Sullivan & Cromwell LLP Logo
  • Home
  • Lawyers
  • Practices
  • Insights
  • About
  • Careers
  • Alumni
  • Twitter icon
  • LinkedIn icon
  •  icon
  • Podcasts icon
© 2025 Sullivan & Cromwell LLP
    • Home
    • Lawyers
    • Practices
    • Insights
    • About
    • Careers
    • Alumni
    Home /  Practices /  Cybersecurity

    Cybersecurity

    Related Lawyers

    S&C’s Cybersecurity Group includes elite practitioners with deep government experience who have investigated and prosecuted cybercrimes and security threats and helped shape the field with award-winning and internationally recognized work. Our interdisciplinary approach, enhanced by our extensive government investigations practice, enables us to tailor cybersecurity strategies that integrate our array of governance, regulatory, technology, investigations, risk management and communications expertise.

    We regularly advise companies on cybersecurity preparedness, incident response, post-breach investigation, complex litigation, related corporate governance issues and data privacy matters, including U.S. and international   privacy laws. We act as outside cybersecurity counsel to a range of global corporations, including technology companies, financial institutions and manufacturers. We regularly advise on cutting-edge matters, including those involving national security, theft of confidential and proprietary information, unauthorized access to personal data, loss of funds and business disruption.

    “Proactive risk discussion is essential. In the event of a breach, regulators and private litigants will challenge boards about what they did ahead of time to assess and mitigate cybersecurity risk.”

    –Nicole Friedlander

    Co-head of S&C’s Cybersecurity Group

    Recognized by:

    Global Data Review’s GDR 100 2021

    U.S. News & World Report 2021 for Privacy & Data Security Law


    Read More

    Spotlight

    Six S&C Partners Named to Lawdragon’s ‘500 Leading Global Cyber Lawyers’ List for 2025

    Read More

    Nicky Friedlander and Tony Lewis Again Named to Cybersecurity Docket’s ‘Incident Response 50’

    Read More

    S&C Advises Symbotic in Acquisition of Walmart’s Advanced Systems and Robotics Business

    Read More

    S&C Sidebar – A Conversation with Jay Clayton and Nicky Friedlander

    Read More
    sc_sidebar_clayton_friedlander_368x159

    S&C Sidebar – A Conversation with Jay Clayton and Tony Lewis

    Read More
    sc_sidebar_clayton_lewis_368x159
    • Experience
    • Rankings and Recognitions
    • News
    • Publications, Videos and Podcasts
    • Practice Contacts
    • Related Lawyers
    Experience

    Experience

    Incident Response Experience

    • FTX chapter 11 debtors in responding to a breach resulting in unauthorized transfers of hundreds of millions of dollars’ worth of crypto assets on the date of FTX’s bankruptcy filing, coordinating complex efforts to identify and secure billions of dollars’ worth of crypto assets that remained at risk following the breach, investigating the breach, and cooperating in related law enforcement and regulatory investigations.
    • A multibillion-dollar public company experiencing a ransomware attack and data extortion (customer PII and financial information), including advising on communications with the Board of Directors and ransom negotiations, providing SEC disclosure advice, coordinating recovery and forensic review with outside experts, crafting and coordinating a communications plan with a PR firm, notifying over 50 thousand affected customers, assisting in responding to reporters, and coordinating insurance approvals.
    • A Fortune 500 public company experiencing a ransomware attack and data extortion (company IP and data), including advising on risks of payment and law enforcement notifications, providing SEC disclosure advice, and assisting with guidance on recovery and forensic review.

    • A Fortune 500, publicly-traded financial services firm acquiring a company that experienced a ransomware attack at signing. We advised on ransom negotiations, recovery, and forensic review in coordination with external forensics experts, and revisions to M&A agreements to allocate risk and cost, and require certain remedial measures. The deal successfully signed and closed.
    • Scottrade with respect to the exposure of unencrypted files containing customers’ personal data, including on state privacy law issues and nationwide customer notification.
    • Popular in responding to a criminal cyber breach of company systems, including on state privacy issues, nationwide customer notification, and coordinating with their prudential banking regulator.
    • A technology company in responding to the cyber theft of its source code and attempted extortion, including notification to millions of customers, coordination with law enforcement, and conducting an internal investigation.
    • A major, publicly-traded financial institution on responding to the data extortion of a vendor that, through the compromise, lost hundreds of thousands of bank customers’ sensitive personal data and voluminous SAR information. We provided SEC disclosure advice; assisted in drafting notice and updates to federal and state bank regulators and answering questions from the bank regulators; assisted in drafting notice and updates, and coordinating with, FinCEN regarding the loss of SAR data; drafted and coordinated notice to Attorneys General in many states; crafted and coordinated a communications plan with no assistance from a PR firm; notified over 400,000 bank customers; arranged for call centers and credit monitoring for customers; assisted in crafting call center and website communications; and assisted in coordinating with insurers and the affected vendor.
    • A public company regarding a potential breach of its network by a hostile nation-state, including coordinating with federal law enforcement and intelligence agencies.
    • Numerous companies and individuals victimized in cyber-fraud and phishing schemes, including coordination with federal and international law enforcement and of overseas litigation resulting in substantial recoveries for our clients. We have secured substantial and complete recoveries for clients, and recovered millions of dollars on numerous occasions. In one instance, as a result of our work, our client recovered almost the entirety of more than $20 million diverted by cybercriminals to Hong Kong.
    • More than a dozen public companies in responding to SEC requests concerning the SolarWinds breach and related matters.
    • A retailer in connection with a cybersecurity breach at its third-party e-commerce platform.
    • A retailer regarding an ongoing breach of customer credit card information.

    Preparedness, Data Privacy and Cyber Advisory Experience

    • Regional, national and international financial institutions, and public and private corporations across industries on cyber governance responsibilities, including advice to boards of directors and senior management on incident response planning, disclosure controls and procedures, director duties related to cybersecurity risks, and the coordination and implementation of cybersecurity “tabletop exercises.”
    • Numerous public companies and financial institutions on potential sanctions risks associated with paying ransom in connection with ransomware attacks.
    • Several major financial institutions on the legality and legal risks associated with particular transfers they are asked to make for customers to facilitate the purchase of cryptocurrency to pay ransom. We advise on OFAC and FinCEN requirements (including MSB and SAR-filing issues).
    • The Bank Policy Institute, a consortium of the nation’s leading banks, on the legal and regulatory implications of paying or facilitating the payment of ransom in response to ransomware attacks.
    • The Bank Policy Institute, SIFMA, the American Bankers’ Association and the International Bankers’ Association in drafting a comment letter, on behalf of hundreds of financial institutions, regarding the notice of proposed rulemaking by the federal bank regulators concerning computer security incident notification requirements.
    • Drafting amicus briefs for the U.S. Chamber of Commerce on behalf of Marriott in the Fourth Circuit and Alphabet in the U.S. Supreme Court concerning disclosures required by public companies regarding cybersecurity risks.
    • A major real estate company and commercial landlord on the legal and regulatory implications of the installation of thermometer readers in commercial lobbies across multiple states in response to COVID-19. S&C is also advising this client on CCPA compliance and the use of biometric data in connection with this matter.
    • A multinational mining, metals and petroleum company on privacy matters in connection with its investment in a company engaged in analyzing geolocation data.
    • Multiple companies on use of customer information for data analytics purposes, including whether certain uses would comply with federal and state privacy and other laws.

    Cybersecurity, Data Privacy and Class Action Litigation

    • Airbnb in obtaining a preliminary injunction preventing the City of New York from implementing a new ordinance intended to collect personal data about the users of short-term rental platforms, which Airbnb argues is invalid under the Fourth Amendment of the U.S. Constitution. This case has significant implications, not just for Airbnb, but potentially for any business concerned about protecting the privacy of its users.
    • A healthcare technology company whose computer system was hacked, and fraudulent health care benefit debit cards were issued as a result without necessary geographical, merchant or monetary restrictions. As a result, the client lost millions of dollars through fraudulent debit cards that were used like legitimate credit cards with virtually unlimited credit limits. We advised and represented the client in connection with successful settlement negotiations with its insurer despite numerous allegedly applicable policy exclusions.

    For additional details on S&C’s litigation experience, please visit our litigation practice page.

    Read More
    Rankings and Recognitions

    Rankings and Recognitions

    • Six S&C Partners Named to Lawdragon’s ‘500 Leading Global Cyber Lawyers’ List for 2025

      May 8, 2025
    • Nicky Friedlander and Tony Lewis Again Named to Cybersecurity Docket’s ‘Incident Response 50’

      April 23, 2025
    • S&C Named Finalist for New York Law Journal’s ‘Litigation Department of the Year’

      July 15, 2024
    • Nicky Friedlander and Tony Lewis Once Again Named to Cybersecurity Docket’s ‘Incident Response 50’ for 2024

      April 19, 2024
    • Nicky Friedlander and Tony Lewis Named to Cybersecurity Docket’s “Incident Response 50” for 2023

      April 21, 2023
    • Nicole Friedlander Recognized in Profiles in Diversity Journal’s 2022 “Women Worth Watching in Leadership”

      October 18, 2022
    Read More
    Read More
    News

    News

    • S&C Advises Symbotic in Acquisition of Walmart’s Advanced Systems and Robotics Business

      January 23, 2025
    • S&C Authors Influential Amicus Brief for U.S. Chamber of Commerce and Business Roundtable in SEC’s SolarWinds Case

      July 24, 2024
    • Sharon Nelles Discusses Corporate Litigation Outlook with Agenda

      February 2, 2023
    • Nader Mousavi Featured on HSU Untied Podcast

      January 11, 2023
    • Karen Seymour, Sharon Nelles, Sharon Cohen Levin, Steve Peikin, Nicole Friedlander and Colin Lloyd to Speak at SIFMA’s C&L Seminar

      March 20–23, 2022
    • Nicky Friedlander Speaks at PLI Event on Doing Business in and With China

      December 6, 2021
    Read More
    Read More
    Publications, Videos and Podcasts

    Publications, Videos and Podcasts

    • DOJ Limits Crypto Prosecutions and Disbands Prosecution Unit

      S&C Memos |  April 9, 2025
    • When Worlds Collide: EU Data Protection, Artificial Intelligence and Trade Secrets

      S&C Memos |  March 10, 2025
    • SEC Reports Historically Low Activity Levels for FY 2024

      S&C Memos |  November 26, 2024
    • S&C Sidebar – A Conversation with Jay Clayton and Nicky Friedlander

      Podcasts |  November 19, 2024
    • S&C Sidebar – A Conversation with Jay Clayton and Tony Lewis

      Podcasts |  November 8, 2024
    • Ryan Logan Authors Bloomberg Law Practical Guidance Article on EU-U.S. Data Privacy Framework Consumer Personal Data Privacy Policy

      Articles |  October 1, 2024
    Read More
    Read More
    Practice Contacts

    Practice Contacts

    Nicole Friedlander Headshot Photo
    Nicole Friedlander
    New York
    +1-212-558-4332
    Email
    vCard
    Anthony J. Lewis Headshot Photo
    Anthony J. Lewis
    Los Angeles
    +1-310-712-6615
    Email
    vCard
    Jared M. Fishman Headshot Photo
    Jared M. Fishman
    New York
    +1-212-558-1689
    Email
    vCard
    Read More
    Sullivan & Cromwell LLP Logo
    • Twitter icon
    • LinkedIn icon
    • RSS Feed icon
    • Podcasts icon
    • Home
    • Contact Us
    • Information Policy Relating to Cookies
    • Privacy Policy
    • California Privacy Policy
    • Website Notice
    • Attorney Advertising Notice
    © 2025 Sullivan & Cromwell LLP