
Cybersecurity oversight has officially entered the realm of board level fiduciary responsibility. In several 2025 decisions, the Delaware Court of Chancery made clear that cybersecurity is a mission critical risk for most companies. In the aftermath of these decisions, directors of Delaware corporations now face heightened expectations for monitoring, documenting and addressing cybersecurity risks as part of their oversight duties.
The duty of oversight for board members originates from the decision in In re Caremark International Inc. Derivative Litigation and was later affirmed in Stone v. Ritter. These cases established that directors may be liable if they fail to implement systems for reporting and monitoring corporate risk or ignore red flags. Historically, Caremark claims were difficult to plead and rarely succeeded. However, recent decisions have expanded the application of the duty of oversight to include cybersecurity risks, especially in industries where data protection is central to operations.
In 2025, the Court of Chancery emphasized that cybersecurity risks qualify as mission critical for companies that store consumer data, operate online platforms or rely heavily on digital infrastructure. In addition, the Court has concluded that boards must receive regular cybersecurity briefings and may not delegate oversight entirely to management. Documenting oversight efforts means that recordkeeping is more essential than ever. The absence of board minutes documenting cybersecurity discussions may support an inference of oversight failure. Moreover, failure to respond adequately to known vulnerabilities could constitute a red flag under the Caremark standard.
Although the Court did not impose strict liability on directors involved in these 2025 cases, it nonetheless signaled that cases in 2026 and beyond may have different outcomes if directors fail to demonstrate active oversight supported by tangible evidence. Many California companies are incorporated in Delaware. Therefore, these decisions apply directly to their boards regardless of where their primary operations or headquarters are located. In order to insulate boards from liabilities, companies must ensure that board committees have clear cybersecurity responsibilities and that documentation reflects active engagement. To that end, boards must incorporate cybersecurity into their quarterly (or even monthly) agendas.
Also, directors should require management to present regular and recurring updates on vulnerabilities, incidents and mitigation efforts. Boards should also take an active role in reviewing third party risk management programs, and ensure that management maintains an incident response plan and tests it regularly. As part of their record keeping efforts, boards should also maintain detailed minutes reflecting discussions and decisions that revolve around and relate to data security.
Clearly, cybersecurity has become a core governance issue with direct implications for fiduciary duty. Delaware courts expect directors to maintain informed and active oversight, and companies that build strong governance frameworks and document their practices will be best positioned to mitigate litigation and regulatory risk moving forward.
This publication is published by the law firm of Ervin Cohen & Jessup LLP. The publication is intended to present an overview of current legal trends; no article should be construed as representing advice on specific, individual legal matters. Articles may be reprinted with permission and acknowledgment. ECJ is a registered service mark of Ervin Cohen & Jessup LLP. All rights reserved.
- Partner
Jeffrey R. Glassman is Partner and Chair of the Intellectual Property and Technology Law Department and has earned the esteemed designation of Certified Information Privacy Professional (CIPP/US).
Jeffrey has spent the last two ...
Subscribe
Recent Posts
- Privacy Returns to the Supreme Court: Geolocation, Video Data & What Clients Should Expect | By: Jeffrey R. Glassman
- The Risk of Boilerplate PAGA Waivers in Employment Arbitration Agreements | By: Jared W. Slater
- California Issues New Minimum Wage Poster | By: Kelly O. Scott
- What Is the Proper Venue for Filing Financing Statements and Judgment Liens When the Entity Involved Was Formed Out of State? | By: Peter A. Davidson
- Employment Arbitration Agreement Rollout During Class Action Backfires in Federal Court Case | By: Jared W. Slater
- Why Collateral Terms in Your Non-Disclosure Agreement May - or May Not - Tank Your Arbitration Policy | By: Jared W. Slater
- Courts Decline to Short-Circuit AI Copyright Claims | By: Banu Naraghi
- When Does the Time to Appeal Run for an Order Appointing a Receiver? | By: Peter A. Davidson
- PAGA Standing Remains a Matter for the Courts Even After Arbitration | By: Jared W. Slater
- Delaware Expands Expectations for Board Oversight of Cybersecurity | By: Jeffrey R. Glassman
Blogs
Contributors
Archives
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- October 2019
- September 2019
- August 2019
- July 2019
- June 2019
- May 2019
- March 2019
- February 2019
- January 2019
- November 2018
- October 2018
- September 2018
- August 2018
- July 2018
- June 2018
- May 2018
- April 2018
- February 2018
- January 2018
- December 2017
- November 2017
- October 2017
- September 2017
- August 2017
- July 2017
- June 2017
- May 2017
- April 2017
- March 2017
- February 2017
- January 2017
- December 2016
- November 2016
- October 2016
- September 2016
- August 2016
- July 2016
- June 2016
- May 2016
- April 2016
- January 2016
- December 2015
- November 2015
- October 2015
- September 2015
- August 2015
- July 2015
- June 2015
- May 2015
- April 2015
- March 2015
- February 2015
- January 2015
- December 2014
- November 2014
- October 2014
- September 2014
- August 2014
- July 2014
- June 2014
- May 2014
- April 2014
- March 2014
- February 2014
- January 2014
