image

Cybersecurity

Overview

As cybersecurity risks continue to evolve and escalate, the prospect of undergoing a cyberattack is more a question of “when” than “if” for most companies. The Anderson Kill cybersecurity team includes authors of leading treatises on cyber insurance recovery; former government officials and federal and state prosecutors; IP attorneys with extensive tech experience; and attorneys with deep understanding of the technical as well as legal aspects of cybersecurity and compliance.

Our cybersecurity attorneys help clients to

  • Establish working relationships with state and federal agencies overseeing cybersecurity, including the DOJ, FBI, FTC, DHS, the federal Cybersecurity and Infrastructure Agency (CISA), the New York Department of Financial Services,  the New York Dept. of Homeland Security, and appropriate agencies in other states.
  • Develop policies to ensure compliance with the EU’s General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), other key national privacy and data protection laws, and relevant state statutes and regulations, including biometric privacy laws.
  • Establish cyber security, crisis management and disaster recovery plans and teams that address the full range of potential incidents and establish lines of communication and authority.
  • In the event of a data breach or other attack, assist in-house personnel as they work to:
  1. Verify the breach, determine its extent, and contain it.
  2. Determine what data is affected and what risks result — e.g., inoperability of computer systems, identity theft (from customers, employees, others), theft of trade secrets, liability to injured parties, government penalties, reputational damage
  3. Consider whether there is a compulsory requirement to inform anyone (e.g., regulators, data subjects, suppliers, customer) of the breach, or if there are good reasons to do so even if there is not. Establish good working relations with regulatory agencies probing the event.
  4. Consider all communications – to customers and partners, regulators, markets and the general public, including via social media —  in light of regulatory requirements, public relations considerations and litigation risk, including defamation, and in light of preserving privilege where appropriate.
  5. Assess and manage contractual obligations, with particular reference to clauses relating to data protection obligations, compliance with laws, force majeure and rights to terminate. Meet contractual notification requirements.
  6. Forestall or defend against regulatory action or litigation from consumers, other customers, or shareholders.
  7. In the event of theft, negligence triggering loss on the part of third parties, or theft of trade secrets or other IP, or cryptocurrency assets, pursue redress, including litigation if necessary.
  8. Navigate the regulatory risks and potential criminal liability associated with ransomware payments.
  9. Assess the manifold sources of loss and liability, give prompt notice to all potentially responsive insurance policies, and aggressively pursue insurance claims to cover those losses and liabilities.
  10. Conduct after-action review. Modify systems and processes to limit the risk of reoccurrence and optimize response if a reoccurrence proves unavoidable.

In today’s high-risk cyber environment, effective prevention and crisis response are a continuum.  Our team is well equipped to help clients avoid cyber losses and liabilities, mitigate them when they do occur, and maximize insurance recovery after the fact.

 

Click the links below to learn more and purchase a treatise:

Events

Social engineering fraud: Understand how cyber and crime insurance policies do (and do not) respond

Lockton / April 28, 2026

Cyber and Privacy Risk and Insurance in 2025: Part I—”the Basics”

HB Litigation / August 7, 2025

Cyber Insurance:  What All In-House Counsel Need to Know

2025 Cybersecurity Summit / March 24, 2025

Cyber Risks and Recovering Insurance Proceeds for Cyber Incidents

Practising Law Institute / March 5, 2025

AI Did What? Anticipating Insurance Coverage Issues Arising from AI Liability (2023)

Anderson Kill / November 3, 2023

Strategies for Mitigating Risk Management and Data Breach Losses Arising out of Social Media Activity – RIMS Tampa Bay (2016)

RIMS Tampa Bay Chapter / June 15, 2016

Can Cyber Insurance Stand in the (Data) Breach? How to Maximize Coverage in a Buyer’s Market (2016)

Anderson Kill's 2nd Annual Cyber Insurance Recovery Conference / May 12, 2016

Strategies for Mitigating Risk Management and Data Breach Losses Arising Out of Social Media Activity (2016)

RIMS Upstate New York Chapter / March 8, 2016

What Every Risk Manager Needs to Know About Data Security Jul-2015

RIMS Kentuckiana/Bluegrass Chapter / July 23, 2015

What Every In-House Counsel Needs to Know about Data Security (2015)

ACC Minnesota / June 18, 2015

What every in-house counsel needs to know about data security

Association of Corporate Counsel Greater Philadelphia Chapter / May 19, 2015

What Every Risk Manager Needs to Know About Data Security Mar-2015

Central Florida RIMS Chapter / March 19, 2015

Cyber Security Development You Need to Know

New Jersey Institute for Continuing Legal Education / January 28, 2015

Cyber Breach & Security: Risk Management & Insurance Issues

Westchester-Fairfield CPCU / November 21, 2014

What Every Risk Manager Needs to Know About Data Security Aug-2014

Memphis RIMS PERK Chapter / August 21, 2014

Publications

When Sublimits Bite: Navigating Cyber Insurance Risks in Retail and Hospitality

Cyber Insurance Recovery Alert / May 13, 2026

Protecting Policyholders as AI is Developed for Insurance Claims Handling: Ensuring “Decency and Humanity” in the Digital Age

Journal of Emerging Issues in Litigation / May 22, 2024

Cyberattacks are bankrupting health care providers. Insurance may help.

Medical Economics / May 13, 2024

The Promise and Peril of Quantum Computing and Its Implications for Cyber Insurance

Journal of Emerging Issues in Litigation / February 22, 2024

SEC’s SolarWinds Litigation Expands Regulatory Cyberrisk Landscape

Risk Management Magazine / November 22, 2023

The Board’s Role in Cyber Risk Management

Risk Management Magazine / June 1, 2023

SEC’s Proposed Cyber Rules Underscore D&O Risks

Risk Management Magazine (RMM) / June 15, 2022

Cyberattacks — A Spotlight On Ransom Losses And Insurance

American Bar Association (ABA) / September 10, 2021

Multiple Insurance Policy Lines Can Cover Ransomware Losses

Cyber Insurance Alert / May 21, 2021

Ransomware Attack on Colonial Pipeline Underscores Multiplicity of Cyber Risks and Potential Insurance Coverages

Cyber Insurance Alert / May 14, 2021

Cyber Risk Management In The Pandemic Era

Risk Management Magazine / November 12, 2020

A Pandora’s Box Of Cyberrisks

Risk Management Magazine / June 4, 2018

Rising Ransomware Threats And Their Insurance Solutions

Law360 / July 5, 2017

Baby Monitors & Steel Mills: The New World Of Cybersecurity Risk

Risk Management Magazine / February 6, 2017

News

Companies face potentially tighter constraints on AI use as regulators lead drive to assess risks

May 1, 2024

Insurers seek to keep pace with explosive use of AI

May 1, 2024

23andMe Breach Compounded by Theft of Ethnicity Data

November 7, 2023

Cybersecurity Awareness Month with Pamela Hans of Anderson Kill

October 10, 2023

Home Depot Hack Coverage Loss Gives Policyholders Pause

September 14, 2023

Soaring Ransomware Risks Require Vigilance

October 29, 2019

People

image
Luma S. Al-Shibib

Shareholder , New York

image
image
Cameron R. Argetsinger

Shareholder , Washington, DC

image
image
Joshua Gold

Shareholder , New York

image
image
Pamela D. Hans

Office Managing Shareholder , Philadelphia

image
image
Jeremy B. Shockett

Shareholder and General Counsel , New York

image
Key Contact(s)
image
Joshua Gold
View Moreimage
image
Luma S. Al-Shibib
View Moreimage

© Copyright 2026 by Anderson Kill P.C. ClickySoft - WordPress Development Company