top of page


A Working Definition of “Reasonable Security” in Cybersecurity
“Reasonable security” is not a checklist or a dollar figure — it is a governance-driven, scalable approach to cybersecurity. This blog defines it through due care (board and executive attention to risks) and due diligence (verification, monitoring, and documentation). Drawing on negligence law, regulatory enforcement, and compliance principles, it offers boards a roadmap to achieve defensibility, accountability, and proportional safeguards.

Hector R. Lopez
Oct 16 min read
bottom of page