Author: George Hampton
Cybersecurity Enforcement Has Changed
For years, cybersecurity enforcement followed a familiar pattern. A breach occurred, regulators investigated, and penalties followed if safeguards or responses fell short. That model no longer reflects today’s reality. Enforcement actions are now frequently brought without a major breach. Regulators are looking closely at what companies say about their cybersecurity programs, how those programs are governed, and whether organizations can prove their controls were in place when it mattered. The shift is clear. Cybersecurity enforcement is no longer about technical failure alone. It is about accountability, accuracy, and evidence.
Regulators are increasingly treating cybersecurity representations as enforcement targets. Public disclosures, customer commitments, and compliance certifications are all under scrutiny. For executives, boards, and legal teams, cybersecurity has moved well beyond IT. It is now a core business risk and a governance issue that directly impacts credibility, valuation, and enterprise risk. Organizations are being evaluated not just on whether they have a cybersecurity program, but whether that program is aligned with what they have represented to regulators, customers, and the market.
Enforcement is no longer limited to data breaches or system outages. Instead, regulators are focusing on process failures, particularly where companies have described their cybersecurity programs as robust but cannot substantiate those claims. The question has changed. It is no longer just what failed. It is what leadership knew, what the company represented, and what it can prove. This shift places increased pressure on executives and boards to understand cybersecurity not as a technical function, but as a governance responsibility tied directly to enterprise risk.
Federal enforcement trends reflect this shift. The Department of Justice’s Civil Cyber-Fraud Initiative is expanding False Claims Act exposure for organizations that certify compliance with cybersecurity requirements tied to federal funding but fail to meet them in practice. In these cases, the issue is not just whether controls existed, but whether the organization’s representations were accurate at the time they were made. In parallel, the Federal Trade Commission continues to pursue actions where companies overstate their security posture or fail to maintain reasonable safeguards, treating those gaps as unfair or deceptive practices. Together, these developments signal a broader enforcement focus on alignment between what companies say and what they can demonstrate.
Cybersecurity is also now a disclosure issue. The Securities and Exchange Commission is actively enforcing against companies that fail to accurately describe cyber risks or incidents. Downplaying known risks, presenting real exposure as hypothetical, or failing to update disclosures can all create exposure. This is particularly important for public companies, where cybersecurity disclosures are increasingly tied to investor expectations and market transparency. The takeaway is straightforward. How a company communicates cyber risk matters just as much as how it manages it.
At the state level, California continues to set the pace. The California Privacy Protection Agency is actively enforcing data governance obligations, with a focus on operational and oversight failures rather than breach response alone. Recent actions highlight issues such as failure to honor opt-out rights, use of dark patterns, excessive data collection, and insufficient vendor oversight. These are not isolated compliance issues. They reflect a broader expectation that organizations maintain control over how data is collected, used, and shared across the business. Enforcement in this area increasingly reaches into product design, marketing practices, and executive decision-making.
One of the most consistent risks we see is the documentation gap. Many organizations have well-written cybersecurity policies that describe comprehensive programs. Far fewer can demonstrate that those programs were implemented, tested, and maintained over time. That gap between what is written and what can be proven is where enforcement risk and litigation exposure often begin. In today’s environment, policies alone are not enough. Regulators expect to see evidence that controls were operational, monitored, and supported by active oversight.
For executives and boards, the takeaway is clear. This is no longer optional. Cybersecurity must be treated as a legal, operational, and strategic priority. That means building a repeatable, well-documented evidence trail, including risk assessments, remediation decisions, and oversight records. It also means ensuring that public statements, customer commitments, and compliance certifications align with the controls that actually exist and are reviewed regularly. Alignment across legal, compliance, IT, and business teams is critical to managing this risk effectively.
This shift is also driving increased civil litigation risk. Plaintiffs are relying on the same materials that regulators request, including privacy notices, marketing statements, internal communications, and governance records. Misalignment between what a company says and what it can prove can lead to consumer claims, contract disputes, and, for public companies, securities litigation. As regulatory expectations evolve, those same expectations are being mirrored in private litigation. Strong alignment between representations and evidence reduces both regulatory exposure and downstream risk.
In an investigation, regulators move quickly to assess how seriously cybersecurity was treated before any incident occurred. They will request risk assessments, board and committee materials, incident response plans and testing records, vendor diligence files, and internal communications around known vulnerabilities. These are not routine requests. They are used to evaluate credibility, governance maturity, and whether the company’s public statements were supported by real evidence. Organizations that are able to respond quickly and confidently to these requests are in a far stronger position to manage the outcome.
Organizations that are prepared, those that can produce clear, organized, and defensible documentation, are far better positioned to manage scrutiny and protect enterprise value.
At FBFK Law, we counsel clients navigating cybersecurity investigations, enforcement actions, and related litigation. As enforcement priorities evolve, aligning cybersecurity governance with a defensible legal strategy is critical. The organizations that will lead in this environment are not the ones making the strongest promises, but the ones that can prove how cybersecurity is governed, implemented, and disclosed.

