Companies large and small are grappling with an ever-evolving cyber risk landscape. However, two recent cases against companies and their Chief Information Security Officers (CISOs), bring to the fore considerations around personal liability and whistleblowers. Managing these risks at a single company should be straightforward. Executives and CISOs may be personally held accountable for cyber failings, negligence, breaches, and inadequate disclosure around cyber vulnerabilities and incidents.