Impending U.S. Standards for Cybersecurity
by Ira E. Hoffman
Offit Kurman, P.A.
Estimates of the costs to the global private sector from cyber attacks over the past decade easily exceed $100 billion — and they are growing exponentially. Most of those costs result from the theft of intellectual property (IP) and confidential business information, disruption of service, added expenditures to recover from such attacks and improve network security, and reputational damage. Despite the meteoric rise in the number, ferocity and sophistication of such attacks against private enterprise and the Federal, State and local governments in the U.S., Congress has failed to pass comprehensive cybersecurity legislation since 2002.
Two recent developments have, fortunately, marked meaningful efforts by the U.S. Government to make up for the lack of any overarching cyber legislation: (1) Executive Order 13636, which was issued in February 2013 to establish a national policy on critical infrastructure security and resilience; and (2) the Preliminary Cybersecurity Framework (the Framework) that the National Institute of Standards and Technology (NIST) issued in October 2013 to improve cybersecurity for America’s critical infrastructure.
In the Executive Order, the President made the policy a shared responsibility, not only among Federal, State, and local authorities, but also among public and private owners and operators of critical infrastructure (including multinational owners). Although the Executive Order does not have the same authority as an Act of Congress, it defined “critical infrastructure” to encompass 16 broad sectors — chemical; commercial facilities; communications; critical manufacturing; dams; the Defense Industrial Base; emergency services; energy; financial services; food and agriculture; Government facilities; healthcare and public health; information technology; nuclear reactors, materials and waste; transportation systems; and water and wastewater systems — to extend the impact of the Executive Order as much as practicable.
In addition, the Executive Order also directed NIST to establish a document – which became the Framework —for improving critical infrastructure security against persistent cyber threats. As NIST has explained, the Framework will consist of standards, methodologies, procedures and processes that align policy, business, and technological approaches to address cyber risks. To be sure, the Framework is “preliminary,” but it is intended to evolve as the nature and intensity of cyber attacks evolve, and many industry experts do not expect it to change much before February 2014, when the first finalized iteration is due to be released. Then, in the absence of any new superseding legislation, the Framework will likely become the de facto standard that courts will apply to determine whether critical infrastructure companies were negligent when their customers were victimized by cyber attacks. Moreover, since cyber attacks are not limited to the critical infrastructure, the Framework will likely become the civil liability standard in the U.S. for protecting privacy, proprietary data, confidential information and IP from malicious cyber activities.
Given that more than 50 different Federal statutes, plus laws in most of the 50 States in the U.S., address separate aspects of cybersecurity, either directly or indirectly, the importance of the Framework as an emerging uniform standard for cybersecurity compliance cannot be exaggerated. Thus, the attorneys in Offit Kurman’s Cybersecurity Practice Group, who already have considerable experience in cyber law, have also immersed themselves in the Framework. In that way, they can better assist their clients — plus fellow GGI members and their clients — in this rapidly changing area of law, by, e.g.:
- Creating security policies and corporate governance approaches,
- Ensuring compliance with classified security requirements,
- Negotiating licenses and contract clauses for “cloud computing” and other data storage or outsourcing of data handling,
- Navigating notice requirements once a security breach has occurred,
- Negotiating contracts to include security and data protections,
- Drafting licenses and IP protection for software advances,
- Advising on compliance with U.S. export controls (ITAR and EAR) for technology,
- Navigating e-commerce rules and issues,
- Developing privacy policies for companies handling Personal Health Information (PHI) and Personally Identifiable Information (PII),
- Assisting in audits of IP assets,
- Responding to government inquiries and investigations,
- Conducting internal investigations and advising on voluntary disclosures,
- Pursuing insurance indemnification and defense costs related to security breaches and remediation, and
- Providing legislative updates and information.
Since the cost of a single cyber breach has been estimated at $5 million and since the number of targets and intensity of attacks will only increase, businesses will remain at significant risk unless they implement more effective cyber strategies and start treating cybersecurity as an issue for the CEO and Board of Directors, and not just as a problem for the IT department.
In short, whether businesses or individuals have already been victimized by cyber attacks, which is quite likely, or are preemptively seeking advice on compliance with the emerging cyber standards, attorneys in the Cybersecurity Practice Group at Offit Kurman — which is based in the Baltimore/Washington, D.C. corridor, known as the “epicenter” of cybersecurity in the U.S. —are ready to assist them.

GGI member firm
Offit Kurman, P.A.
Legal, Banking, Bankruptcy, Construction, Corporate, Cybersecurity, Employment, Estates & Trusts, Family law, Government Contracts, International, Litigation, Real Estate, Tax.
Over 100 attorneys in seven offices serving Washington DC, Baltimore, Philadelphia, Wilmington and Northern Virginia,



