Michael Daugherty spent years wrangling with the Federal Trade Commission over a 2008 data breach at his now-defunct company LabMD before finally defeating the agency after the U.S. Court of Appeals for the Eleventh Circuit ruled the FTC overstepped its authority in ordering sweeping and largely undefined remedial measures.

That five-year fight isn't over: Daugherty and LabMD—which still exists as a corporate entity—are still embroiled in litigation, including a $1.7 million attorney fee request he filed against the FTC to recoup his fees at the Eleventh Circuit.

But Daugherty also is using the knowledge and contacts he's made over the years to help head off online data pirates, founding a cybersecurity foundation that held its first event in Atlanta on Tuesday as the city braces for the Super Bowl and what speakers said are the inevitable attacks that come with it.

“It's not a matter of 'if.' We know there are going to be attacks,” said Daugherty, who put together a panel of lawyers, corporate executives and security professionals to address 100 or so attendees at the daylong Cyber Culture workshop at the Atlanta Tech Village.

“The word 'cybersecurity' scares executives, but it has to be addressed legally and functionally,” Daugherty said in an interview. “The best defense is always a good offense.”

Daugherty—who is neither a lawyer nor a security expert—said his own experience of having his once-successful cancer-testing company hacked and subsequently targeted by the FTC led him to launch the Cyber Education Foundation last year.

“I'm not a cybersecurity expert from the tech side,” said Daugherty. “I'm doing what I do best. Just like I brought the best physicians together for LabMD, I'm bringing the best experts I can find to talk about the law and security.”

Douglas Meal with Orrick in Boston.

Among the speakers was Boston-based attorney Douglas Meal, who recently left Ropes & Gray to join Orrick, Herrington & Sutcliffe and who argued Daugherty's successful appeal at the Eleventh Circuit.

Meal is also a specialist in cybersecurity, and his presentation emphasized the legal strategies and liabilities companies should use in preparing a security strategy.

A data breach may result in blame being cast toward a company's information systems, so good use should be made of outside security assessments, Meal said. At the same time, those assessments can be used by investigating agencies like the FTC or third parties, to target companies working through the aftermath of a data breach.

“When you have an event, one of their first requests is, 'Please provide all your assessments,'” Meal said.

Meal added half the cases he's handled involving data-breach investigations are built on a company's security assessments.

“I would think long and hard about having assessments done under attorney-client privilege,” said Meal, because “that's not a document you have to turn over to an adversary.”

Companies should also be wary of issuing sunny overviews of their security procedures.

“Time and again, what hangs up regulators is not bad security but deceptive statements,” Meal said.

Most important is having a relatively simple security plan in case of a data breach and making sure everyone is on board with it, Meal said.

“A lot of time the plans don't include the GC, CEO or the board,” he said. “Those are the people who make the decisions.”

“In real life, an event occurs, the plan comes out, and the GC or CEO says, 'No, we're not going to do that.' It happens all the time,” Meal said.

In the meantime, he said, damage is ongoing, and what might have been a breach of 10,000 records can snowball into a million or more.

“Every day you have your head in the sand, the event continues,” he said.

Kate Kuehn, the CEO of cybersecurity platform company Senseon's United states division, said in an interview that Atlanta is in a sense more prepared for the Super Bowl in February because of last year's ransomware attack that shut down city computers for several days.

“The idea that Atlanta went through a major breach could be considered a major prep test,” Kuehn said.

Whether it's the Super Bowl, World Series or a major soccer event, said Kuehn. “Whenever you have a large number of people gathering, you'll have a lot of others trying to cause chaos and havoc.”