CYBER INCIDENTS ARE NOW LITIGATION EVENTS

CD: Over the past few years, how have you seen the nature of cyber incidents evolve from primarily technology and security issues into broader litigation, regulatory and governance events?

Tenery: Historically, cyber incidents had limited accountability, and aftermath activity was ascribed to just technology teams and practitioners. Now, responsibility and accountability are extended across a much broader population of the enterprise, from IT and security, to human resources (HR), legal, finance and even all the way up to the board. Now when questions are asked about when or where the incident began, and what the company knew, it is not only the chief information security officer (CISO) and IT teams responsible for answering those questions. Furthermore, class actions have taken on new industry level proportions in terms of the size, rigour and maturity of resources pursuing damages from breached firms. This also aligns with the spirit of increased and continually increasing regulation and oversight, such as advancements in California Consumer Privacy Act requirements, and deeper levels of inquiry and scrutiny by states when incidents are reported by victim companies.

CD: What factors are driving the increase in cyber incidents triggering multiple forms of exposure simultaneously, including regulatory investigations, shareholder actions, commercial disputes and class actions?

Fisher: More and more enterprises are interconnected, through supply chain, service providers, customers and product users. An incident is rarely confined to a single victim, and risks transfer into multiple environments and extend to multiple victims. What is more, firms also must balance the risks of an increased attack surface area with often rapid adoption of new technology, or assets newly generated from artificial intelligence (AI). Enterprises are experiencing a rapid sprawl while certain remaining legacy platforms represent significant risk.

Oct-Dec 2026 issue

StoneTurn