Andrew Tannenbaum
Image of Andrew Tannenbaum

Andrew Tannenbaum

Partner

Andrew is Global Co-Head of Cybersecurity.

Andrew is a leading technology lawyer with more than two decades of experience in financial services, big tech, government, and national security. His practice sits at the intersection of cybersecurity, AI, and data privacy, where he advises global enterprises, boards, and senior executives on their most significant technology-related risks. Ranked in Chambers USA, Andrew counsels clients across the full lifecycle of cyber, AI, and data matters, from governance, deployment, and compliance to incident response, investigations, national security and geopolitical considerations, and emerging issues such as frontier and agentic AI risks. With his unique background combining senior in-house and government roles, Andrew brings a deep and first-hand understanding of the operational and practical challenges clients face navigating high-stakes and emerging technology risks in highly regulated industries. 

Prior to joining A&O Shearman, Andrew served as General Counsel for Barclays Execution Services, the global services company of the Barclays Group. In that role, Andrew led Barclays’ legal teams worldwide across all areas of technology and operations, including cyber, AI, data privacy, emerging technologies, intellectual property, operational resilience, third-party risk management, technology transactions, and crisis management. 

Andrew has pioneered cybersecurity and AI roles for lawyers at the top levels of industry and government. He was the first Chief Cybersecurity Counsel at IBM, where he founded one of the earliest global corporate cyber legal teams, and he was Barclays’ first global legal head of AI, cyber, and data. During a decade in government, Andrew served as the National Security Agency’s first Deputy General Counsel for Cyber and held prominent positions in the White House and Department of Justice. He has overseen hundreds of cyber incidents and data breach investigations at all levels of severity, guiding clients through cross-border crisis response and regulatory investigations. 

A trusted advisor to boards, C-suite executives, general counsels, CISOs, and technology leaders, Andrew provides practical, business-focused counsel in highly dynamic and operational environments. Recognized for his thought leadership, Andrew teaches cybersecurity, privacy, and government surveillance law at Columbia Law School, has testified before Congress on cybersecurity law, and has contributed to leading publications such as The Wall Street Journal and Harvard Business Review.

Expertise

Industries

Experience

Representative matters

  • The Board of Directors of one of the largest global financial institutions on AI governance, oversight, and related cyber risks.
  • Multiple original participants in Anthropic’s Project Glasswing on legal considerations and risks around their early access to Mythos and other advanced cyber-capable frontier models.
  • A U.S. multinational bank on an end-to-end AI compliance risk assessment and strategy for novel customer-facing uses of AI across its wealth management and institutional client platforms, as well as the bank’s internal use of AI tools.
  • Several major financial institutions on a high-profile supplier data breach targeting large volumes of consumer loan application materials.
  • A leading cybersecurity company on its collection of dark web intelligence and incident response activities assessed against local legal requirements and risks in numerous countries across the globe.
  • A global luxury retailer on a sophisticated cyberattack exposing client personal data. Advised on all aspects of the incident, including rapid containment and evidence preservation, supervision of forensic investigation, coordination with law enforcement, regulatory and customer communications, and post-incident remediation planning.
  • A multinational fintech and payment platform on the launch of innovative payment and AI-enabled products, and compliance with global multifactor authentication and biometrics requirements.
  • A leading enterprise AI platform company on a ransomware incident targeting the training data of its enterprise clients. Led the investigation and response including forensic oversight, data review and impact assessment, enterprise customer engagement, individual and regulator notifications, law enforcement coordination, Board updates, and post-incident security program uplifts.
  • An AI platform for talent recruitment and intelligence on their global privacy, biometrics, and AI policies and practices.
  • A Canadian bank on its compliance with New York Department of Financial Services (NYDFS) Part 500 cybersecurity regulations, as well as biometrics privacy compliance across multiple global jurisdictions.
  • Multiple multinational organizations on AI meeting transcription and summarization, AI prompt and output retention requirements, AI-related litigation hold and discovery considerations, AI-related privilege preservation, and AI communications recordkeeping obligations.
  • A global leader in measurements technology on its compliance with Department of War requirements to certify non-use of Anthropic products and services in connection with government contracts.
  • Multiple global companies on compliance with the U.S. Department of Justice rule on the transfer of bulk sensitive personal data to China, Hong Kong, and other designated countries of concern, including data mapping, security and access controls, contractual safeguards, and compliance program documentation and approach.
     

Published Work

  • Quoted, (2025) “SEC Dismissal of SolarWinds Case”, The Wall Street Journal
  • Quoted, (2025) “SEC Dismissal of SolarWinds Case”, Law.com
  • Co-author, (2025) “SEC Dismissal of SolarWinds Case”, Harvard Law School Forum on Corporate Governance
  • Co-author, (2025) “Data Centers and Emerging Cyber Risks”, Dow Jones Risk Journal
  • Quoted, (2025) “Mythos and AI Agents’ Impact on Cybersecurity”, IT Brew
  • Quoted, (2025) “Mythos and AI Agents’ Impact on Cybersecurity”, Cybersecurity Law Report
  • Author, Why Do IoT Companies Keep Building Devices With Huge Security Flaws?, Harvard Business Review, 2017
  • Author, To Prevent Cyberattacks, Share the Threat Data, Op-Ed, Wall Street Journal, 2015
  • Author and Testifying Witness, The Growing Cyber Threat and its Impact on American Business, Statement for the Record, United States House of Representatives Permanent Select Committee on Intelligence, 2015

Speaking Engagements

  • Moderator, Cybersecurity in Focus, IAPP Chicago, October 2025 
  • Moderator, Cybersecurity – You’ve Been Hacked, International Bar Association Boston Conference, June 2025 
  • Panelist, Building Cyber Resilience: Defending Against Fraud and Cybercrime in Digital Age, IAPP London, March 2025 
  • Panelist, Cybersecurity, Hacking, and Data Breach – Scenarios for Preparedness, PLI TechLaw Institute, March 2024 
  • Law & Technology Practitioner in Residence, Perspectives in Cybersecurity and Informational Privacy, Indiana University Maurer School of Law, February 2024 
  • Guest Lecturer, Cyber Law & Ethics, Dartmouth College Computer Science Program, November 2023
  • Panelist, Cyber Issues: Traps for the Unwary, SIFMA Annual C&L Seminar, March 2022
  • Panelist, Cybersecurity Update: Combating an Evolving Threat, SIFMA C&L Forum, July 2021

Leadership Positions And Professional Affiliations

  • Adjunct Faculty, Lecturer in Law, Columbia Law School
  • Founding Board Member, Cyber Counsel Group

Recognition

Andrew’s approach, and depth and breadth of knowledge, is what instills trust and confidence from his clients.
Chambers USA 2026: Privacy & Data Security: Cybersecurity
He is incredibly smart, calm under pressure, commercial, reasonable and personable.
Chambers USA 2026: Privacy & Data Security: Cybersecurity

Awards

  • Cybersecurity & Data Privacy Trailblazer, National Law Journal, 2016
  • Attorney General’s Distinguished Service Award, 2010

Qualifications

Admissions

New York, 2001

Academic

JD, Columbia Law School, 2000

AB, Dartmouth College, 1997

Disclaimer
A&O Shearman was formed on May 1, 2024 by the combination of Shearman & Sterling LLP and Allen & Overy LLP and their respective affiliates (the legacy firms). Any matters referred to above may include matters undertaken by one or more of the legacy firms rather than A&O Shearman.