New Bill Targets Cybersecurity Expertise on Boards of Directors

Cooley Alert

On December 17, 2015, Senators Jack Reed (D-RI) and Susan Collins (R-Maine) introduced, S2410, the Cybersecurity Disclosure Act of 2015, which would require public companies to disclose what cybersecurity expertise their Board of Directors ("Board") possesses. If enacted, this bill would require the Securities and Exchange Commission to issue new rules mandating that public companies describe any cybersecurity experience or expertise held by the members of their Board in the companies' annual reports or proxy statements. If a company's Board does not have any members with cybersecurity expertise, the bill would require the company "to describe what other cybersecurity steps taken by the reporting company were taken into account" by nominating committees when selecting potential board members.

This bill would not require public companies to elect Board members with any cybersecurity expertise. If enacted (which is highly uncertain), it might lead shareholders to pressure companies to include cybersecurity experts on their Board, or to strengthen and clarify how the Board is advised and educated about cybersecurity threats. Even if the bill is not enacted into law, its introduction still may raise shareholder awareness about the need for Board members to better understand and address cybersecurity threats.

Related Contacts
Nicole Brookshire Partner, Boston
Tom Coll Partner, San Diego
Darren DeStefano Partner, Reston
Jim Fulton Partner, New York
Jon Gavenman Partner, Palo Alto
Kenneth Guernsey Partner, San Francisco
Brian Leaf Partner, Reston
Randy Sabett Special Counsel, Washington, DC
Vince Sampson Special Counsel, Washington, DC
Brent Siler Partner, Washington, DC
Scott Stemetzki Associate, Reston
Francis Wheeler Partner, Colorado
Related Practices & Industries

Privacy & Data Protection