As the leader of Shook’s cybersecurity-counseling and incident-response work, advising clients on information security is at the core of Colman's practice. He helps organizations prepare for, respond to, and recover from cybersecurity incidents, and counsels them on the legal obligations that go hand in hand with that work. His expertise has earned Colman multi-year rankings in Chambers USA and Chambers Global for Privacy & Data Security and Lawdragon's Leading Global Cyber Lawyers in both Privacy & Data Security and Incident Response. 

Colman is a recognized thought leader in privacy and cybersecurity law. He chairs The Sedona Conference® Working Group 11: Data Security and Privacy Liability, a national working group where judges, in-house counsel, and outside practitioners come together to shape the guidance and best practices that inform privacy and data-security law across the country. In that role, he helps set the group's research agenda and programming on issues spanning compliance, incident response, and litigation in the field of privacy and security. Colman also served as lead editor of Lexology Panoramic: Cybersecurity 2026, a comparative guide to cybersecurity law and practice across jurisdictions worldwide. He is a frequent speaker and media source as well, writing and presenting on topics ranging from the use of artificial intelligence in cyberattacks to the global cybersecurity regulatory landscape, and is an active member of the International Association of Privacy Professionals.

Colman's experience spans a broad range of industries, including healthcare, manufacturing, financial services, insurance, education, retail, energy, and technology. He regularly directs matters ranging from ransomware attacks to business email compromise to employee theft of information to HIPAA risk assessments—overseeing forensic investigations, preparing and delivering required notifications, and managing regulator inquiries. Clients frequently turn to Colman before an incident ever occurs, relying on him to put the governance in place needed to respond quickly and defensibly when something does go wrong.

That same proactive approach carries into Colman's privacy compliance work. He advises clients nationwide on their obligations under domestic and international privacy and data-security laws, translating dense regulatory requirements into practical guidance suited to each client's actual risk profile.

Before turning his focus to privacy and cybersecurity, Colman spent more than a decade as a litigator. That experience—briefing motions, managing discovery, and seeing firsthand how legal exposure unfolds once a dispute is underway—continues to inform how he counsels clients today. Colman brings a litigator's eye for risk to his cybersecurity and privacy work, helping clients make front-end decisions, from the incident-response plan they adopt to the vendor terms they negotiate, with a clear view toward controlling both short- and long-term liability.

 

Presentations and Publications

Cybersecurity: Global Overview, Lexology, March 31, 2026.

The Evolving Use of A.I. in Cyberattacks, ABA Cybersecurity Legal Task Force, October 3, 2025 (with Josh Hansen).

Data Privacy Primer, Second EditionSedona Conference Midyear Meeting, October 29, 2024.

Data Privacy Primer, Second Edition, The Sedona Conference Working Group 11 Annual Meeting 2024, Minneapolis, Minnesota, May 2, 2024 (Panel moderator). 

WG11 Town Hall, The Sedona Conference Working Group 11 Annual Meeting 2024, Minneapolis, Minnesota, May 2, 2024 (Panel member).

Draft Commentary on the Privacy and Security of Emerging Health Data, The Sedona Conference Working Group 11 Annual Meeting 2024, Minneapolis, Minnesota, May 2, 2024 (Panel member).

A Deep Dive into the Complex Web of Federal and State Cyber and Privacy Laws and Regulations – and the Core Elements of a Cyber Compliance Program, American Conference Institute, February 28, 2024. 

An Overview of EU and US Cybersecurity Regulations, Interact Law, September 25, 2023, and November 8, 2023 (with Josh Hansen and Jasper Holsebosch).

Data Privacy Primer, Second Edition, The Sedona Conference Working Group 11 Mid-year Meeting 2023, Tampa, Florida, November 2, 2023 (Panel moderator). 

Children's Data Privacy, The Sedona Conference Working Group 11 Annual Meeting 2023, Denver, Colorado, May 5, 2023 (Panelist).

Privacy and Cybersecurity Overview, Virtual CLE Presentation, October 11, 2022 (with Josh Grajewski).

California’s Consumer Privacy Rights Act (CPRA): What Arizona Data Processors Need to Know, CPRA Enforcement and Tabletop Exercise, ARM International and Arizona Chapter Event, Phoenix, Arizona, September 15, 2022 (with Starr Drum and Garrett Groos).

Talking Tech: Making Sense of Forensics, ABA National Institute on Cybersecurity and Data Protection, San Francisco, California, September 13, 2022 (with Fidan Karimli, Serge Jorgensen, and Bryce Welke).

Tidal Wave Approaching: The Accelerating Trend of Comprehensive Privacy Laws, Update of the Law CLE webinar, June 2, 2022 (with Camila Tobón). 

Biometric Privacy Primer, The Sedona Conference Working Group 11 Annual Meeting 2022, Phoenix, Arizona, April 27, 2022 (Panelist). 

Data Privacy Trends & Cybersecurity Preparedness, ACC Mid-America Chapter and Shook, Hardy & Bacon, L.L.P.,  April 13, 2022 (with Josh Hansen). 

Hot Topics in Privacy and Cybersecurity Law, Virtual Presentation, December 20, 2021 (with Al Saikali and Camila Tobón).

Insurance Cybersecurity Laws: Overview and Trends, Virtual CLE, December 14, 2021 (with Jon Wilson).

Cybersecurity and Environmental Management, Midwest Environmental Compliance Conference, Overland Park, Kansas, October 26, 2021 (with Dalton Mott).

Privacy & Security Developments, Update of the Law CLE, Virtual Presentation, Shook, Hardy & Bacon, June 10, 2021 (with Erin Hines, Tatiana Rice, Bill Sampson and Maveric Searle).

A Mishmash of Privacy and Data Security, Virtual CLE, February 25, 2021 (with Al Saikali).

Breaking It Down and Breaking It Out: Minimizing the Legal Risks of Emerging Trends in Privacy and Cybersecurity, ACC Annual Conference, October 14, 2020 (with Al Saikali and Melissa Siebert).

Ethical Issues for Privacy and Data Security Professionals, Practicing Law Institute’s Twenty-First Annual Institute on Privacy and Cybersecurity Law, Virtual Presentation, August 18, 2020.

The Office: A Series of Corporate Privacy and Data Security Vignettes,
Update of the Law CLE, Virtual Presentation, Shook, Hardy & Bacon, June 12, 2020 (with Al Saikali and Melissa Siebert).

Data Privacy Survival Guide—Building a Roadmap for Success,
ACC Mid-America Chapter, Virtual Presentation, May 13, 2020 (with Rebecca Perry and Ron Hoffman).

What All Corporate Counsel Should Know About Privacy and Data Security in 2020, CLE, Association of Corporate Counsel, Denver, Colorado, November 19, 2019 (Panel Leader).

The California Consumer Privacy Act (or: What I Did on My Summer Vacation), Webinar, National Association of Manufacturers, October 23, 2019 (with Steve Vieux). 

Privacy and Security Governance for Law Firms: Is it Time to Hire a CPO? ABA Fourth National Institute on Cybersecurity and Data Protection: A Law Firm's Responsibility in Managing Data Risk, New York City, June 20, 2019 (Panel Moderator).

Medical Device Cybersecurity: How the U.S. Food and Drug Administration and Other Stakeholders Are Collaborating to Increase Patient Safety, Update of the Law CLE, Kansas City, Missouri, June 13, 2019 (with Sonali Gunawardhana). 

The Ins and Outs of Blockchain and AI, Confidential Client Presentation - CLE, Sunnyvale, California, March 27, 2019 (with Cory Fisher and Keith Bae).

Advising Clients With Limited Resources on Cost-Effective Data Security and Privacy Strategies, The Sedona Conference Working Group 11 Annual Meeting 2019, Houston, Texas, March 1, 2019 (Panelist). 

Minimizing Cyber Risks: What Every In-House Lawyer Needs to Know, Mid-America Chapter of the Association of Corporate Counsel (CLE), Kansas City, Missouri, December 5, 2018 (with Al Saikali). 

Privacy & Data Security Risks,  Confidential Client Presentation - CLE, New York City, November 29, 2018 (with Al Saikali). 

The Legal and Ethical Risks of Privacy and Data Security Traps, Update of the Law CLE, Kansas City, Missouri, June 14, 2018 (with Alfred Saikali, Eric Boos, Patrick Castle, Bill Sampson and Camila Tobón).

Exhausted!: The Supreme Court Weakens Patent Owners’ Rights to Enforce Post-Sale Restrictions on Patented Products, Shook IpQ, August 2017 (with Robert Reckers, Elena McFarland and Melissa Marrero).

Patent War on Two Fronts, Update of the Law CLE, Kansas City, Missouri, June 22, 2017 (with Tanya Chaney and Fiona Bell). 

Criminal Relationships: Vertical and Horizontal Relatedness in Criminal RICO, 86 Wash. U. L. Rev. 1493, 2009.

Media

Steps to Address the New California Audit Rule That Seeks to Reset Reasonable Security, Cybersecurity Law Report, November 5, 2025.

Ten Cybersecurity Resolutions for 2024, Cybersecurity Law Report, January 10, 2024.

Indiana Senate Passes Consumer Privacy Bill Lacking Right to Sue, February 2, 2022.