D&O Liability for Known Technology Risk

ModernLift · ·9 min read

Directors-and-officers liability for technology risk turns on what leadership knew and failed to act on. Under the Delaware Caremark line of cases, directors owe a duty of oversight — and after Marchand v. Barnhill (2019) and the Boeing 737 MAX derivative ruling (2021), courts have been more willing to let oversight claims survive a motion to dismiss when the failure involves a mission-critical risk the board ignored. A known, unpatchable legacy system in a critical path is exactly the kind of risk that is hard to characterize as a surprise. This page is educational, not legal advice. We retire the underlying exposure slice by slice, with an audit trail that demonstrates due care.

There is a difference, in the eyes of a court, between a risk that surprised you and a risk you watched develop. The first is misfortune. The second is a decision. Directors-and-officers exposure for technology risk lives almost entirely in that second category — not in the existence of an aging system, but in what leadership knew about it and chose not to do.

This page is educational, not legal advice; the liability judgment belongs to your counsel. What we can do is describe the doctrine plainly and connect it to the systems we actually work on, because the exposure that worries boards most is grounded in the one thing technology leaders can see clearly — the system everyone already knew was a problem.

The doctrine: a duty to oversee, not to be perfect

The relevant standard comes from Delaware’s Caremark line of cases. In re Caremark (1996) established that directors owe a duty of oversight — a duty to make a good-faith effort to implement a system for monitoring and reporting on the corporation’s central risks, and not to consciously ignore what that system surfaces. For years the claim was considered one of the hardest in corporate law to win, precisely because it requires showing bad faith or conscious disregard, not ordinary negligence. A board that tries and fails is generally protected; a board that doesn’t try, or that looks away from a known problem, is not.

Two decisions shifted the landscape. In Marchand v. Barnhill (2019), the Delaware Supreme Court revived a Caremark claim against the board of an ice-cream company after a listeria outbreak, holding that the directors had made no good-faith effort to oversee food safety — a risk “essential and mission critical” to the business. In the Boeing 737 MAX derivative litigation (Court of Chancery, 2021), the court allowed an oversight claim against Boeing’s directors to proceed, finding the stockholders had adequately pleaded that the board failed to monitor airplane safety, again a mission-critical risk. Together, these cases meaningfully lowered the practical barrier for oversight claims to survive a motion to dismiss — the stage where most such claims used to die.

Courts and commentators have since extended the same reasoning to cybersecurity and technology risk. The logic is straightforward: if a system is mission-critical, the board’s duty to oversee it is real, and a documented, ignored failure is exactly the kind of red flag the doctrine is about. And in In re McDonald’s Corporation Stockholder Derivative Litigation (2023), the Court of Chancery held for the first time that the duty of oversight applies to officers as well as directors — pulling the executives who own the systems directly into the frame.

For a board or general counsel, the through-line of the doctrine sits in a short line of Delaware decisions. The table below is a plain reference to what each is known for, not a prediction of how any of them would apply to your facts.

CaseYearWhat it established (general information)
In re Caremark1996Delaware first recognized a director duty of oversight, meaning a good-faith effort to put monitoring and reporting in place and not to ignore what it surfaces.
Stone v. Ritter2006The Delaware Supreme Court adopted the Caremark standard and grounded it in the duty of good faith, setting the conscious-disregard bar.
Marchand v. Barnhill2019An oversight claim was revived where a board made no good-faith effort to monitor a mission-critical safety risk.
In re Boeing 737 MAX2021The Court of Chancery let an oversight claim proceed over the board’s monitoring of airplane safety, again a mission-critical risk.
In re McDonald’s2023The court held for the first time that the oversight duty reaches officers, scoped to each officer’s area of responsibility.

Where a legacy system turns into D&O exposure

The throughline of every one of these cases is knowledge. Liability attaches not to the bad outcome alone but to the board’s relationship with a known risk. That is what makes legacy systems a particular concern:

  • The risk is documented. Audit findings, risk registers, penetration-test reports, and insurer letters create a written record that the organization knew a system was unsupported or unpatchable. “We didn’t realize” gets much harder to say when the finding is in last year’s board deck.
  • The failure is foreseeable. A preventable breach on a platform the vendor abandoned is hard to frame as a surprise. Foreseeability is the hinge between misfortune and a decision.
  • The system is mission-critical. Marchand and Boeing both turned on the centrality of the risk. A legacy system in a payment, safety, or core-operations path is, almost by definition, the kind of thing the board is expected to oversee.
  • The red flag was raised and not addressed. Conscious disregard is the heart of a Caremark claim. A risk surfaced repeatedly and left in place for budget reasons is the fact pattern plaintiffs look for.

None of this means an old system creates personal liability on its own — it doesn’t, and we won’t pretend otherwise. The bar remains high. But the trajectory is unmistakable: the gap between known and addressed is where the exposure lives, and it widens every cycle a flagged system stays in the critical path.

The second vector: disclosure

Oversight is one duty. Disclosure is another, and for a public company the two compound. Where the oversight question is whether the board acted on a known risk, the disclosure question is whether the company told investors and regulators about it accurately and on time.

The SEC’s cybersecurity disclosure rules, adopted in 2023, sharpened this. A registrant must report a material cybersecurity incident on Form 8-K within four business days of determining it is material, and must describe its cybersecurity risk management, strategy, and governance each year in its annual report. A known, unremediated legacy system that later fails can therefore raise a second question alongside “did the board oversee it,” which is whether the risk and any resulting incident were disclosed as the rules require. The same documented red flag that supports an oversight claim can also anchor a claim that a disclosure was misleading by omission. Materiality is a fact-specific judgment for counsel, and this remains general information, not securities-law advice.

What discharging the oversight duty looks like

The governance response is not ours to run, but the pattern is well understood, and it is worth naming because it is the line between a defensible record and a liability. A board discharges the oversight duty by being able to show it saw the risk, weighed it, and acted. In practice that record has a few recurring parts:

  • A live risk register. The mission-critical systems and their known failure modes are written down, owned, dated, and kept current, not carried in one person’s head.
  • A reporting line to the board. Technology and security risk reaches the full board or a named committee on a regular cadence, with the material items escalated rather than buried in an appendix.
  • Minuted decisions. When a flagged risk is accepted, deferred, or funded, the reasoning and the decision go into the minutes. Conscious disregard is hard to allege against a board that visibly considered the risk.
  • A funded remediation plan. A red flag met with a budget, a sequence, and a date reads very differently from one met with silence. The plan does not have to be finished. It has to be real and moving.
  • Evidence the plan is executing. A plan that lives only on a slide is fragile. A validated record of changes actually shipped is what turns intent into due care.
  • Accurate disclosure. Where the company reports to investors or regulators, the known risk and any incident are disclosed on the standard the law sets, on time.

The first four and the last belong to leadership and counsel. The one we can put beyond dispute is the fifth, evidence that the remediation is real and executing.

How we help retire the underlying exposure

D&O exposure for technology risk is, at bottom, a governance problem with a technical root. The governance response — board oversight, documented decisions, a funded plan — belongs to leadership and counsel. The technical response is ours: actually closing the gap that the record says you knew about, and producing evidence that you did.

We treat a flagged legacy system the same way we treat any modernization — a sequence of small, reversible steps, not a single risky cutover. A strangler facade sits in front of the system so the legacy path and the modernized path run side by side. We move the highest-risk slice first, and before any slice carries live traffic, we prove it behaves identically to the legacy — same results, same state, reconciled record by record. AI-accelerated discovery reads the application, data, and integration surface end to end and captures what the system actually does, including the undocumented logic, under senior-engineer review. Traffic shifts only on green, rollback stays a flag away, and the legacy system stays in the critical path only until nothing depends on it.

The output that matters to a board is the audit trail: a documented, validated sequence of changes that shows the known risk was met with a deliberate, evidenced remediation rather than left to chance. That record is what lets leadership demonstrate due care — the opposite of conscious disregard.

We’re not your counsel

This is not legal advice, and we are not your counsel. Caremark claims remain difficult to win, and most aging systems will never be the subject of one. An old platform outside any mission-critical path, with no documented red flags against it, may be a maintenance matter rather than a fiduciary one — and we’ll say so rather than escalate every legacy system to a boardroom emergency. What we can do honestly is map the technical facts your counsel reasons from and retire the exposure that genuinely warrants it. The decision to modernize for governance reasons is yours to make; we make sure the work, once decided, is real and provable.

Where to start

The first step is to know which systems would sit behind a foreseeable, preventable failure — and which of them are already on the record as known risks. A discovery call scopes those systems, the defensibility of the current posture, and what a remediation path would look like, on evidence rather than a pitch. The companion board accountability guide covers turning that into a funded mandate, and the legacy system liability assessment names the broader exposure. Reach the team at sales@modernlift.ai.

Frequently asked questions

What is the Caremark duty of oversight, and how does it reach technology risk?
Caremark is the Delaware standard holding that directors can be liable for a sustained failure to oversee the corporation — either by failing to implement any reporting or monitoring system, or by consciously ignoring red flags it surfaces. The Delaware Supreme Court revived the doctrine in Marchand v. Barnhill (2019), and the Court of Chancery applied it to Boeing's board over 737 MAX safety oversight (2021). Commentators and litigants now apply the same reasoning to cybersecurity and technology risk, on the theory that a mission-critical system the board knew was failing is the kind of red flag Caremark is about.
Does running a known end-of-life system create personal exposure for directors?
Not by itself, and we won't overstate it. Caremark sets a high bar — plaintiffs must show bad-faith or conscious disregard, not mere negligence. But the doctrine's recent trajectory makes one pattern harder to defend, the documented, repeatedly raised, unaddressed risk. A legacy system flagged in audit findings, risk registers, or insurer letters and then left in a critical path moves the question from honest misfortune toward conscious inaction. That is the distinction that matters to a court, and it is the distinction this exposure turns on.
Does the duty of oversight apply to officers too, or only directors?
In In re McDonald's Corporation Stockholder Derivative Litigation (2023), the Delaware Court of Chancery held for the first time that the Caremark duty of oversight applies to corporate officers, not just directors — though the officer duty is more context-driven and tied to each officer's area of responsibility. For technology risk, that reasoning points squarely at the executives who own the systems and the security posture, which is part of why known legacy exposure has moved up the org chart.
What are a board's disclosure duties around known technology and cyber risk?
Separate from the duty of oversight, public companies carry disclosure duties. Under the SEC cybersecurity rules adopted in 2023, a registrant must report a material cybersecurity incident on Form 8-K within four business days of determining it is material, and must describe its cybersecurity risk management, strategy, and governance each year in its annual report. A known, unremediated legacy system raises the risk that a later incident was not disclosed accurately or on time, which is a distinct claim from any failure to oversee the risk. Materiality is a fact-specific judgment, and this is general information rather than securities-law advice.
How does a board discharge the duty of oversight for a known legacy-system risk?
A board discharges the oversight duty by being able to show it saw the risk, weighed it, and acted. In practice that means a maintained risk register naming the mission-critical systems and their known failure modes, a regular reporting line that brings technology and security risk to the board or a named committee, minutes that record how a flagged risk was accepted or funded, and a real, funded remediation plan with evidence it is executing rather than sitting on a slide. The governance record demonstrates due care, and a validated trail of shipped changes is what backs it with proof.