Advises companies on cybersecurity incident response, including ransomware attacks, data breaches, fund transfer fraud, and business email compromise
Represents clients in data security and privacy litigation and regulatory investigations
Counsels publicly traded companies on SEC cybersecurity disclosure requirements, including Form 10-K and Form 8-K filings
Leverages a background in computer programming and IT analysis to advise on data security, privacy, AI, and computer forensic investigations
Stephen Reynolds (CIPP/US, CISSP) advises some of the largest companies in the world on complex data security and privacy matters.
Stephen assists companies with responding to cybersecurity incidents such as ransomware attacks, fund transfer fraud, data breaches, and business email compromise matters – including helping companies comply with regulatory obligations arising from these incidents, such as U.S. Securities and Exchange Commission (SEC) filings for publicly traded companies. He has also advised multiple publicly traded companies on compliance with the SEC’s requirements for disclosing cybersecurity incidents, risk management, and governance in Form 10-K annual reports and Form 8-Ks. Having litigated data security and privacy cases from the trial court level through the highest levels of appeal, Stephen also represents clients in litigation and regulatory investigations regarding data security, privacy, and technology matters.
Stephen frequently educates others on data security and privacy at industry conferences and forums. He is a former board member of the International Association of Privacy Professionals (IAPP), an instructor of the IAPP’s CIPP/US certification, and an instructor for the CISSP certification through ISC(2). He also lectures on Data Security and Privacy Law at Indiana University Robert H. McKinney School of Law.
- Handling cybersecurity response for a global technology company with operations in more than 150 countries
- Led the response to a ransomware attack involving a demand of more than $25 million from a threat actor that had critical global implications for the supply chain; oversaw the forensic investigation and coordinated with law enforcement*
- Led the response to a significant data security incident involving millions of individuals’ data
- Lexology Data 100, Recommended, 2026
- The Best Lawyers in America, Commercial Litigation, 2021 and 2025-2026, Litigation – Health Care, 2021 and 2025-2026
- IAPP Diversity in Privacy Award, Inaugural Recipient, 2023
- Cybersecurity Docket’s Incident Response 50, 2023
- Indianapolis Bar Association, E-Discovery, Information Governance & Cybersecurity Professional of the Year, 2022
- Southern District of Indiana, Local Rules Advisory Committee, member
- International Association of Privacy Professionals, Board of Directors
- US Secret Service Chicago Cyber Fraud Task Force, Steering Committee, member
- InfraGard Indiana, member
- Indiana University Maurer School of Law, Board of Directors
- Indiana University Maurer School of Law, JD
- University of Florida, BA
- District of Columbia
- Indiana
- English