CSL CSL Corporate Liability & Risk Management 1 — Questions and Answers
Question 1: Under which legal theory can a corporation be held liable for cybersecurity failures of its officers if those failures resulted in harm to shareholders?
- Respondeat superior
- Breach of fiduciary duty (Correct answer)
- Negligence per se
- Strict liability
Correct answer: Breach of fiduciary duty
Corporate directors and officers owe fiduciary duties of care and loyalty to shareholders, and systematic failure to oversee cybersecurity risks can constitute a breach.
Question 2: What is the primary legal standard that protects corporate directors from personal liability for good-faith cybersecurity decisions that later prove wrong?
- Business judgment rule (Correct answer)
- Duty of loyalty exception
- Safe harbor provision
- Best efforts standard
Correct answer: Business judgment rule
The business judgment rule protects directors who make informed, good-faith decisions in the corporation's best interest, even if those decisions lead to losses.
Question 3: The SEC's 2023 cybersecurity disclosure rules require public companies to disclose material cybersecurity incidents within how many business days of determining materiality?
- 2 business days
- 4 business days (Correct answer)
- 10 business days
- 30 calendar days
Correct answer: 4 business days
The SEC's 2023 rules require disclosure of material cybersecurity incidents on Form 8-K within four business days of determining the incident is material.
Question 4: Under FTC Act Section 5, what cybersecurity standard are companies held to when they fail to protect consumer data?
- Strict liability for all data breaches
- Unfair or deceptive trade practices standard (Correct answer)
- Negligence per se based on NIST standards
- Reasonable care under common law
Correct answer: Unfair or deceptive trade practices standard
The FTC uses Section 5's prohibition on unfair or deceptive acts to enforce cybersecurity, finding violations when companies fail to maintain reasonable security promised to consumers.
Question 5: Which legal doctrine can hold a parent company liable for cybersecurity failures of its subsidiary?
- Piercing the corporate veil
- Respondeat superior
- Both A and B depending on facts (Correct answer)
- Neither, subsidiaries are always separate
Correct answer: Both A and B depending on facts
Courts may pierce the corporate veil when a subsidiary is merely an alter ego of the parent, or apply respondeat superior when parent employees directed the subsidiary's operations.
Question 6: What is the legal term for the obligation of companies to have a documented process for identifying, assessing, and managing cybersecurity risks?
- Due diligence
- Duty of care
- Reasonable security obligation (Correct answer)
- Cybersecurity governance
Correct answer: Reasonable security obligation
The reasonable security obligation requires organizations to implement security measures appropriate to the sensitivity of data and potential harm from a breach.
Under which legal theory can a corporation be held liable for cybersecurity failures of its officers if those failures resulted in harm to shareholders?