In recent years, Congress has become increasingly focused on private sector cybersecurity practices as a matter of public concern and national security, particularly as the cybersecurity threat landscape continues to evolve rapidly.  Lawmakers on both sides of the aisle have demonstrated sustained interest in whether companies appropriately collect, safeguard, and respond to compromises of sensitive data and protect critical systems, and cybersecurity is likely to remain a congressional priority regardless of which party controls Congress after the midterm elections.

This means that a cybersecurity incident may lead to scrutiny from Congress in addition to regulators, shareholders, and other stakeholders, such as consumers and customers.  In this alert, we explain how cybersecurity incidents can attract congressional scrutiny, the distinct risks that arise when a cybersecurity incident draws congressional attention, and emerging areas of congressional focus that may increase scrutiny of corporate cybersecurity practices.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Robert Kelner Robert Kelner

Robert Kelner is the chair of Covington’s nationally recognized Election and Political Law Practice Group.  He counsels clients on the full range of political law compliance matters, and defends clients in civil and criminal law enforcement investigations concerning political activity. He also leads…

Robert Kelner is the chair of Covington’s nationally recognized Election and Political Law Practice Group.  He counsels clients on the full range of political law compliance matters, and defends clients in civil and criminal law enforcement investigations concerning political activity. He also leads the firm’s prominent congressional investigations practice.

Rob’s political law compliance practice covers federal and state campaign finance, lobbying disclosure, pay to play, and government ethics laws. His expertise includes the Federal Election Campaign Act, Lobbying Disclosure Act, Ethics in Government Act, Foreign Agents Registration Act, and Foreign Corrupt Practices Act.

He is also a leading authority on the arcane rules governing political contributions and marketing activities by registered investment advisers and municipal securities dealers.

Rob’s political law clients include numerous multinational corporations, many of which are household names.  He counsels major banks, hedge funds, private equity funds, trade associations, PACs, political party committees, candidates, lobbying firms, and politically active high-net-worth individuals. He has represented the Republican National Committee, National Republican Congressional Committee, and National Republican Senatorial Committee.  He also advises Presidential political appointees on the complex vetting and confirmation process.

As a partner in the firm’s White Collar Defense & Investigations practice group, Rob regularly defends clients in congressional investigations before virtually every major congressional investigation committee.  He also defends corporations and others in investigations by the Federal Election Commission, the Public Integrity Section of the U.S. Department of Justice, federal Offices of Inspector General, and the House & Senate Ethics Committees.  He has prepared many CEOs and corporate executives for testimony before congressional investigation panels. He regularly leads the Practicing Law Institute’s training program on congressional investigations for in-house lawyers.  In addition, he is frequently retained to lead internal investigations and compliance reviews for major corporate clients concerning lobbying and campaign finance law issues.

Rob has appeared as a commentator on political law matters on The PBS News Hour, CNBC, Fox News, and NPR, and he has been quoted in the New York Times, Washington Post, Wall Street Journal, Associated Press, Legal Times, Roll Call, The Hill, Politico, USA Today, Financial Times, and other publications.

Rob is Chairman of Covington’s Professional Responsibility Committee and a General Counsel of the firm.  He also currently serves as Chairman of the District of Columbia Bar’s Legislative Practice Committee, and he previously was appointed by the President of the American Bar Association to serve on the ABA’s Standing Committee on Election Law.

Photo of Ashden Fein Ashden Fein

Ashden Fein is co-chair of Covington’s Data Privacy and Cybersecurity Practice. He advises clients on cybersecurity and national security matters, including crisis management and incident response, risk management and governance, government and internal investigations, and regulatory compliance. Ashden also serves as lead counsel…

Ashden Fein is co-chair of Covington’s Data Privacy and Cybersecurity Practice. He advises clients on cybersecurity and national security matters, including crisis management and incident response, risk management and governance, government and internal investigations, and regulatory compliance. Ashden also serves as lead counsel in criminal, civil, and internal investigations involving cybersecurity, insider risk, and U.S. national security issues.

Ashden regularly counsels clients on preparing for and responding to cyber-based attacks, assessing security controls and practices for the protection of data and systems, developing and implementing cybersecurity risk management and governance programs, and complying with federal and state regulatory requirements. Ashden frequently supports clients as the lead investigator and crisis manager for global cyber and data security incidents, including data breaches involving personal data, advanced persistent threats targeting intellectual property across industries, state-sponsored theft of sensitive U.S. government information, extortion and ransomware, and destructive attacks.

Ashden also assists clients from across industries with leading internal investigations and responding to government inquiries related to U.S. national security and insider risks. He frequently represents government contractors in False Claims Act matters involving cybersecurity and national security. Additionally, he advises aerospace, defense, and intelligence contractors on security compliance under U.S. national security laws and regulations including, among others, the National Industrial Security Program (NISPOM), U.S. government cybersecurity regulations, FedRAMP, and requirements related to supply chain security.

Before joining Covington, Ashden served on active duty in the U.S. Army as a Military Intelligence officer and prosecutor specializing in cybercrime and national security investigations and prosecutions — to include serving as the lead trial lawyer in the prosecution of Private Chelsea (Bradley) Manning for the unlawful disclosure of classified information to Wikileaks. Ashden is a retired U.S. Army officer.

Photo of Caleb Skeath Caleb Skeath

Caleb Skeath helps companies manage their most complex and high‑stakes cybersecurity and data security challenges, combining deep regulatory insight, technical fluency, and practical judgment informed by leading incident response matters.

Caleb Skeath advises in‑house legal and security teams on the full lifecycle of…

Caleb Skeath helps companies manage their most complex and high‑stakes cybersecurity and data security challenges, combining deep regulatory insight, technical fluency, and practical judgment informed by leading incident response matters.

Caleb Skeath advises in‑house legal and security teams on the full lifecycle of cybersecurity and privacy risk—from governance and preparedness through incident response, regulatory engagement, and follow‑on litigation. A Certified Information Systems Security Professional (CISSP), he is trusted by clients across highly regulated and technology‑driven sectors to provide clear, practical guidance at moments when legal judgment, technical understanding, and business realities must be aligned.

Caleb has deep experience leading and overseeing responses to complex cybersecurity incidents, including ransomware, data theft and extortion, business email compromise, advanced persistent threats and state-sponsored threat actors, insider threats, and inadvertent data loss. He regularly helps in‑house counsel structure and manage investigations under attorney‑client privilege; coordinate with internal IT, information security, and executive stakeholders; and engage with forensic firms, crisis communications providers, insurers, and law enforcement. A central focus of his practice is advising on notification obligations and strategy, including the application of U.S. federal and state data breach notification laws and requirements along with contractual notification obligations, and helping companies make defensible, risk‑informed decisions about timing, scope, and messaging.

In addition to his work responding to cybersecurity incidents, Caleb works closely with clients’ legal, technical, and compliance teams on cybersecurity governance, regulatory compliance, and pre‑incident planning. He has extensive experience drafting and reviewing cybersecurity policies, incident response plans, and vendor contract provisions; supervising cybersecurity assessments under privilege; and advising on training and tabletop exercises designed to prepare organizations for real‑world incidents. His work frequently involves translating evolving regulatory expectations into actionable guidance for in‑house counsel, including in highly-regulated sectors such as the financial sector (including compliance with NYDFS cybersecurity regulations, the Computer Security Incident Notification Rule, and GLBA guidelines and guidance) and the pharmaceutical and healthcare sector (including compliance with GxP standards, FDA medical device guidance, and HIPAA).

Caleb’s practice also addresses evolving and emerging areas of cybersecurity and data security law, including advising clients on compliance with the Department of Justice’s Data Security Program, CISA‑related security requirements for restricted transactions, and preparation for new regulatory regimes such as the CCPA cybersecurity audit requirements and federal incident reporting obligations. He regularly counsels clients on how artificial intelligence and connected devices intersect with cybersecurity, privacy, and consumer protection risk, and how to support innovation while managing regulatory exposure.

Caleb also has extensive experience helping clients navigate high-stakes cybersecurity-related inquiries from the Federal Trade Commission, state Attorneys General, and other sector-specific regulators, including incident-specific inquiries as well as broader inquiries related to an entity’s cybersecurity practices and the security of product or service offerings. For companies that have entered into cybersecurity-related settlement agreements with regulators, Caleb has helped guide them through compliance with settlement agreement obligations, including navigating required third-party assessments and strategically responding to cybersecurity incidents that can arise while a company is subject to a settlement agreement. Caleb also routinely works hand-in-hand with colleagues in Covington’s class action litigation, commercial litigation, and insurance recovery practices to prepare for and successfully navigate incident-related disputes that can devolve into litigation.

Photo of Susan B. Cassidy Susan B. Cassidy

Susan Cassidy co-chairs Covington’s Aerospace and Defense Industry Group, and has been advising government contractors for more than 35 years on the requirements imposed on companies contracting with the U.S. Government. She is Chambers ranked in both Government Contracts – Cybersecurity (Band 1)…

Susan Cassidy co-chairs Covington’s Aerospace and Defense Industry Group, and has been advising government contractors for more than 35 years on the requirements imposed on companies contracting with the U.S. Government. She is Chambers ranked in both Government Contracts – Cybersecurity (Band 1) and Government Contracts (Band 2).

Susan’s practice focuses on the intersection of cybersecurity, national security, and supply chain risk management for companies that sell products and services to the U.S. Government. Susan advises contractors at all phases of the procurement cycle, and regularly:

advises clients on compliance obligations imposed by the FAR, DFARS, and other agency regulatory requirements;
leads internal and government False Claims Act (FCA) investigations addressing allegations of violations of government cybersecurity, national security, supply chain, quality, and MIL-SPEC requirements; and
advises clients who have suffered a cyber breach where U.S. government information may have been impacted.

In her work with global, national, and start-up contractors, Susan advises companies on all aspects of government supply chain issues including:

Government cybersecurity requirements, including the Cybersecurity Maturity Model Certification (CMMC), DFARS 252.204-7012, FedRAMP, controlled unclassified information (CUI), and NIST SP 800-171 requirements;
Evolving sourcing issues such as Section 889, counterfeit part requirements, Section 5949 semiconductor product and service restrictions, and limitations on sourcing a variety of products from China; and
Federal Acquisition Security Council (FASC) regulations and product exclusions.

Susan previously served as senior in-house counsel for two major defense contractors (Northrop Grumman Corporation and Motorola Incorporated). Chambers USA has quoted sources stating that “Susan’s in-house experience coupled with her deep understanding of the regulatory requirements is the perfect balance to navigate legal and commercial matters.”

Susan is a former Public Contract Law Procurement Division Co-Chair, former Co-Chair and current Vice-Chair of the ABA PCL Cybersecurity, Privacy and Emerging Technology Committee.

Susan’s pro-bono work extends to assisting veterans in a variety of matters, as well as providing advice to elderly clients on their wills and other end-of-life planning documents.

Photo of Angelle Smith Baugh Angelle Smith Baugh

Angelle Smith Baugh is of counsel in the firm’s Election and Political Law and White Collar Litigation practice groups. She has significant experience in broad-based crisis management, advising clients on legal and political matters presenting complex risks. She has been individually ranked by…

Angelle Smith Baugh is of counsel in the firm’s Election and Political Law and White Collar Litigation practice groups. She has significant experience in broad-based crisis management, advising clients on legal and political matters presenting complex risks. She has been individually ranked by Chambers for Congressional Investigations for three consecutive years, with clients describing her as “…incredibly responsive, thorough and has great expertise in congressional investigations.”

Angelle’s practice focuses on defending companies and individuals in high-profile congressional investigations, as well as other criminal, civil, and internal investigations. She represents clients before House and Senate Committees, as well as in criminal and civil government investigations before the Public Integrity Section of the Department of Justice, Federal Election Commission, and the Office of Congressional Ethics.

She assists companies and executives responding to formal and informal inquiries from Congress and executive branch agencies for documents, information, and testimony. She has experience preparing CEOs and other senior executives to testify before challenging congressional oversight hearings.

Angelle also has experience and expertise navigating federal and state ethics laws, and provides ongoing political law advice to companies, trade associations, PACs, and individuals.

Photo of Nicholas Xenakis Nicholas Xenakis

Nick Xenakis draws on his Capitol Hill and legal experience to provide public policy and crisis management counsel to clients in a range of industries.

Nick assists clients in developing and implementing policy solutions to litigation and regulatory matters, including on issues involving…

Nick Xenakis draws on his Capitol Hill and legal experience to provide public policy and crisis management counsel to clients in a range of industries.

Nick assists clients in developing and implementing policy solutions to litigation and regulatory matters, including on issues involving antitrust, artificial intelligence, bankruptcy, criminal justice, financial services, immigration, intellectual property, life sciences, national security, and technology. He also represents companies and individuals in investigations before U.S. Senate and House Committees.

Nick previously served as General Counsel for the U.S. Senate Judiciary Committee, where he managed committee staff and directed legislative efforts. He also participated in key judicial and Cabinet confirmations, including of Attorneys General and Supreme Court Justices. Before his time on Capitol Hill, Nick served as an attorney with the Federal Public Defender’s Office for the Eastern District of Virginia.

Photo of Perrin Cooke Perrin Cooke

Perrin Cooke is special counsel in the firm’s Washington, DC office and a member of the White Collar Defense and Investigations, Election and Political Law, and Public Policy Practice Groups, with a focus on assisting clients responding to high-profile congressional investigations.

Drawing on…

Perrin Cooke is special counsel in the firm’s Washington, DC office and a member of the White Collar Defense and Investigations, Election and Political Law, and Public Policy Practice Groups, with a focus on assisting clients responding to high-profile congressional investigations.

Drawing on his experience in government, most recently as Deputy General Counsel at the U.S. Department of Health and Human Services, Perrin advises clients on matters presenting significant legal, political, and reputational risks. During the Biden Administration, Perrin served as the lead attorney on oversight matters across two federal agencies. In this capacity, he guided the development of strategic responses to congressional requests and subpoenas touching on a range of topics. Through his work in both government and private practice, Perrin has extensive experience preparing witnesses – including numerous corporate executives, cabinet secretaries, and other senior government officials – appearing in briefings, transcribed interviews, and hearings before congressional oversight committees.

In addition to his investigations practice, Perrin advises clients – including political campaigns, advocacy organizations, trade associations, and corporations – on a wide variety of election and political law compliance matters.

Photo of Ali Cooper-Ponte Ali Cooper-Ponte

Ali Cooper-Ponte draws on her experience at the U.S. Department of Justice to advise clients on complex and sensitive national security, cybersecurity, and online safety matters across regulatory, investigations, enforcement, and litigation contexts.

In her investigations and litigation practice, Ali guides clients through…

Ali Cooper-Ponte draws on her experience at the U.S. Department of Justice to advise clients on complex and sensitive national security, cybersecurity, and online safety matters across regulatory, investigations, enforcement, and litigation contexts.

In her investigations and litigation practice, Ali guides clients through both internal and government investigations. She helps clients across industries navigate significant enterprise risks, including insider, criminal, and advanced persistent or nation-state threats, as well as challenges relating to emerging technologies. She has also helped clients proactively engage with or respond to inquiries by the U.S. Department of Justice, state Attorneys General, and the Federal Trade Commission.

In her advisory practice, Ali helps clients strategically manage rapidly-changing regulatory and technological landscapes. She counsels clients on compliance with national security, cybersecurity, data privacy, content moderation, and child exploitation laws. She has particular expertise on issues relating to government access to data, including the Electronic Communications Privacy Act and the Foreign Intelligence Surveillance Act and the Fourth Amendment. She also has significant experience with new Federal and state laws implicating Section 230 of the Communications Decency Act and the First Amendment. Here, her experience spans industries (including the technology, healthcare, cryptocurrency and financial services, and aerospace and defense industries) and includes providing practical advice on new legislation, regulatory frameworks, and court rulings as well as developing legislative proposals and potential challenges to new legislation and government action.

Previously, Ali served in the U.S. Department of Justice as Senior Counsel in the Office of the Assistant Attorney General for the Criminal Division, where she focused on the cyber and child exploitation portfolios, and as a Trial Attorney in the National Security Division’s National Security Cyber Section and the Criminal Division’s Computer Crime and Intellectual Property Section. She joined the Justice Department as part of its inaugural class of Cyber Fellows, which gave her broad exposure to the Department’s work to address cyber and cyber-enabled threats.

Earlier in her career, Ali clerked for Judge José A. Cabranes on the U.S. Court of Appeals for the Second Circuit. Prior to law school, Ali worked as a legal investigations specialist focused on electronic surveillance and law enforcement access issues at a large technology company.

In addition to her regular practice, Ali leverages her experience to counsel pro bono clients engaged in work to protect children and civil liberties.

Photo of Stephanie Nnadi Stephanie Nnadi

Stephanie Nnadi is an associate in the Congressional Investigations, Election and Political Law, and White Collar Defense and Investigations Practice Groups. Stephanie represents clients responding to or preparing for high-profile investigations and hearings before Congress and federal agencies, particularly in matters involving significant…

Stephanie Nnadi is an associate in the Congressional Investigations, Election and Political Law, and White Collar Defense and Investigations Practice Groups. Stephanie represents clients responding to or preparing for high-profile investigations and hearings before Congress and federal agencies, particularly in matters involving significant legal, political, and reputational risks. Stephanie also regularly assists clients in compliance with federal and state campaign finance, election, and lobbying laws. Additionally, Stephanie maintains an active pro bono practice focused on civil and human rights and government transparency.