By in-house counsel, for in-house counsel ®

Online Learning Center

SEC Cyber Incident and Risk Management Disclosure Readiness: Materiality Assessments, Related Incident Assessments and Cyber Risk Program Disclosures

Recorded On: 03/26/2024

  • Register
    • Non-member - $40
    • Member - $25
    • *Further discounts may apply once you log in.
In today’s digital age, cyber incident and risk management disclosure readiness is a critical aspect of the Security Exchange Commission’s (SEC) regulatory framework. Materiality assessments help companies determine the significance of a cyber incident in the context of their financial reporting and are rapidly becoming a core element of company programs as a result of the rule passed in July of 2023 by the SEC, requiring companies to disclose material cybersecurity incidents they experience and to disclose on an annual basis material information regarding their cybersecurity risk management, strategy and governance. Related incident assessments are equally important as they provide insight into the nature and scope of the incident, aiding in the development of a comprehensive disclosure strategy. Disclosures today require Security Incident Response Teams (likely part of Information Security) and Legal/Compliance teams to work more closely together than ever before. In all likelihood, there is a component of data privacy and risk related to data privacy breach analysis that is included in such reviews. In a world where cyber threats are increasingly prevalent and more sophisticated, companies must be vigilant and prepared to address questions from investors about their cybersecurity strategy and preparedness regarding disclosure, before an event occurs. This 60-minute panel discussion will help teams to better understand how to prepare for SEC cyber incident and risk management disclosure requirements including materiality and related incident assessments and cyber risk program disclosures.

Key:

Complete
Failed
Available
Locked
Program Recording
Recorded 03/26/2024  |  60 minutes
Recorded 03/26/2024  |  60 minutes
Program Feedback Form
7 Questions

Brice White

Associate General Counsel, Privacy Incidents

Meta

Carolyn Herzog

Chief Legal Officer

Elastic

Michelle VonderHaar

Chief Legal Officer

Tenable

Michelle VonderHaar, Chief Legal Officer and Corporate Secretary, leads Tenable’s global legal organization. Tenable is a leader in exposure management providing products and solutions that empower organizations to understand and reduce their cybersecurity risk. Michelle is a seasoned legal executive with more than 30 years of domestic and international legal experience, working and living in the United States, Europe, and Asia, and leading global legal teams focused on providing strategic and practical advice to global organizations.
Prior to Tenable, Michelle served as Senior Vice President, Deputy General Counsel and Assistant Secretary at HP, driving transformation of the company’s commercial global legal affairs team from a three-region model to nine geographic markets. Michelle also served as the HP’s Chief Compliance Officer and Deputy General Counsel for the Print Global Business Unit, Global Ethics & Compliance, Employment, Brand Security, Litigation, Privacy, Supply Chain, Antitrust, Environmental, Health & Social Responsibility.

Prior to HP, Michelle served as Senior Vice President and General Counsel of Veritas Technologies, a leading backup and storage enterprise software company that spun out of Symantec Corporation. Before that, Michelle held various positions with Symantec, a global enterprise and consumer antivirus and storage software provider, in its legal department, including leading the corporate function, M&A and compliance. Michelle also led Symantec’s legal team in the APJ region, based in Singapore, and served as the General Counsel to the Huawei-Symantec joint venture, based in China.

Before moving in-house, Michelle was a commercial litigator with Katten Muchin Zavis LLP in Los Angeles and Irvine, and a corporate finance and M&A attorney with O’Melveny & Myers LLP practicing in London, San Francisco, and Silicon Valley.

Michelle is admitted to practice law in California, Washington, D.C., New York, and England & Wales, and she received her law degree from the University of Arizona, James E. Rogers College of Law where she was a member of and published in the Arizona Law Review.

Michelle also serves as a board member for a number of non-profit organizations, including D.C.-based Urban Libraries Council, Silicon Valley Leadership Group Foundation, and Catholic Charities of Santa Clara County. She also serves as an advisory board member of Parents Helping Parents.

Natalie Prescott

General Counsel & Chief Privacy Officer

Fulgent Genetics

Experienced executive (Russel 2000; NASDAQ: FLGT), AmLaw 2 (Latham & Watkins LLP), healthcare and life sciences attorney, board member, cybersecurity professional, award-winning book author, and privacy law specialist (PLS). Expert negotiator and problem-solver. I am a valued partner, trusted advisor, and business strategist. I pride myself on strong leadership, cross-functional collaboration, and solution-oriented approach.

I lean into nearly two decades of legal experience to mitigate business risks, including complex business litigation, healthcare, regulatory, class actions, corporate securities, corporate governance, risk management, privacy, data breach response, compliance, ESG & DEI, labor and employment, HR, and intellectual property.

https://www.linkedin.com/in/np...

Alexander "Sandy" Bilus

Partner

Saul Ewing

Alexander (Sandy) R. Bilus assists clients who are facing complex commercial litigation or who need legal advice on issues involving cybersecurity and data privacy, particularly in the higher education and financial services industries. Sandy's litigation experience includes arguing cases before the U.S. Court of Appeals for the Third Circuit and assisting with cases before the U.S. Supreme Court and the Supreme Court of Pennsylvania. His cybersecurity and data privacy experience includes responding to potential data breaches and providing advice on compliance with the European Union's General Data Protection Regulation (GDPR). 

Sandy's work for institutions of higher education includes providing advice and conducting internal investigations connected to their compliance concerns, as well as responding to private lawsuits and government enforcement activity.

https://www.saul.com/professio...