A cross-border business holds customer data, vendor credentials, and contract obligations in several jurisdictions at once. When a breach, vendor failure, or regulator letter arrives, the legal exposure is rarely one problem — it is a contract dispute, a notification duty, and an insurance question landing on the same week. Our cyber practice focuses on that intersection: the commercial and cross-border legal consequences of data-security events.
What We Handle
Breach-related commercial disputes
When a vendor, SaaS provider, or counterparty’s security failure causes loss, the fight usually turns on the contract: indemnification scope, limitation-of-liability clauses, the definition of “reasonable security,” and who bears notification costs. We prosecute and defend these disputes in court and in arbitration, including where the counterparty is abroad and enforcement will cross borders. See our cross-border disputes practice.
Cyber-insurance coverage issues
Cyber policies are dense, and coverage often turns on notice timing, application accuracy, and exclusions for acts of war or system maintenance. We review policies before an incident and handle coverage disputes arising from cyber events, alongside our broader insurance practice.
Data-security terms in international transactions
Most data risk is allocated long before an incident — in data-processing agreements, security addenda, audit rights, and cross-border transfer terms such as the EU standard contractual clauses. We negotiate these provisions in supply, licensing, and services agreements so that the paper matches the actual data flows. Related: international licensing agreements.
Breach-notification obligations
Florida’s Information Protection Act, Fla. Stat. § 501.171, generally requires notice to affected Florida residents within 30 days of determining that a breach has occurred, with limited extensions — and other states impose their own timelines and content requirements. For businesses with customers in multiple states or countries, we help determine which laws apply and coordinate compliant notice. Statutory framework current as of August 2026.
International dimensions
A U.S. business selling into Europe can face GDPR exposure under that regulation’s territorial-scope rules even without an EU office. Cyber disputes also raise cross-border evidence questions — including Section 1782 discovery in aid of proceedings before foreign courts and governmental or intergovernmental tribunals — though after the Supreme Court’s ZF Automotive decision, Section 1782 does not ordinarily reach private commercial arbitrations — and enforcement of judgments across borders. Our international litigation practice handles these procedural layers.
What We Do Not Do
We are not a digital-forensics or incident-response vendor, and we do not investigate intrusions ourselves. In an active incident we work alongside your technical responders and, where appropriate, engage forensic experts through counsel — a structure that can support privilege or work-product protection depending on purpose, facts, and jurisdiction, though it does not guarantee it. Criminal cyber matters are handled only within the scope of our white-collar practice or referred to specialist defense counsel.
How an Engagement Starts
Most cyber engagements begin one of two ways: a contract-and-policy review before anything goes wrong, or a dispute assessment after something has. Either way, the first step is a conflicts check and a defined scope with clear pricing — see our retainer and payment options, then contact our office.
Legal landscape described as of August 26, 2026.