The room was quiet except for the soft hum of the projector. A CEO was walking the board through the quarterly numbers when a director asked a question that had nothing to do with revenue: “If we get breached next month, are any of us personally on the hook?” Nobody had a good answer. The general counsel shifted in her seat. The CFO stared at the table. That silence, more than any threat report, is why board members are suddenly paying attention to cybersecurity.
Here’s the uncomfortable truth. For years, corporate boards treated cybersecurity as an IT problem. Something the CISO handled. Something you reviewed once a year in a slide deck and nodded along to. That era is over. Regulators, plaintiffs’ attorneys, and shareholders have all figured out that a breach isn’t just a technical failure — it’s a governance failure. And when governance fails, the people who are supposed to be governing start looking personally liable.
If you sit on a board, or you advise people who do, this article is for you. We’re going to walk through what personal cyber liability actually means, where the risk comes from, what the real-world cases look like, and how to build a defense that holds up. We’ll also talk about how frameworks like VisibleOps Cybersecurity, built by Scott Alldridge and the IT Process Institute, give boards a practical way to demonstrate oversight without turning directors into part-time security engineers.
Let’s get into it.
Why Board Members Are Suddenly Exposed to Personal Cyber Liability
A decade ago, the idea that a director could be sued personally over a data breach would have sounded absurd. Today, it’s a routine part of the conversation at any serious company. So what changed?
Three things, mostly.
The regulatory shift toward personal accountability
Regulators stopped being satisfied with corporate fines. The SEC’s 2023 rules on cybersecurity disclosure require public companies to report material incidents within four business days and to describe their processes for assessing and managing cyber risk. That sounds procedural, but the subtext is clear: the board is expected to have a process. If it doesn’t, that’s a governance problem, and regulators now have a paper trail to prove it.
The FTC has been aggressive too. Its enforcement actions have increasingly named executives and officers, and the agency has made it clear it will pursue individuals when it believes they ignored known risks. The message to directors is simple: “We didn’t know” is no longer a defense if you had a duty to know.
The rise of derivative lawsuits
A derivative lawsuit is when shareholders sue on behalf of the company, alleging that directors and officers breached their fiduciary duties. After a major breach, this has become almost automatic. The playbook goes like this: the company discloses the incident, the stock drops, a plaintiffs’ firm files a derivative suit, and suddenly every board member is a named defendant.
The most famous example is the SolarWinds case. In 2023, the SEC charged the company’s CISO with fraud and internal control failures related to the 2020 breach. A federal judge later dismissed most of the claims, but the case still sent shockwaves through boardrooms. If a CISO could be personally named, what about the directors who approved the risk appetite?
The Caremark doctrine and the oversight duty
Delaware corporate law has a concept called the Caremark duty, named after a 1996 case. It requires directors to make a good-faith effort to oversee the company’s compliance with law. For decades, it was almost impossible to win a Caremark claim because the bar was so high. Then came Marchand v. Barnhill in 2019, where the Delaware Supreme Court allowed a claim to proceed against Blue Bell Creameries directors after a listeria outbreak. The court found that the board had no system for monitoring food safety.
That case cracked the door open. Since then, plaintiffs have used similar logic to argue that boards with no cyber oversight system are failing their Caremark duty. The result: directors who once felt untouchable now need to show that they actually engaged with cyber risk.
The practical reality
Here’s what all this means for you as a board member. If your company gets breached, and there’s evidence you had no real process for overseeing cyber risk, you can be personally named in a lawsuit. You can spend years in litigation. You can face reputational damage that follows you to every future board seat. And depending on the jurisdiction and the facts, you may not be fully covered by indemnification or D&O insurance.
That’s the risk. Now let’s talk about who’s actually coming after you.
Who Can Sue a Board Member Over a Data Breach?
The list of potential plaintiffs is longer than most directors realize. Let’s break it down.
Shareholders
This is the most common source of personal liability. Shareholders argue that the board failed to protect company assets, failed to disclose risks properly, or failed to act on known vulnerabilities. Derivative suits don’t require the company to go bankrupt — just to suffer a measurable loss tied to the breach.
What makes these suits dangerous is that they don’t require proof of intent. The plaintiffs only need to show that the board acted in bad faith or with conscious disregard for its duties. In practice, that often means showing the board ignored warning signs.
Regulators
The SEC, FTC, and state attorneys general all have cyber enforcement powers now. The SEC has been particularly active. In addition to the SolarWinds case, the agency has fined companies for misleading disclosures and for failing to maintain adequate controls. The critical point: regulators increasingly name individuals, not just entities. A director who signed off on a misleading risk disclosure can be personally exposed.
State regulators add another layer. The California Privacy Protection Agency, the New York Department of Financial Services, and others have their own enforcement regimes. If you sit on a board of a company doing business in multiple states, you’re dealing with multiple regulators.
Customers and business partners
Class action lawsuits from customers are common after a breach. But what surprises directors is the contractual exposure. If your company signed a service agreement with a security clause and then got breached, the counterparty can sue for breach of contract. If the contract includes personal guarantees — rare, but not unheard of — you could be on the hook directly.
Employees
HR data is sensitive. If a breach exposes employee personal information, employees can sue. In some states, they can sue individually or as a class. The board’s exposure here is usually derivative, but if there’s evidence the board knew about a vulnerability and did nothing, individual claims become more plausible.
The board itself
This one is subtle but real. In some cases, boards sue their own members. If one faction of the board believes another faction ignored risk, they can bring a claim. This is rare, but it happens in family-owned companies and in companies with activist investors.
The takeaway: personal cyber liability isn’t hypothetical. It’s live, it’s growing, and it applies to you even if you’re not a security expert.
The Real-World Cases Every Board Member Should Know
Let’s look at what’s actually happened. These cases aren’t outliers — they’re the template.
SolarWinds and the SEC’s personal charges
In 2020, SolarWinds suffered one of the most significant supply chain breaches in history. Russian hackers compromised the company’s Orion software and used it to penetrate thousands of customers, including U.S. government agencies. In 2023, the SEC charged SolarWinds and its CISO, Timothy Brown, with fraud and internal control failures.
The SEC alleged that Brown and the company misled investors about the severity of the breach and about the company’s security practices. The case was partially dismissed in 2024, but the core message remained: regulators are willing to name individuals.
For board members, the lesson is that your CISO can be personally exposed, and if the CISO is exposed, the board that oversaw them is next in line.
The Caremark cases and food safety analogies
Marchand v. Barnhill was about ice cream, not cybersecurity. But the legal reasoning applies directly. The Delaware Supreme Court found that Blue Bell’s board had no committee or process for monitoring food safety, which was the company’s central compliance risk. The court allowed the derivative claim to proceed.
Since then, plaintiffs have filed similar suits against boards in industries with high cyber risk. The argument is consistent: if cyber is a central risk, the board must have a monitoring system. If it doesn’t, the board has breached its duty.
Derivative suits after major breaches
After the Equifax breach in 2017, shareholders filed derivative suits against the board. The company settled for hundreds of millions. After the Target breach in 2013, similar suits followed. Neither case resulted in directors paying out of pocket, but the legal costs and reputational damage were significant.
The pattern is clear. A breach happens. Shareholders sue. The board spends years dealing with it. The board members who had a documented, active oversight process fare better than those who didn’t.
The D&O insurance problem
Here’s the part that surprises people. Directors and Officers insurance is supposed to protect you, but it has limits. Insurers have become more cautious about cyber-related claims. Some policies exclude cyber entirely. Others require the board to demonstrate that it followed basic governance practices.
If your D&O policy has a cyber exclusion, or if the insurer argues that you failed to disclose known risks, you could be personally responsible for legal fees and settlements. That’s a financial risk that can run into the millions.
The Three Pillars of Personal Cyber Liability Exposure
To understand your risk, it helps to break it down into three categories. Each one creates a different kind of exposure.
Pillar 1: The duty of oversight
This is the Caremark duty. Directors must make a good-faith effort to oversee the company’s compliance with law, including cyber law. The key word is “effort.” You don’t have to be perfect, but you have to try. You have to ask questions, request reports, and document your engagement.
If you can’t show that, you’re exposed.
Pillar 2: The duty of disclosure
Public companies have a duty to disclose material risks to investors. Cyber risk is now considered material. If your company doesn’t disclose its cyber risk properly, or if it downplays a known vulnerability, the board can be liable for misleading statements.
This is where the SEC’s disclosure rules matter. The board doesn’t have to write the disclosures, but it has to ensure that management is doing it accurately. If the board signs off on a review that it didn’t actually perform, that’s a problem.
Pillar 3: The duty of loyalty and good faith
Directors owe a duty of loyalty to the company. If a breach exposes evidence that a director put their own interests ahead of the company’s — for example, by delaying a security investment to protect a bonus — that’s a breach of loyalty. Similarly, if the board consciously disregarded a known risk, that can be a breach of good faith.
These claims are harder to prove, but they’re more damaging when they succeed. They can strip you of indemnification and D&O coverage, leaving you personally exposed.
Why Cyber Risk Is Different From Other Board Risks
You might be thinking: “I already oversee financial risk, legal risk, and operational risk. What’s different about cyber?”
Good question. The answer is speed, complexity, and evidence.
Speed
A financial problem unfolds over quarters. A cyber breach unfolds over hours. By the time the board is briefed, the damage is done. That compresses the window for oversight. Directors can’t wait for the next quarterly meeting to engage with cyber risk — the risk moves faster than the board’s schedule.
Complexity
Cyber risk is technical, but it’s also operational, legal, and reputational. It touches every part of the business. Most directors don’t have the technical background to evaluate it directly, so they rely on management. That reliance creates a gap: if management doesn’t provide good information, the board can’t exercise oversight.
Evidence
Everything in cyber is documented. Logs, emails, meeting minutes, vulnerability scans. In litigation, that evidence is discoverable. A plaintiff’s attorney can request the board’s cyber-related emails and meeting notes. If there’s no evidence of engagement, the plaintiff wins.
Compare that to a financial risk claim, where the board can argue that it relied on auditors. Cyber risk doesn’t have the same cushion. The board has to show its own work.
What Good Cyber Oversight Looks Like for a Board
Okay, enough about the risk. Let’s talk about what you can actually do.
Good cyber oversight isn’t about becoming a security expert. It’s about establishing a repeatable process that demonstrates engagement. Here’s what that looks like in practice.
Step 1: Establish a cyber committee or designate a cyber lead
Not every board needs a full committee, but every board needs someone whose job it is to own cyber risk. That person should have direct access to the CISO and should report back to the full board. The committee structure also provides a paper trail, which matters in litigation.
Step 2: Get regular, plain-language reporting
The CISO’s job isn’t to impress you with acronyms. The job is to give you the information you need to make decisions. Ask for a monthly or quarterly report that covers the top risks, the status of remediation, and any incidents. Ask for it in plain language.
If your CISO can’t explain the risk in business terms, that’s a red flag. Either they don’t understand it well enough, or the board isn’t asking the right questions.
Step 3: Tie cyber risk to business risk
Cyber risk isn’t separate from business risk. It’s part of it. A ransomware attack that shuts down production is an operational risk. A data breach that triggers regulatory fines is a financial risk. A breach that leaks customer data is a reputational risk.
When the board discusses cyber, it should discuss it in the context of business outcomes. That makes the risk real and actionable.
Step 4: Ask the uncomfortable questions
Here are some questions every board member should be asking:
- What are our top three cyber risks right now, and what are we doing about them?
- How would we know if we were breached? What’s our detection capability?
- Do we have a tested incident response plan? When was it last exercised?
- What’s our cyber insurance coverage, and what does it exclude?
- How do we compare to our peers in terms of security maturity?
- What’s the cost of a worst-case scenario, and are we comfortable with that?
If management can’t answer these questions, that’s a governance gap.
Step 5: Document everything
Minutes should reflect that cyber was discussed, what was presented, what questions were asked, and what decisions were made. This is your evidence. In a derivative suit, the meeting minutes are often the first documents plaintiffs request.
Step 6: Use a proven framework
This is where frameworks matter. A framework gives the board a structure for oversight. It also provides a defensible standard: “We followed the framework.” That’s much stronger than “We did our best.”
How VisibleOps Cybersecurity Helps Boards Demonstrate Oversight
This is where Scott Alldridge’s work becomes directly relevant.
Scott Alldridge spent over 30 years in IT management and cybersecurity. He holds an MBA in Cybersecurity, is a Certified Chief Information Security Officer (CCISO), a CISSP, and holds a Harvard certification in Privacy and Technology. He co-created the VisibleOps framework with the IT Process Institute, and the VisibleOps Cybersecurity handbook series has sold more than 400,000 copies worldwide.
The framework exists because of a specific problem: IT operations and security teams often work in silos. Operations focuses on uptime and efficiency. Security focuses on risk and compliance. When those goals conflict, things slip through the cracks. VisibleOps brings them together.
For boards, the value is in three areas.
It gives the board a governance structure
VisibleOps emphasizes disciplined change management, continuous incident resolution, and real-time monitoring. Those aren’t just technical practices — they’re governance practices. They create a system that can be described, measured, and audited. That’s exactly what a board needs to demonstrate oversight.
It translates technical risk into business language
The VisibleOps Cybersecurity: Executive Companion Handbook is written specifically for non-technical leaders. It strips out the jargon and explains cyber risk in terms of business outcomes. That means board members can engage with the material without needing a technical background. It also means the board can have informed conversations with management instead of relying on blind trust.
It addresses Zero Trust and compliance
Zero Trust is one of the most talked-about security models, but it’s often poorly implemented. VisibleOps Cybersecurity integrates Zero Trust with operational practices, including micro-segmentation, identity management, and continuous verification. For boards in regulated industries — PCI, HIPAA, Sarbanes-Oxley — the framework also addresses compliance automation. That’s important because compliance failures are often the trigger for personal liability.
The bottom line: VisibleOps doesn’t just help the security team. It gives the board a defensible, documented approach to oversight. That’s the difference between “we talked about cyber once” and “we have a governance process.”
Building a Board-Level Cyber Risk Program: A Step-by-Step Walkthrough
Let’s make this concrete. Here’s a practical process for building a board-level cyber risk program from scratch.
Step 1: Assess your current state
Start by documenting what you already do. Do you have a cyber committee? Do you receive regular reports? Do you have a documented risk appetite? If the answer is “not much,” that’s your baseline.
Step 2: Define your oversight model
Decide who owns cyber risk at the board level. Options include:
- A standalone cyber committee
- A subcommittee of the audit committee
- A designated director with cyber expertise
- Full board oversight with a management liaison
Each model has trade-offs. The key is to choose one and document it.
Step 3: Establish a reporting cadence
Set a schedule for cyber reporting. Monthly is ideal for large organizations. Quarterly is the minimum. The report should cover:
- Top risks and changes since the last report
- Incidents and near-misses
- Remediation progress
- Key metrics (mean time to detect, mean time to respond, patch compliance)
- Regulatory developments
Step 4: Define your risk appetite
The board should define how much cyber risk the company is willing to accept. This isn’t a technical exercise — it’s a business decision. For example: “We are willing to accept moderate risk of a data breach but not risk of a production shutdown.” That statement guides management’s priorities.
Step 5: Integrate with enterprise risk management
Cyber risk shouldn’t live in a silo. It should be part of the company’s broader enterprise risk management (ERM) process. That means it gets the same attention as financial risk, legal risk, and operational risk.
Step 6: Test the plan
Once a year, run a tabletop exercise with the board. Walk through a simulated breach. What happens? Who calls whom? What decisions need to be made? This exercise does two things: it tests the plan, and it creates evidence of board engagement.
Step 7: Review and improve
Cyber risk changes constantly. New threats emerge. New regulations pass. The board’s oversight process should evolve. Schedule an annual review of the program and update it as needed.
Common Mistakes Boards Make With Cyber Oversight
Even boards that take cyber seriously can get it wrong. Here are the most common mistakes.
Relying on the CISO alone
The CISO is important, but they’re not the board’s only source of information. Directors should also hear from internal audit, external auditors, and sometimes outside experts. Relying on one voice creates blind spots.
Treating compliance as security
Compliance is a floor, not a ceiling. A company can be PCI-compliant and still get breached. Boards that focus only on checkboxes miss the bigger picture.
Skipping the post-incident review
After an incident, the board should review what happened, what was learned, and what changed. Skipping this step signals that the board isn’t serious about oversight — and plaintiffs’ attorneys will notice.
Ignoring third-party risk
Many breaches start with a vendor. Boards should ask how the company manages third-party risk, including cloud providers, contractors, and software vendors.
Not documenting discussions
If it isn’t in the minutes, it didn’t happen. Boards that have good conversations but don’t document them are leaving themselves exposed.
Assuming D&O insurance covers everything
D&O policies have limits and exclusions. Boards should review their coverage with counsel and understand exactly what’s covered.
The D&O Insurance Angle: What Directors Need to Know
D&O insurance is your first line of defense, but it’s not a magic shield. Here’s what to watch for.
Exclusions
Many policies now include cyber exclusions or sublimits. Some exclude claims arising from failure to maintain security. Others exclude regulatory investigations. Read the policy carefully.
The “known risk” problem
If the board knew about a specific vulnerability and didn’t act, the insurer may deny coverage. This is why documentation matters. If the board discussed the risk and made a reasoned decision, that’s different from ignoring it.
Side A coverage
Side A coverage protects directors when the company can’t indemnify them. This is critical in insolvency situations. Make sure your policy has strong Side A coverage.
Retention and limits
Understand the retention (deductible) and the policy limits. If a breach triggers a $10 million claim and the policy limit is $5 million, the difference comes from somewhere.
The role of the broker
Your insurance broker should be able to explain the coverage in plain language. If they can’t, find a new broker.
How to Protect Yourself as a Board Member: A Practical Checklist
Here’s a checklist you can use right now.
- Confirm you have a cyber oversight process. If not, propose one at the next board meeting.
- Review your D&O policy. Understand the exclusions, limits, and retention.
- Ask for regular cyber reports. Monthly or quarterly, in plain language.
- Document your engagement. Ensure meeting minutes reflect cyber discussions.
- Define your risk appetite. Put it in writing.
- Request a tabletop exercise. Run it annually.
- Review third-party risk. Ask how vendors are managed.
- Consider a cyber-savvy director. If no one on the board has expertise, recruit someone who does.
- Use a framework. VisibleOps Cybersecurity provides a defensible structure.
- Get outside advice. If you’re unsure, bring in an expert — ideally someone like Scott Alldridge, who has both the technical depth and the board-level perspective.
The Role of the Executive Companion Handbook
One of the challenges for board members is that most cybersecurity material is written for security professionals. It’s full of acronyms and assumes technical knowledge. The VisibleOps Cybersecurity: Executive Companion Handbook flips that.
The handbook is designed for CEOs, COOs, CFOs, board members, and business owners. It explains cyber risk in business terms. It covers:
- How to evaluate your company’s security posture
- What questions to ask management
- How to prioritize investments
- How to understand Zero Trust without getting lost in the technical details
- How to align cybersecurity with business strategy
For a board member who wants to be genuinely useful, this is a practical starting point. It’s not a technical manual — it’s a governance guide.
What to Do in the First 90 Days
If you’re a new board member, or if your board is just starting to take cyber seriously, here’s a 90-day plan.
Days 1–30: Learn
- Read the VisibleOps Cybersecurity: Executive Companion Handbook.
- Meet with the CISO and ask the questions listed earlier.
- Review the company’s cyber insurance policy.
- Review recent incident reports and audit findings.
Days 31–60: Assess
- Evaluate the current oversight process. What’s working? What’s missing?
- Benchmark against peers. How does the company’s security maturity compare?
- Identify gaps in reporting, documentation, or risk appetite.
Days 61–90: Propose
- Bring recommendations to the board. This could include a new committee, a reporting cadence, or a tabletop exercise.
- Propose a framework for oversight. VisibleOps is a strong candidate.
- Document the plan and set a review date.
The Cost of Doing Nothing
Let’s talk about what happens if you don’t act.
A breach happens. The board is caught flat-footed. Shareholders sue. The SEC investigates. The D&O insurer denies coverage because the board didn’t have a process. Legal fees mount. The directors who had no oversight process are personally exposed.
Even if the case settles, the reputational damage is real. Directors who were named in a breach lawsuit find it harder to get new board seats. They face uncomfortable questions at other companies. The personal toll — stress, time, legal fees — is significant.
Now compare that to the alternative. A board that has a documented oversight process, regular reporting, and a tested incident response plan is in a much stronger position. If a breach happens, the board can show that it did its job. The legal exposure drops. The insurance coverage holds. The reputational damage is manageable.
The cost of building a cyber oversight program is small — a few meetings, some training, maybe a consulting engagement. The cost of not building one can be career-ending.
Frequently Asked Questions
Can a board member really be personally liable for a cyber breach?
Yes. Directors can be named in derivative lawsuits, SEC enforcement actions, and other proceedings. Personal liability usually requires evidence of bad faith or failure to oversee, but the bar is lower than it used to be. The Caremark doctrine and recent enforcement actions have made personal exposure more realistic.
Does D&O insurance cover cyber claims?
It depends on the policy. Many D&O policies include cyber coverage, but with exclusions, sublimits, or conditions. Some exclude cyber entirely. Directors should review their policies carefully with counsel and understand exactly what’s covered.
What’s the Caremark duty, and how does it apply to cyber?
Caremark is a Delaware legal doctrine that requires directors to make a good-faith effort to oversee compliance. It applies to cyber because cyber is now a central compliance risk. If the board has no process for monitoring cyber risk, it may be found to have breached its duty.
How often should the board receive cyber reports?
Quarterly is the minimum. Monthly is better for larger organizations or those in high-risk industries. The report should cover top risks, incidents, remediation, and key metrics.
What’s the best way to demonstrate cyber oversight?
Documentation. Meeting minutes, committee charters, risk appetite statements, and incident response plans all serve as evidence. Using a proven framework like VisibleOps strengthens the board’s position.
Do private companies face the same risk?
Yes, though the dynamics differ. Private companies face less SEC scrutiny but can still face lawsuits from shareholders, customers, and employees. Directors of private companies should still take cyber oversight seriously.
How can Scott Alldridge help my board?
Scott Alldridge and the VisibleOps framework provide training, coaching, and consulting for boards and executives. The Executive Companion Handbook is specifically designed to help non-technical leaders understand cyber risk. IP Services, Scott’s managed IT and cybersecurity company, also offers hands-on support.
What’s the first step?
Start with a conversation. Ask your board chair to put cyber risk on the agenda. Bring in an expert if needed. The first step is acknowledging that the risk is real — and that it’s shared by the whole board.
Conclusion: Oversight Is Your Best Defense
Personal cyber liability isn’t a distant threat. It’s a present reality for board members across industries. Regulators, shareholders, and plaintiffs’ attorneys have all figured out that cyber risk is governance risk. Boards that treat it seriously — with documented processes, regular reporting, and a proven framework — are in a much stronger position. Boards that don’t are exposed.
The good news is that the solution isn’t complicated. You don’t need to become a security expert. You need to establish a repeatable process for oversight, ask the right questions, and document your engagement. Frameworks like VisibleOps Cybersecurity give you a structure to follow. And experts like Scott Alldridge give you a guide who understands both the technical and the boardroom sides of the problem.
If you’re a board member, the question isn’t whether you should act. It’s how soon.
Start by reading the VisibleOps Cybersecurity: Executive Companion Handbook. Then bring the conversation to your board. Ask the hard questions. Build the process. Because when the breach happens — and for many companies, it will — you want to be the board that was ready, not the board that was named in the lawsuit.
Your seat at the table comes with responsibilities. Cyber oversight is one of them now. Handle it well, and you protect the company, your fellow directors, and yourself.
The next board meeting is your opportunity. Take it.