Ready to Register?

MyLawCLE All-Access Pass

Best choice

Add the All-Access Pass and get this program —
plus 1,000+ live CLE programs every year.


All specialty & ethics credits included
38 practice areas
New sections: AI & the Law, Practice Management
100s of current and trending legal topics
Nationally recognized and highly experienced presenters

$395 / year — this program included
Register with the All-Access Pass

This program + 1,000+ CLE programs, all year

Or register for just this program

On-Demand Video

Recorded access + self-study credit.
$195 Register

Anatomy of a Ransomware Attack: Breach Response, Cyber Insurance, and Post-Incident Remediation Strategy

Master ransomware response from prevention through remediation. Learn to navigate cyber insurance, avoid costly breach-response mistakes, and build enterprise risk strategies that protect clients from financial, legal, and reputational fallout.

2026-06-19 13:00:00

Program Details

2026-06-19 13:00:00

Program Details

2026-06-19 13:00:00

Over 1,000+ webinars

2026-06-19 13:00:00

Course Overview

The Cyber Policy You Have Not Read Until It Is Too Late

2026-06-19 13:00:00

Ransomware, business email compromise, and cyber extortion no longer land solely in the server room — they detonate across statutory notification deadlines, insurance coverage disputes, and regulatory exposure that attach the moment data moves. Counsel advising government entities and the organizations that serve them are already on the hook, often working from incident-response assumptions and policy language written before extortion became a board-level liability and before insurers began contesting coverage on technical grounds. This panel of cybersecurity, cyber insurance, and cyber/privacy law practitioners maps the current threat environment, the legal triggers a cyber-attack sets off, and the coverage terms that decide who absorbs the loss, then walks through what to lock down before a breach, the response missteps that compound legal and reputational damage, and the remediation steps that harden an enterprise against the next one. Attendees leave able to build an enterprise-wide risk management strategy, pressure-test a cyber policy before it is tested for them and direct a breach response that withstands later scrutiny.

Format

CLE Credit

2h CLE Credits

Level

Intermediate

Length

2

Key topics that will be covered

01
Industry panel
Cybersecurity, cyber insurance, and cyber/privacy law leaders share real-world experience.
02
Ransomware attacks
Panelists provide in-depth insight into ransomware attack dynamics and response.
03
Email compromise
Real-world experience addressing business email compromise incidents affecting organizations.
04
Cyber extortion
Panelists examine cyber extortion threats and organizational response considerations.
05
Risk strategy
Implementing enterprise-wide risk management to prevent and mitigate cyber-attack harms.
06
Harm mitigation
Addressing financial, legal, and reputational harms before, during, and after attacks.

Program schedule

clock 1:00 pm - 1:30 pm EST

Current Threat Landscape and Cyber Insurance Navigation

Examine today’s evolving ransomware, business email compromise, and data breach threats alongside emerging legal issues, while learning how to evaluate cyber insurance policies, identify coverage gaps, and secure adequate protection for organizational clients.

Spencer S. PollockSpencer S. Pollock
Kelly CampbellKelly Campbell
Chris LoehrChris Loehr
clock 1:30 pm - 2:00 pm EST

Proactive Measures Before a Breach Occurs

Discover essential preventive strategies organizations must implement before a cyber-attack strikes, including enterprise-wide risk management frameworks, incident response planning, employee training protocols, and vendor management practices that minimize exposure and strengthen defenses.

Spencer S. PollockSpencer S. Pollock
Kelly CampbellKelly Campbell
Chris LoehrChris Loehr
clock 2:10 pm - 2:40 pm EST

Avoiding Common Mistakes During Breach Response

Identify critical errors organizations frequently make when responding to active cyber incidents, and learn proven protocols for preserving privilege, coordinating with law enforcement, managing ransom negotiations, and meeting notification obligations under applicable state and federal regulations.

Spencer S. PollockSpencer S. Pollock
Kelly CampbellKelly Campbell
Chris LoehrChris Loehr
clock 2:40 pm - 3:10 pm EST

Remediation And Prevention of Future Breaches

Master post-incident remediation steps that transform breach experiences into stronger security postures, including forensic investigation protocols, system hardening, policy revisions, and long-term strategies designed to prevent recurring attacks and protect against future cyber threats.

Spencer S. PollockSpencer S. Pollock
Kelly CampbellKelly Campbell
Chris LoehrChris Loehr
Spencer S. Pollock

Spencer S. Pollock

McDonald Hopkins LLC

Kelly Campbell

Kelly Campbell

McDonald Hopkins LLC

Chris Loehr

Chris Loehr

Cyrenity

Spencer S. Pollock

Spencer S. Pollock

McDonald Hopkins LLC

Spencer Pollock is an award-winning data privacy and cybersecurity attorney who serves as a Member of McDonald Hopkins’ national Data Privacy and Cybersecurity team. Based in Baltimore, he specializes in incident response and privacy consulting, having handled hundreds of cyber incidents and data breaches for clients across financial services, healthcare, insurance, education, and managed service provider industries.

Education & Credentials

Pollock earned his Juris Doctor from the University of Baltimore School of Law in 2012 and holds a Bachelor of Arts in Political Science from Sewanee: The University of the South. He is admitted to practice in Maryland, the District of Columbia, and the U.S. District Court for the District of Maryland. He holds two leading privacy credentials from the International Association of Privacy Professionals — Certified Information Privacy Professional/United States (CIPP/US) and Certified Information Privacy Manager (CIPM) — and is a Certified Mediator.

Recognition & Leadership

Pollock has been recognized as a Maryland Super Lawyers Rising Star for six consecutive years (2020–2025) and has been consistently ranked in Business Litigation. He hosts the Cyber Law Revolution podcast, which was named to FeedSpot's Top 10 Breach Podcasts list in 2025 and recently released its milestone 100th episode. In 2022, he anchored McDonald Hopkins' expansion into Maryland by launching the firm's Baltimore office. He is frequently called upon for national legal and business commentary on cybersecurity incidents, and has been featured or quoted in The American Lawyer, CBS News Baltimore (WJZ-TV), WBAL, Fox 45, and the Cyber Insurance Leaders podcast.

Professional Involvement

Pollock is an active member of the Maryland State Bar Association, where he serves on the Cybersecurity Task Force, and the International Association of Privacy Professionals (IAPP). He is a prolific author and speaker, regularly presenting at industry programs including NetDiligence Cyber Risk Summits, IT Nation Connect and IT Nation Secure, the ABA TIPS Section Conference, the GTIA Cybersecurity Conference, and regional CPCU, AFP, and URMIA chapters nationwide. He has authored numerous articles on HIPAA compliance, ransomware defense, state privacy legislation, AI governance, and forensic report privilege, and delivers CLE programs through Quimbee, Celesq, HalfMoon Education, and CeriFi.

Experience

With more than a decade of legal practice, Pollock has guided clients through ransomware attacks, business email compromises, cyber extortion events, vendor-caused breaches, and multi-state notification obligations, while defending them in regulatory investigations before state attorneys general, HHS OCR, and NYDFS. His practice spans the full lifecycle of cyber risk management — pre-breach readiness, incident response, forensic coordination, ransom negotiation strategy, notification compliance under state, federal, and international laws, and post-breach remediation and litigation defense. He also advises C-Suites and boards on enterprise-wide risk management, cyber insurance procurement and claims, vendor due diligence, and AI governance. Before joining McDonald Hopkins in 2022, Pollock practiced at Whiteford, Taylor & Preston and Niles, Barton & Wilmer, where he built a substantial civil trial practice with an 85% win rate as lead counsel in more than 50 jury trials.
Kelly Campbell

Kelly Campbell

McDonald Hopkins LLC

Kelly Campbell is Counsel on McDonald Hopkins’ national Data Privacy and Cybersecurity team, based in the firm’s Baltimore office. She advises clients across a wide variety of industries on addressing data privacy and cybersecurity incidents in compliance with state, federal, and international laws, guiding them through investigation, messaging and public communications, breach notification obligations, post-breach response, and proactive pre-breach services designed to protect personal, sensitive, and confidential information.

Education & Credentials

Campbell earned her Juris Doctor from the University of Baltimore School of Law, where she served as Editor-in-Chief of the University of Baltimore Law Review. She holds a Bachelor of Arts in Public Relations from the University of South Carolina. She is admitted to practice in Maryland and the District of Columbia, as well as before the U.S. District Court for the District of Maryland and the U.S. Court of Appeals for the Fourth Circuit. The International Association of Privacy Professionals (IAPP) recognizes Campbell as a Certified Information Privacy Professional (CIPP/US).

Recognition & Leadership

Campbell was selected to the 2026 Maryland Super Lawyers Rising Stars list, and in 2024 she was named among the Living Classrooms Foundation's Rising Stars by the Baltimore Business Journal, which recognizes accomplished young professionals making meaningful contributions to the Baltimore community. In 2022, she helped launch McDonald Hopkins' new Baltimore office as a founding attorney of the firm's Maryland presence, extending the national Data Privacy and Cybersecurity practice into the Baltimore–D.C. corridor.

Professional Involvement

Campbell is an active member of the Maryland State Bar Association's Young Lawyers Section, the Federal Bar Association, the Baltimore City Bar Association, and the IAPP. She is a frequent author and speaker on data privacy and cybersecurity topics, with recent presentations including "Cybersecurity for Solos – Defending Your Firm" (2025), "Legislative and Regulatory Update" at the Stronger Conference 2024, "Cyber & Privacy Headaches" at the Mid-Atlantic AFP Treasury and Financial Forum, "The Cyber Arms Race" at the URMIA Annual Conference, and "Insurance Data Security Model Laws" at the Big I Maryland Annual Conference. She has authored articles on California's data breach notification law, MSP liability, Washington's My Health My Data Act, and state-level ransomware legislation, and has been quoted in Privacy Daily on multi-state notification deadlines. She is passionate about providing equitable education and opportunities to students throughout her community.

Experience

With experience spanning the full lifecycle of cyber incident response, Campbell has guided clients through ransomware attacks, business email compromises, vendor-caused breaches, and complex multi-state notification obligations under evolving state, federal, and international privacy regimes. Her pre-breach work includes policy development, vendor due diligence, employee training, and building incident response plans designed to minimize risk and strengthen compliance posture. In addition to her data privacy and cybersecurity practice, Campbell maintains an active complex commercial litigation practice, representing clients in state and federal courts. Before joining McDonald Hopkins in 2022, she practiced at Whiteford, Taylor & Preston LLP in Baltimore, where she began focusing on data security and cybersecurity matters and co-authored published guidance on ransomware and insider threats.
Chris Loehr

Chris Loehr

Cyrenity

Chris Loehr is a cybersecurity executive with more than 25 years of leadership experience in cybersecurity, information technology, and security operations. He currently serves as Co-Founder and Executive Vice President of Cyrenity Security, a managed cybersecurity and incident response firm protecting small and medium-sized businesses. His work centers on ransomware incident response, digital forensics, cyber-extortion and ransom negotiation, and proactive security operations. Earlier in his career he concentrated on designing and delivering cybersecurity and IT operational strategies within the financial services sector before moving into frontline incident response, where he has guided organizations through active cyberattacks and approached response efforts as more than a purely technical exercise.

Education & Credentials

Chris Loehr earned a Bachelor of Science in Management Information Systems and a Master of Business Administration in Finance, both from Oklahoma City University. He also holds the Chainalysis Reactor Certification (CRC), relevant to cryptocurrency tracing in ransom-payment investigations.

Recognition & Leadership

Chris Loehr is a Co-Founder and Executive Vice President of Cyrenity Security, one of five co-founders who together bring over 100 years of combined experience across cybersecurity, digital forensics, and security operations. He previously held executive leadership roles as Executive Vice President and Chief Technology Officer of CFC Response and as Executive Vice President and President of Solis Security. He has also served as a keynote speaker at the SecureIT Summit.

Professional Involvement

Chris Loehr is an active public speaker and frequent podcast and webinar guest on ransomware, incident response, and crisis communications. He has appeared on programs including The Weekly CyberCall, Cyber Crime Junkies, Joey Pinz Discipline Conversations, and the Wise Up Podcast, and is a contributor to SC Media. He has been quoted extensively as a ransomware and incident-response expert in investigative journalism, including ProPublica's reporting on the economics of ransomware and ransom negotiation.

Experience

Chris Loehr currently serves as Co-Founder and Executive Vice President of Cyrenity Security. Previously, he was Executive Vice President and Chief Technology Officer of CFC Response following CFC's acquisition of Solis Security, where he oversaw the day-to-day operations of the firm's incident response and proactive cybersecurity teams. Before that, he served as Executive Vice President and President of Solis Security, building and leading its incident response practice. His earlier career was concentrated in IT and IT-operations leadership within the financial services sector, including roles at USAA, IBC Bank, and other financial institutions.
Spencer S. Pollock

Spencer S. Pollock

McDonald Hopkins LLC

Spencer Pollock is an award-winning data privacy and cybersecurity attorney who serves as a Member of McDonald Hopkins’ national Data Privacy and Cybersecurity team. Based in Baltimore, he specializes in incident response and privacy consulting, having handled hundreds of cyber incidents and data breaches for clients across financial services, healthcare, insurance, education, and managed service provider industries.

Education & Credentials

Pollock earned his Juris Doctor from the University of Baltimore School of Law in 2012 and holds a Bachelor of Arts in Political Science from Sewanee: The University of the South. He is admitted to practice in Maryland, the District of Columbia, and the U.S. District Court for the District of Maryland. He holds two leading privacy credentials from the International Association of Privacy Professionals — Certified Information Privacy Professional/United States (CIPP/US) and Certified Information Privacy Manager (CIPM) — and is a Certified Mediator.

Recognition & Leadership

Pollock has been recognized as a Maryland Super Lawyers Rising Star for six consecutive years (2020–2025) and has been consistently ranked in Business Litigation. He hosts the Cyber Law Revolution podcast, which was named to FeedSpot's Top 10 Breach Podcasts list in 2025 and recently released its milestone 100th episode. In 2022, he anchored McDonald Hopkins' expansion into Maryland by launching the firm's Baltimore office. He is frequently called upon for national legal and business commentary on cybersecurity incidents, and has been featured or quoted in The American Lawyer, CBS News Baltimore (WJZ-TV), WBAL, Fox 45, and the Cyber Insurance Leaders podcast.

Professional Involvement

Pollock is an active member of the Maryland State Bar Association, where he serves on the Cybersecurity Task Force, and the International Association of Privacy Professionals (IAPP). He is a prolific author and speaker, regularly presenting at industry programs including NetDiligence Cyber Risk Summits, IT Nation Connect and IT Nation Secure, the ABA TIPS Section Conference, the GTIA Cybersecurity Conference, and regional CPCU, AFP, and URMIA chapters nationwide. He has authored numerous articles on HIPAA compliance, ransomware defense, state privacy legislation, AI governance, and forensic report privilege, and delivers CLE programs through Quimbee, Celesq, HalfMoon Education, and CeriFi.

Experience

With more than a decade of legal practice, Pollock has guided clients through ransomware attacks, business email compromises, cyber extortion events, vendor-caused breaches, and multi-state notification obligations, while defending them in regulatory investigations before state attorneys general, HHS OCR, and NYDFS. His practice spans the full lifecycle of cyber risk management — pre-breach readiness, incident response, forensic coordination, ransom negotiation strategy, notification compliance under state, federal, and international laws, and post-breach remediation and litigation defense. He also advises C-Suites and boards on enterprise-wide risk management, cyber insurance procurement and claims, vendor due diligence, and AI governance. Before joining McDonald Hopkins in 2022, Pollock practiced at Whiteford, Taylor & Preston and Niles, Barton & Wilmer, where he built a substantial civil trial practice with an 85% win rate as lead counsel in more than 50 jury trials.
Kelly Campbell

Kelly Campbell

McDonald Hopkins LLC

Kelly Campbell is Counsel on McDonald Hopkins’ national Data Privacy and Cybersecurity team, based in the firm’s Baltimore office. She advises clients across a wide variety of industries on addressing data privacy and cybersecurity incidents in compliance with state, federal, and international laws, guiding them through investigation, messaging and public communications, breach notification obligations, post-breach response, and proactive pre-breach services designed to protect personal, sensitive, and confidential information.

Education & Credentials

Campbell earned her Juris Doctor from the University of Baltimore School of Law, where she served as Editor-in-Chief of the University of Baltimore Law Review. She holds a Bachelor of Arts in Public Relations from the University of South Carolina. She is admitted to practice in Maryland and the District of Columbia, as well as before the U.S. District Court for the District of Maryland and the U.S. Court of Appeals for the Fourth Circuit. The International Association of Privacy Professionals (IAPP) recognizes Campbell as a Certified Information Privacy Professional (CIPP/US).

Recognition & Leadership

Campbell was selected to the 2026 Maryland Super Lawyers Rising Stars list, and in 2024 she was named among the Living Classrooms Foundation's Rising Stars by the Baltimore Business Journal, which recognizes accomplished young professionals making meaningful contributions to the Baltimore community. In 2022, she helped launch McDonald Hopkins' new Baltimore office as a founding attorney of the firm's Maryland presence, extending the national Data Privacy and Cybersecurity practice into the Baltimore–D.C. corridor.

Professional Involvement

Campbell is an active member of the Maryland State Bar Association's Young Lawyers Section, the Federal Bar Association, the Baltimore City Bar Association, and the IAPP. She is a frequent author and speaker on data privacy and cybersecurity topics, with recent presentations including "Cybersecurity for Solos – Defending Your Firm" (2025), "Legislative and Regulatory Update" at the Stronger Conference 2024, "Cyber & Privacy Headaches" at the Mid-Atlantic AFP Treasury and Financial Forum, "The Cyber Arms Race" at the URMIA Annual Conference, and "Insurance Data Security Model Laws" at the Big I Maryland Annual Conference. She has authored articles on California's data breach notification law, MSP liability, Washington's My Health My Data Act, and state-level ransomware legislation, and has been quoted in Privacy Daily on multi-state notification deadlines. She is passionate about providing equitable education and opportunities to students throughout her community.

Experience

With experience spanning the full lifecycle of cyber incident response, Campbell has guided clients through ransomware attacks, business email compromises, vendor-caused breaches, and complex multi-state notification obligations under evolving state, federal, and international privacy regimes. Her pre-breach work includes policy development, vendor due diligence, employee training, and building incident response plans designed to minimize risk and strengthen compliance posture. In addition to her data privacy and cybersecurity practice, Campbell maintains an active complex commercial litigation practice, representing clients in state and federal courts. Before joining McDonald Hopkins in 2022, she practiced at Whiteford, Taylor & Preston LLP in Baltimore, where she began focusing on data security and cybersecurity matters and co-authored published guidance on ransomware and insider threats.
Chris Loehr

Chris Loehr

Cyrenity

Chris Loehr is a cybersecurity executive with more than 25 years of leadership experience in cybersecurity, information technology, and security operations. He currently serves as Co-Founder and Executive Vice President of Cyrenity Security, a managed cybersecurity and incident response firm protecting small and medium-sized businesses. His work centers on ransomware incident response, digital forensics, cyber-extortion and ransom negotiation, and proactive security operations. Earlier in his career he concentrated on designing and delivering cybersecurity and IT operational strategies within the financial services sector before moving into frontline incident response, where he has guided organizations through active cyberattacks and approached response efforts as more than a purely technical exercise.

Education & Credentials

Chris Loehr earned a Bachelor of Science in Management Information Systems and a Master of Business Administration in Finance, both from Oklahoma City University. He also holds the Chainalysis Reactor Certification (CRC), relevant to cryptocurrency tracing in ransom-payment investigations.

Recognition & Leadership

Chris Loehr is a Co-Founder and Executive Vice President of Cyrenity Security, one of five co-founders who together bring over 100 years of combined experience across cybersecurity, digital forensics, and security operations. He previously held executive leadership roles as Executive Vice President and Chief Technology Officer of CFC Response and as Executive Vice President and President of Solis Security. He has also served as a keynote speaker at the SecureIT Summit.

Professional Involvement

Chris Loehr is an active public speaker and frequent podcast and webinar guest on ransomware, incident response, and crisis communications. He has appeared on programs including The Weekly CyberCall, Cyber Crime Junkies, Joey Pinz Discipline Conversations, and the Wise Up Podcast, and is a contributor to SC Media. He has been quoted extensively as a ransomware and incident-response expert in investigative journalism, including ProPublica's reporting on the economics of ransomware and ransom negotiation.

Experience

Chris Loehr currently serves as Co-Founder and Executive Vice President of Cyrenity Security. Previously, he was Executive Vice President and Chief Technology Officer of CFC Response following CFC's acquisition of Solis Security, where he oversaw the day-to-day operations of the firm's incident response and proactive cybersecurity teams. Before that, he served as Executive Vice President and President of Solis Security, building and leading its incident response practice. His earlier career was concentrated in IT and IT-operations leadership within the financial services sector, including roles at USAA, IBC Bank, and other financial institutions.

Credits by state

AK2.0
AL2.0
AR2.0
AZ2.0
CA2.0
CO2.0
CT2.0
DC
DE2.0
FL2.0
GA2.0
HI2.0
IA2.0
ID2.0
IL2.0
IN2.0
KS2.0
KY2.0
LA2.0
MA2.0
MD2.0
ME2.0
MI2.0
MN2.0
MO2.4
MS2.0
MT2.0
NC2.0
ND2.0
NE2.0
NH120.0
NJ2.0
NM2.0
NV2.0
NY2.0
OH2.0
OK2.5
OR2.0
PA2.0
RI2.5
SC2.0
SD2.0
TN2.0
TX2.0
UT2.0
VA2.0
VT2.0
WA2.0
WI2.0
WV2.4
WY2.0

1000+

Live stream programs

24/7

Access to live webinars & recordings

70,000+

Trusted by Legal Professionals

1000+

Live stream programs

24/7

Access to live webinars & recordings

70,000+

Trusted by Legal Professionals

1000+

Live stream programs

24/7

Access to live webinars & recordings

10,000+

Trusted by Legal Professionals

1000+

Live stream programs

24/7

Access to live webinars & recordings

70,000+

Trusted by Legal Professionals

MCLE Credits

Alabama
Approved
Alaska
Approved
Arizona
Approved
Arkansas
Approved
California
Approved
Colorado
Pending
Connecticut
Approved
Delaware
Pending
District of Columbia
No Required
Florida
Approved
Georgia
Approved
Hawaii
Approved
Idaho
Pending
Illinois
Pending
Indiana
Pending
Iowa
Pending
Kansas
Pending
Kentucky
Pending
Louisiana
Pending
Maine
Pending
Maryland
No Required
Massachusetts
No Required
Michigan
No Required
Minnesota
Pending
Mississippi
Pending
Missouri
Approved
Montana
Pending
Nebraska
Pending
Nevada
Pending
New Hampshire
Approved
New Jersey
Approved
New Mexico
Approved
New York
Approved
North Carolina
Pending
North Dakota
Approved
Ohio
Approved
Oklahoma
Pending
Oregon
Pending
Pennsylvania
Approved
Rhode Island
Pending
South Carolina
Pending
South Dakota
No Required
Tennessee
Approved
Texas
Approved
Utah
Pending
Vermont
Approved
Virginia
Not Eligible
Washington
Approved
West Virginia
Pending
Wisconsin
Approved
Wyoming
Approved

Alabama

Requirements

The Alabama State Bar MCLE Commission requires attorneys to complete 12 credits, including 1 ethics, by December 31 of each year. All credits must be reported by February 15 of the following year. A maximum of 12 credits, including 1 ethics credit, may be carried over for 1 year only.  

Formats

  • Attorneys can earn unlimited “live” credit through live seminars, live webcasts, and co-sponsored locations with MyLAWCLE-Alabama approved programs
  • Attorneys are limited to 6 credits per compliance period of “online” programs through MyLAwCLE On-Demand programs