Most boards unprepared for crisis, say legal departments

Companies are poorly prepared for a crisis with one in three admitting they have no crisis management plan in place.
Prefer the Global Legal Post on Google

Rawpixel

Only three per cent of respondents said their companies were 'well prepared' to handle a crisis. This is despite one in four companies (24 per cent) saying they were the victims of ransomware in the past year alone. Furthermore, despite increased scrutiny on boards of directors regarding cybersecurity oversight, 38 per cent of respondents do not report to their boards on cyber matters whilst another 14 per cent do so less than once a year. The research also revealed that companies are nearly evenly split when it comes to distinguishing internally between privacy and data security, with 53 per cent of respondents indicating that their organisations do so.

No actionable plan

The two challenges that emerged in the research as top-of-mind concerns were privacy and data security, and risk and crisis management. Whilst nearly all companies recognise the importance of planning and preparedness for a material cyber security breach or other crisis, a significant swath still either have no actionable plan in place or do not test their plans with any regularity. 

Vulnerabilities

John Carlin, formerly the assistant attorney general for national security in the DOJ’s national security division and chair of Morrison & Foester's global risk and crisis management group, says of the findings: 'The survey bears out what I have heard repeatedly in my private practice and in my prior time in government: Few companies consider themselves well prepared for a crisis, and even many companies that have a response plan in place either lack key components in their plan or do not test those plans frequently enough to be confident they would work. Keys to effective crisis planning include being clear-eyed about vulnerabilities, regularly taking account of new developments in the field, and applying lessons learned from other companies’ experiences.  In addition, a plan must be routinely updated and tested so the muscle memory is there and can be counted on when needed.'

Cybersecurity oversight by the board

Co-chair Miriam Wugmeister Wugmeister added: 'Today, data protection issues affect nearly every company, and with the overwhelming digitisation and globalisation of business, legal and IT departments must contend with a web of complex regulatory requirements and heightened enforcement, making compliance more important than ever. Cybersecurity oversight has also moved to the boardroom, where directors are expected to be accountable for cyber matters, but, we discovered, are often not briefed on these issues regularly enough.  With high-profile data security incidents constantly in the news, including a wave of recent global ransomware attacks, regular board reporting is a key component of an organisation’s readiness plan.'

Research

The survey of 200 corporate counsel was carried out by Morrison & Foester and American Lawyer.

Email your news and story ideas to: [email protected]

The Global Legal Post

© 2026 The Global Legal Post. All Rights Reserved

Top