Menu

New Bill Targets Cybersecurity Expertise on Boards of Directors

Cooley Alert

On December 17, 2015, Senators Jack Reed (D-RI) and Susan Collins (R-Maine) introduced, S2410, the Cybersecurity Disclosure Act of 2015, which would require public companies to disclose what cybersecurity expertise their Board of Directors ("Board") possesses. If enacted, this bill would require the Securities and Exchange Commission to issue new rules mandating that public companies describe any cybersecurity experience or expertise held by the members of their Board in the companies' annual reports or proxy statements. If a company's Board does not have any members with cybersecurity expertise, the bill would require the company "to describe what other cybersecurity steps taken by the reporting company were taken into account" by nominating committees when selecting potential board members.

This bill would not require public companies to elect Board members with any cybersecurity expertise. If enacted (which is highly uncertain), it might lead shareholders to pressure companies to include cybersecurity experts on their Board, or to strengthen and clarify how the Board is advised and educated about cybersecurity threats. Even if the bill is not enacted into law, its introduction still may raise shareholder awareness about the need for Board members to better understand and address cybersecurity threats.

Related Contacts
Tom Coll  Partner San Diego
Darren DeStefano  Partner Reston
Jim Fulton  Partner New York
Jon Gavenman  Partner Palo Alto
Kenneth Guernsey  Partner San Francisco, Palo Alto
Brian Leaf  Partner Reston
Randy Sabett  Special Counsel Washington, DC
Vince Sampson  Special Counsel Washington, DC
Brent Siler  Senior Counsel Washington, DC, Reston
Francis Wheeler  Partner Colorado
Related Practices & Industries

Cyber/Data/Privacy