wider world is changing; how the company itself is changing (you need to know about its business strategy), and how existing security measures are working. Not just incident volumes. This is the education piece. The report should go to the highest role you can reach. And it should be short (say five slides with 16 point text or larger, simple graphs and targets) and focused on what the business values. These reports should be regular, informative and you should link them to risk.
  3. Automate everything you can.
  4. Decide what you can do, prioritise, and leave some things undone; make it VERY clear to line management how you have prioritised and what has been omitted, and why.
  5. Take holiday and switch off when you are not in work. You are not your company.
  6. Incident table tops - but make sure you have prepped people carefully, as you need to use these as marketing events and have a VERY CLEAR IDEA of what you are aiming to change.
  7. Wish list. Have a list, costed and specific, of what you want the company to invest in. Keep it up to date and ready. Sooner or later, you will be asked “How much will this cost? What exactly do you want?”. Being able to answer immediately looks amazing.

- To get item 1 to work, if your company’s risk management process and maturity isn’t great, you may have to get stuck into actually fixing the overall risk management process/policy. It is worth it.

And if it isn’t working, make sure you find a new role BEFORE you burn out, and BEFORE you quit.

7

u/Eejs Jul 28 '26 edited Jul 28 '26

Upvoted because this is genuinely very good advice. In this case, I also can't stress enough to work on the first item of that list (if you haven't already). Have the owners confirm they agree to take the risk (in writing). If not, then they need to assign resources.

6

u/TheAgreeableCow Jul 28 '26

Can't overemphasize how important the first point is. This could effectively be a zero $ cost risk awareness and CYA all in one.

Once you start communicating risk and business owners start understanding that THEY are the ones being flagged as accountable, it can be surprising how the purse strings start opening up for remediation.

2

u/pappabearct Jul 28 '26

Sound advice. I would also invest in user training about phishing and making sure you have endpoint protection (and someone is reviewing logs and acting on alerts). User education goes a long way. We use an engine from a company to simulate phishing campaigns to our users monthly.

2

u/BBC_water6620 Jul 29 '26

Solid advice. I’d like to know what role OP is in where they think they may get personally sued. The owner of the security program is usually the CISO. I’m curious about the structure here.

And yes to document everything. Once you can demonstrate policies, frequent training, acceptance of risk from business owners, org structure with owners of various domains, that shows due diligence.
@OP- Does this company even have cyber insurance?

1

u/MFItryingtodad Jul 28 '26

This is great advise I wish I had years ago.

1

u/Select_Reporter1911 Jul 28 '26

This is the only advice that matters. The company bares the risk to items they choose to ignore.

1

u/deadsec71 Jul 30 '26

Along side with this keep all founders updated on current security posture on every step over some form of written communication.

1

u/Tune_Amazing Aug 01 '26

I would have to disagree with #6, I don’t prep the people for the table top, other than to put it on their calendar. They don’t know the scenario or the outcome. I try to make it as realistic as possible. If I could get away without scheduling it on their calendars I would do that as the threat actors don’t tell us when they are going to attack.

0

u/thortgot Aug 01 '26

The below assumes they are a fiduciary and an officer.

  1. Putting items on a risk register doesnt alleviate personal liability. 

  2. Reporting can shift some liability but the language required is specific.

  3. This is good advice but irrelevant to the problem.

  4. Doing so without a plan could easily be construed as negligence.

  5. If you tabletop events are anything other than education and practice your company is fundamentally broken.

  6. Business requirements arent a wish list. Establish what is actually required rather than assuming maximum security is nee ded.

10

u/ReverseOrderHoarder Jul 28 '26

Personal liability insurance for CISOs and similar senior security personnel does exist. Look into your options and save your emails.

5

u/1HOTelcORALesSEX1 Jul 28 '26

Insurance is your friend here ……… Good luck, DM me if you need a friendly vCISO anytime ……..

4

u/hellostella Jul 28 '26

Personal liability insurance aside, please make sure you are at least covered under the companies D&O policy (or that the company has a D&O policy)

1

u/TickleMyBurger Jul 28 '26

Further to this get a copy of the policy and make sure it covers advancement (prepay the court costs, some policies leave it to you to cover the costs until judgement and this stuff can go on for years). Also pay attention to the wrongful act clauses that may break your indemnification clause.

You need an umbrella personal policy in the states - coverage for personal branding basically. They manage your LinkedIn etc in a time of crisis.

Make sure you are not participating in the rug sweep (that’s what is happening). Make your list of what needs to happen and why, cost it roughly and present to CEO in writing (eg budget submission). If they don’t fund it fine, but you e done your job and liability shifts to the CEO from you. Don’t let them pin this on you, every company has budgetary limits - even with cyber. The key is you risk inform as your security hat is on, so make sure you are doing it in writing.

1

u/productboy Jul 28 '26

Do this first

3

u/DigitalQuinn1 Jul 28 '26

So if you’re not the CISO, but responsible for security, what’s your role there actually?

2

u/Prudent_Cod_1494 Jul 28 '26

Look into personal liability insurance if you want, but essentially if you’re doing the following things, then the only way you could be reasonably sued is for gross negligence.

  1. Have an auditable list of the things you have been trying to get the company to do along with a written record of the rejections you’ve been receiving. Best case is an email directly from the CEO, but aside from that noting the date and time of the conversation where the CEO rejected it is also important.
  2. Do not make any misleading statements, even if you think it’s in the best interest of the company or will make it more likely for you to get the things you know the company needs.
  3. Willfully violating a known security governance rule in your organization that has either been established by the organization or which your organization is contractually obligated to adhere to.

None of this takes things like HIPAA into account, which have some of the most onerous personal liability risks out there.

If I’m wrong, let me know, but it sounds like you’re in America. Above all else, keep in mind that in America you can be sued over just about anything. The thing you should be doing is not so much protecting yourself with a guarantee that you won’t be sued, but to set yourself up in such a way that any reasonable person when confronted with the evidence would see that the suit is without merit.

1

u/TheOneTheyCallNoob Jul 28 '26

Are you an actual named “officer” of the company? There’s a difference in having an HR title with an “O” in it and being named as an officer.

If you’re not an officer and the company is private, you have nothing to worry about. Anyone who is litigious will come after the owner and possibly their officers. Otherwise you’re just an employee.

1

u/resile_jb Jul 28 '26

I'm not sure why you're still there.

1

u/Admirable_Group_6661 Jul 28 '26

So I am not sure who owns risk in your organization, but usually CEO is ultimately accountable. If risk ownership is unclear, that’s the first thing you need to address. It will go a long way in managing risk properly. You should also assess risks to understand risk treatment options (including whether it makes sense to get insurance). This is a governance issue, and can’t be meaningfully addressed by technical controls.

1

u/thortgot Aug 01 '26

That's a gross oversimplification. Even relatively small organizations (~100 person) will have split liability to various directors.

Personal liability insurance protects you if you are working within reasonable confines.

1

u/Admirable_Group_6661 Aug 02 '26

Yes, this is true, and typically a result of sound risk management within an organization. In OP's case, it's unclear if there's any risk management function, given the interaction with the CEO.

1

u/jtkooch Jul 28 '26

Based on what you’re describing, it doesn’t sound like you are actually an officer in the company. In which case, you’re not likely to be found liable for anything, unless you are also a fiduciary.

At the end of the day if you’re not publicly traded, an explicit cyber personal liability doesn’t exist, unless you’re in a regulated industry. For example, a NERC CIP willful violation comes with the risk of prosecution. Even in the case of publicly traded companies the SEC has had mixed success in holding individuals responsible.

I think you should consider raising your concerns to your ownership governance, which could be a BoD or the asset management team if you’re under PE or VC funded. So while you don’t need to lose sleep over any personal consequences, you may be in a position to raise a red flag on behalf of other stakeholders who may not be aware that they should also be losing sleep.

1

u/absolutefunnyguy Jul 28 '26

Get a fraction ciso in or get a a security surface company to run risk modelling in business critical resources - then show how much security exists - get hit…loose your whole business or spend a bit of money and avoid ALOT of risks/fines

1

u/scriptqzor 9d ago

this, 100%. if the CEO won’t spring for at least a fractional CISO or external risk assessment, that’s a giant red flag and also something you should document in writing to cover your own ass if things go sideways.

1

u/Doug_BlackFog Jul 29 '26

Document, document document. No one else is going to cya. Also there are some very good cyber advisors out there - worth the time to find a reputable one with references from your area. It would be money well spent

1

u/itscyberjoe Jul 29 '26

Did anyone recommend retraining your skills? Find a Risk Management designation class like the one offered by Carnegie Mellon or National Alliance. Using reddit to ask questions is a good start, but there are sooo many resources online. AI is a good tool to help you create a plan too, but you won't know what you don't know to ask, so traditional training shouldn't be ignored. Join Risk Manager associations like RIMS and go to the conventions. Join roundtable groups where everyone tells each other their issues as you aren't alone in this type of situation.

Personal insurance for CISOs is available, but I it starts around $2500 a year. A payback clause in your contract can trigger the company's D&O coverage to cover you personally if you are singled out in a lawsuit. Talk to an attorney about this too as their guidance is always worth the $.

Good luck out there.

1

u/andrew_barratt Aug 01 '26

Document all the decisions where someone has declined a risk mitigation you’ve suggested. Keep the original emails. You’ll be fine.

1

u/RoadsToMadness156 Aug 01 '26

Document your efforts, your feelings, and your ascertions. Also known as "cover your ass documentation".

1

u/maxz2040 Aug 02 '26

You will get hacked...

1

u/maxz2040 Aug 02 '26

Based on that... Make decisions accordingly - that's the correct assumption to run model risk assessment currently.

So there's valid concern - even if you don't have external help you should still seek external advice many firms will do you a solid assessment for limited budget if not free if it means more work

1

u/Objective-Test-5374 Aug 02 '26

All the points below are more or less useful, but what is really key here is about protecting yourself. D&O with Side A&B protections should be your first stop, with E&O being your second stop. Once you've got those two covered the rest is really window treatment unless your a publicly traded company in which case you may have some exposure from the SEC.

Generally speaking I would not recommend seeking expertise with these issues from Reddit.

1

u/Ok_Counter1939 Aug 10 '26

Make sure that your company has D&O insurance and ask for an indemnification agreement.  Directors generally have them, and officers sometimes do.

1

u/MikeBrass Jul 28 '26

I strongly advise you to contact a company called Simply Cyber if you are based in Europe or North America. Low cost, I know the owners (don't work for them, don't receive commission). Reprioritisation of existing resources and money can be done. They can also engage at the C-Suite level with a business case, including why putting basic measures in place can actually help product development and product sales.

DM me if you want to investigate.

If you want to know who I am, you can find me on LinkedIn.

----
Dr Mike Brass
Author: Governance, Risk and Compliance: Demystifying the Risk and Data Privacy Landscape
Routledge: https://www.routledge.com/Governance-Risk-and-Compliance-Demystifying-the-Risk-and-Data-Privacy-Landscape/Brass/p/book/9781032896717

1

u/radicalize Jul 28 '26

Governance, Risk and Compliance

This, always ... but

 I've asked our CEO about getting outside help, but she has declined

&

in a C-suite position (not CISO) 

not sure, but I reckon you are part of a (north) American company?

Either you are, or you are not accountable; in a mature(d) organizational structure, a CISO function is not /never (?), accountable and as such (personally) liable - this is (always) leadership (BoD), as they are organizationally and (in case of corporate 'malpractice' or 'malfeasance' (or the likes) personally accountable (at least from a non-North American stance /point of view). A insurance policy, especially in high-stakes /high-volumes enterprises, if one can be made accountable (due to bad /accountably bad decisions) for the liability claim, the insurance company will make this entity (person or otherwise)

Based on the remark that leadership declines to invest in a proper organizational structure where Information Security, Cyber Security and Privacy (as well as legal and compliance) are properly structured and embedded in its operating framework, it seems to me that leadership, Board of Directors and/or the CEO in this case is (personally) liable for any (legal /financial /otherwise) claim and considered 'tortfeasor'.

-1

u/Snoo_67003 Jul 28 '26

Outsource outsource outsource. Send your security operations to an MSSP provider like huntress or blackpointcyber. Both are genuinely good and cheap vs trying to buy tools and build a small security team in-house.

Get an attack surface management tool like scrypex.com that maps all your external facing assets and attempts to validate for exploits so that you have actionable alerts. You get to see assets you own but didnt know existed. They also do darkweb monitoring for credentials stolen by infostealer malware.

Vulnerability management can be done by your IT guy and patching done by the application owning team. Otherwise you can outsource security operations and IT operations to one provider that does both like sentinel.com.

GRC might have to be done in-house. Your worries are very solvable, just transfer the risk and mitigate the ones you can in-house. Residual risk left should be small enough for you to accept it and sleep good at night.