The Defensibility Gap

Companies already spend heavily on GRC, Big Legal, and Big 4 assessments — yet still have no defense when things go wrong. Executives still can't answer three questions: What are we legally accountable for? Where are we exposed? What actions are required?

No Role-Based Accountability

Executives are liable under laws that are never translated into their specific responsibilities. No existing Risk Management, GRC, or Privacy tool maps legal obligations to individual roles, or operationalizes the legal tests used by courts that bring the massive fines post-event.

No Governance Gap Visibility

Leadership cannot see where governance obligations are unmet until after a breach or investigation. By then, the damage is done.

No Guided Remediation

Existing tools track compliance controls and tasks, but do not tell executives what actions they must take to satisfy duty-of-care requirements.

No Defensible Evidence Record

When scrutiny comes, companies cannot produce either record the law expects — proof the decision was reasonable, or proof the obligation was actually met. GRC logs activity; it cannot show judgment or verify implementation.

$21B+

in cyber, privacy & AI enforcement — addressed by Defensible Governance

$1.2B+

in fines tied to harm to minors — addressed by Minors Safety & Child Welfare

Why Now

Compliance activity alone no longer answers the question regulators are asking. Enforcement now turns on governance judgment, not audit activity.

New Laws & Regulatory Convergence

GDPR, EU AI Act, SEC Cyber Rules, NIS2, DORA, and 20+ state privacy laws now all require evidence of proportionate, reasonable decision-making — and proof the required measures were actually implemented, not just controls.

Personal Liability

Uber CSO criminally convicted. SolarWinds CISO personally named. Drizly CEO personally bound for 10 years. D&O insurance increasingly excludes coverage for "gross negligence." The protection leaders assume they have is narrower than it used to be.

Evidence Determines Outcomes

Marriott's fine was substantially reduced on appeal. Citi was fined $536M across two related enforcement actions. Documentation of judgment, not just the underlying incident, shaped both outcomes.

The standard has shifted.

From: "Did you comply?" → To: "Can you prove your leadership took reasonable care — and that the obligation was actually met?"

The Enforcement Evidence — Top 20

Company$ AmountPrimary TransgressionGovernance Failure Characterization
Google (Texas AG)$1.375BLocation tracking, biometric data collection, and Incognito-mode trackingUnreasonable practices; failure to safeguard users from foreseeable privacy harm; deceptive governance
Meta Platforms$3.5B–$4.1B+Illegal cross-border transfers; biometric collection; children's data misuse; transparency failuresSystemic governance failure; inadequate safeguards; unreasonable reliance on invalid transfer mechanisms
Amazon$877MGDPR violations in ad-tech and data processingFailure to implement appropriate technical & organizational measures (Art. 25, 32 GDPR) = Requires defining and applying risk-based thresholds to demonstrate the standard of reasonable and appropriate care
Equifax$575M–$700MFailure to patch known vulnerability; massive consumer data breachNegligence; failure to meet reasonable security standards; foreseeable harm ignored
Epic Games$520MCOPPA violations; dark patterns tied to data useFailure to protect children; unreasonable data and product governance
T-Mobile$500MRepeated breaches; inadequate access controlsFailure of reasonable security; governance breakdown despite prior warnings
Google (Incognito class action)$0 cash to class
plaintiffs valued noncash relief (data deletion, disclosure changes) at $5B–$7.8B; $217.6M in fees requested, Google argued for ≤$40M
Continued tracking users in Incognito/private-browsing modeCourt certified an injunctive-relief class only, no damages class; deceptive disclosure of tracking practices
Google (Web & App Activity jury verdict)$425.7MContinued data collection after users disabled Web & App Activity settingJury found unreasonable disregard of user-disabled privacy controls
Meta (Texas)$1.4B (incl. above)Facial recognition without consentPer-se statutory negligence; failure to govern biometric risk
TikTok (EU)$370MChildren's data mishandlingFailure to implement heightened safeguards for vulnerable populations
Citi (aggregate)$536MData breach controls; internal risk governance failuresFailure to secure financial data; inadequate internal controls = governance failure
Uber (EU)$324MUnlawful international data transfersUnreasonable safeguards; failure to assess transfer risk post-Schrems II
Home Depot$200M+Payment card breachFailure to segment networks and monitor foreseeable attack vectors
Capital One$190M+Cloud misconfiguration; access control failureFailure of reasonable cloud governance and risk assessment
Twitter / X$150MMisuse of security data for advertisingDeceptive governance; misuse of data entrusted for security purposes
Anthem$115MHealthcare data breachFailure to safeguard sensitive health data; foreseeable harm
Oracle$115MImproper data collection and saleInadequate data governance; unreasonable secondary use of personal data
Zoom$85MSecurity failures ('Zoombombing')Failure to design for reasonable security under foreseeable misuse
OPM$63MFederal employee data breachFailure to meet baseline government security standards
Plaid$58MExcessive data collection beyond consumer consentUnreasonable data minimization and access governance
Blackbaud$49.5MRansomware + misrepresentation of riskFailure to implement reasonable ransomware defenses; governance misstatements
Morgan Stanley$35MUnencrypted data disposalFailure of basic data lifecycle governance
See More Enforcement Actions

$21B+ in enforcement penaltiesIn every case, governance failure was the common factor — the exposure Defensible Governance is built to address.

Model Your Exposure