Target's $10 million settlement over its 2013 cyber breach illustrates a shifting tide as director liability grows. As cybersecurity best practices become fixed, boards are being advised to make sure their organizations are adhering to new standards or risk being exposed to increased liability. Rapidly changing trends in cyber litigation are changing the way organizations approach cybersecurity.

Boards need to ensure that they have a direct link with the chief information security officer (CISO), suggests Litigation partner James P. Bobotek. Although many companies place the CISO beneath the chief information officer, Bobotek says that this can shield the board from important information it needs to know about breaches and security budgets.

This is one way data security can be viewed through the lens of enterprise risk management rather than through the IT department, he says – click here to read the full article (subscription required).