Proof — Documentation Determines Outcomes

Proactively documenting reasonable care is the opposite of negligence — and regulators treat it that way. When leadership can show it, fines are often substantially reduced; when they can't, enforcement is devastating even when charges are ultimately dismissed.

Marriott International

Fine substantially reduced

ICO initially proposed £99M. Reduced to £18.4M. Marriott had produced DPIAs, board minutes showing oversight, and alternatives-analysis documentation ahead of the incident.

Citi — $536M in Repeat Fines

No provable rationale

$400M (2020) + $136M (2024). Regulators found a documentation gap — leadership could not produce evidence of why key risks were accepted, delayed, or sequenced. COO replaced. Trust eroded.

SolarWinds — Winning Is Not a Strategy

$46M+ even after dismissal

SEC dismissed all charges Nov 2025. But the cost: $26M settlement, $20M+ legal, CISO personally named, 400 engineers off roadmap for 6 months, renewals dropped from 98% to 80%.

Tim Brown has described, in interviews and speaking appearances since the case, thousands of internal emails reviewed during the investigation — only a handful flagged the risk, and none preserved the rationale for the decisions made.

We don't have validated reduction-percentage amounts, because almost no company is aware of, let alone following, the due-care principles regulators and courts actually apply.

We know Marriott's proposed fine was substantially reduced because they could show reasonable, documented care before anything went wrong — and there are a few other cases that saw reductions.

The other side of the ledger is far larger — and unanimous. Across the biggest enforcement outcomes of recent years — more than 100 actions, the largest reaching into the billions — every one centered on a governance-judgment failure: unreasonable or inadequate measures, disregard for foreseeable harm, or missing documentation — not the breach alone. The 25 largest exceed $14 billion combined.

Defensibility Dossier™ — The Consolidated Evidentiary Record

Defensibility Dossier — Immutable Governance Record

The consolidated governance record: risk assessments, cost-benefit analyses, board-level findings, and executive approval decisions — and the implementation-evidence record proving each committed obligation was actually met and verified — exportable to Word, ready for regulators.

See Full Defensibility Dossier

Tim Brown, CISO — SolarWinds

"I've seen how executive decisions can come under intense scrutiny, even when they're made responsibly. Defensible Governance addresses a critical need: helping leaders show the reasonableness of their actions before they're judged in hindsight."

Rich Mason, Former CSO & CISO — Honeywell

"Too many CISOs, boards, and executives still believe that compliance checkboxes and 'best effort' will shield them from liability. The reality is different. Prosecutors and regulators systematically reconstruct whether leadership met a reasonable duty of care. Defensible Governance™ is the framework that shifts the balance. This is no longer optional — it's necessary body armor for managing cyber legal risk."

Defensible Governance™ is built to create this evidence before scrutiny arrives.

Articles

The Psychological-Welfare Mandate for Gaming, Social Media & EdTech

Two kinds of law now govern minors — and almost everyone is watching only one. A newer body of psychological-welfare law regulates product design itself: feed defaults, curfew hours, dark patterns, and addictive engagement loops. Ten binding regimes, $1.2B+ in fines, and the shift from "did you comply?" to "can you show your leadership weighed the foreseeable harm to a child before it reached them?"

Read Article

Judged Like an Executive, Equipped Like a Technician

CISOs are treated like technical operators before a breach — and held accountable like executives after one. The survey data on personal liability, why GRC doesn't save you, and why a contemporaneous, sealed decision record — not better insurance — is what actually protects an executive under scrutiny.

Read Article

The Threshold Nobody Set: Why Legal Defensibility Requires Infrastructure

A better operating model still doesn't create legal evidence. Why the threshold decision the law now requires — the Calculated Definition of Acceptable Risk — can't be improvised in a conference room, and needs infrastructure that applies the legal test and seals the rationale before the incident, not reconstructed after.

Read Article

The Social Media Liability Verdict: Big Tech's "Big Tobacco" Moment

A Los Angeles jury found Meta and Google liable in a landmark social-media addiction case. The deeper signal isn't the damages — it's the shift from privacy compliance to design accountability, where the question becomes whether leadership can prove it identified foreseeable harms to minors, weighed safer alternatives, and documented proportionate decisions before the harm occurred.

Read Article