
A data breach used to be an IT problem. Now it's a boardroom liability. This article reveals how "cyber-washing," failed oversight, and a little-known DOJ initiative are turning cybersecurity into the next frontier of director and officer lawsuits — and what your board needs to do right now to stay off the plaintiffs' radar.
14
MINUTE READ
For years, cybersecurity was treated primarily as a technical and operational matter — the responsibility of IT departments and Chief Information Security Officers, with little direct bearing on the boardroom. That view is rapidly becoming obsolete. As companies increasingly rely on interconnected systems, third-party vendors, and now artificial intelligence to run core business functions, the consequences of a cybersecurity failure extend well beyond a technical outage. They now reach directly into the realm of corporate governance, exposing directors and officers to shareholder litigation, regulatory enforcement, and personal liability.
From IT Issue to Fiduciary Duty
Boards of directors owe fiduciary duties of care and loyalty to the companies and shareholders they serve. Historically, courts have been reluctant to extend these duties deeply into operational risk oversight. But as cyber incidents have grown more frequent, more costly, and more disruptive to business operations, shareholders and regulators have increasingly argued that a board's failure to oversee cybersecurity risk is itself a breach of fiduciary duty — not merely a technology failure, but a governance failure.
This shift means directors and officers can face personal exposure not because they personally caused a data breach, but because they allegedly failed to ask the right questions, implement reasonable oversight structures, or ensure the company had adequate controls and incident-response plans in place before an event occurred.
Three Ways Cybersecurity Failures Translate into D&O Exposure
1. Failure of Board Oversight. The most direct governance theory is a claim that the board did not adequately monitor cybersecurity risk — failing to receive regular briefings, failing to allocate appropriate resources to security controls, or failing to establish reporting lines that would surface known vulnerabilities to leadership. When a breach later occurs, plaintiffs often argue in hindsight that the board's oversight function was inadequate from the start.
2. Inadequate or Misleading Disclosures — Including "Cyber-Washing." Companies that overstate their cybersecurity readiness to investors, customers, or regulators — a practice increasingly referred to as cyber-washing — face heightened litigation risk when an actual incident reveals that public statements about security posture were materially inaccurate. This mirrors the disclosure theories already driving a wave of"AI-washing" securities litigation, where companies are sued for overstating AI capabilities or governance. Cybersecurity claims can follow the same pattern: the further a company's public narrative about its defenses diverges from reality, the greater its exposure once a breach exposes the gap.
3. Mismanaged Incident Response. Even companies that experience a breach through no clear fault of their own can face liability if their response is slow, disorganized, or communicated poorly to investors and regulators. Delayed disclosure, inconsistent public statements, or a failure to remediate known vulnerabilities after an initial warning sign can transform a contained technical incident into a governance failure with securities and shareholder-derivative litigation attached.
The Regulatory Overlay: The False Claims Act
For companies that do business with the federal government, cybersecurity governance failures carry an additional layer of risk under the False Claims Act (FCA). Through initiatives targeting cybersecurity-related fraud, the Department of Justice has pursued government contractors for knowingly providing deficient cybersecurity products or services, misrepresenting their security practices, or falsely certifying compliance with required cybersecurity standards — exposing companies to treble damages and penalties. Notably, liability under this theory does not require that an actual data breach occur; a false certification of compliance alone can trigger exposure. This adds a compliance-certification dimension to cybersecurity governance that boards of government contractors cannot afford to overlook.
Why This Matters for D&O Underwriting and Risk Management
The convergence of cybersecurity risk and corporate governance has direct implications for how companies think about their insurance programs. Cyber liability insurance remains the primary coverage for the direct costs of a breach — forensics, notification, business interruption, and third-party liability arising from compromised data. But as cybersecurity failures increasingly give rise to claims against directors and officers personally — for breach of fiduciary duty, misleading disclosures, or mismanaged response — D&O insurance becomes an equally critical piece of the puzzle.
Companies should not assume that one policy or the other automatically responds to a cyber-driven claim. A shareholder derivative suit alleging that the board failed to oversee cybersecurity risk is a D&O exposure; a claim by affected customers following a breach is typically a cyber liability exposure; and a claim alleging the company misrepresented its security readiness to investors may implicate both. Boards should work with their brokers to confirm how their D&O and cyber programs interact, where gaps or overlaps exist, and whether sub limits or exclusions could leave a governance-related cyber claim underinsured.
PracticalSteps for Boards
Several concrete steps can help boardsreduce their exposure:
Conclusion
Cybersecurity is no longer aback-office technology concern — it is a board-level governance issue with direct implications for director and officer liability. As litigation theories continue to evolve, from fiduciary duty claims to disclosure-based securities suits to False Claims Act enforcement, boards that treat cybersecurity oversight as a core governance function — rather than delegating it entirely to IT — will be better positioned to defend their decisions and protect both the company and its leadership from the next wave of cyber-related litigation.
Related Industries
Related Articles