logo

Four common infosec legal risks and how to mitigate them

ID: 4136c100-815d-5e0a-afb5-06709199f107

STIX ID: report--4136c100-815d-5e0a-afb5-06709199f107

Feed Name: Expel Blog

Date Published: 2019-04-24

Date Updated: 2026-04-27

Author: Marc Zwillinger; Marci Rosen

...
...

**Executive Summary:** This article outlines four common legal risks arising from information security shortcomings—failing to implement risk-based controls, overlooking vendor security, not documenting or following security policies, and excluding legal teams during incident response—and provides practical mitigations such as using recognized frameworks (e.g., NIST), requiring vendor security assurances and breach notification clauses, documenting and enforcing policies, and designating counsel to direct incident response to preserve privilege and manage regulatory and notification obligations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.