Skip to content
DWT logo
People Services Insights
About Offices Careers
Search
People
Services
Insights
About
Offices
Careers
Search
Desktop Image: Borgia, Michael
Mobile Image: Borgia, Michael

Michael T. Borgia

Partner

T 202.973.4282 Washington, D.C.
I love working at the intersection of law and technology.
  •  

Download vCard Download bio Print this page
Share

Events

06.24.25
Countdown to Enforcement: Navigating DOJ's Bulk Sensitive Data Access Rule

Mike leads DWT's information security practice within the firm's technology, communications, privacy and security practice group. He draws on his years of experience as outside counsel, in-house counsel at a global technology consultancy, and a cybersecurity consultant to deliver solutions that are practical, business-forward and tech-savvy.

A veteran incident response professional, Mike has led investigations of and responses to hundreds of security incidents, from ransomware attacks to trade secret theft to sophisticated nation-state hacking campaigns. He has represented clients in complex investigations by federal and state authorities, including the Federal Communications Commission (FCC), federal banking regulators, the Department of Health and Human Services (HHS), Office of Civil Rights (OCR), the New York Department of Financial Services (NYDFS), and multistate attorneys general following data breaches and other types of cybersecurity and data privacy incidents.

Mike is a trusted advisor to companies operating in many sectors, including telecommunications, financial services, cloud computing and information technology. He regularly advises on compliance with generally applicable and sector-specific information security and data privacy laws and frameworks in the United States and abroad, including the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) and implementing regulations issued by the Cybersecurity & Infrastructure Security Agency (CISA), the California Consumer Privacy Act (CCPA) and its cybersecurity audit regulations, the Gramm-Leach-Bliley Act (GLBA), including the Consumer Financial Protection Bureau's (CFPB) Regulation P and the Federal Trade Commission's (FTC) Safeguards Rule, the Communications Act and regulations issued by the FCC, the Cable Communications Policy Act, the Health Insurance Portability and Accountability Act (HIPAA) and its implementing rules, Executive Order 14028 (Improving the Nation's Cybersecurity), the NYDFS Cybersecurity Regulation, the Payment Card Industry Data Security Standard (PCI DSS), the European Union's NIS2 Directive, Digital Operational Resilience Act (DORA) and Cyber Resilience Act (CRA), and state privacy, data breach and data security laws.

Mike also has extensive experience advising federal and state contractors on information security and privacy requirements for procurement, including requirements of the Federal Risk and Authorization Management Program (FedRAMP), StateRAMP, the Cybersecurity Maturity Model (CMMC), the Federal Acquisition Regulation (FAR), the Defense Federal Acquisition Regulation Supplement (DFARS), and special publications by the National Institute of Standards and Technology (NIST).

Mike regularly serves as data strategy subject matter expert on mergers and acquisitions as well as on commercial agreements, including co-branded credit card arrangements and bank-fintech partnerships. In this capacity, he advises on data privacy, information security, confidentiality, data licensing and other issues to help clients collect and use data to meet their business goals.

Practice Highlights

Complex data breach response

Leads investigations of and responses to complex data breaches and security incidents, including those involving state-sponsored threats, trade secret theft, sophisticated supply-chain attacks, ransomware, industrial espionage, and insider threats.

Government investigations

Represents clients in complex investigations by federal and state authorities, including the FCC, federal banking regulators, HHS OCR, NYDFS, and multistate attorneys general following data breaches and other types of cybersecurity and data privacy incidents.

Cybersecurity compliance and strategy

Advises clients in many sectors, including telecommunications, financial services, cloud computing and information technology, on compliance with federal, state and international information security and data privacy laws and standards, as well as federal and state procurement programs, including FedRAMP and CMMC.

Government investigations

Represented clients in complex investigations by federal and state authorities, including the FCC, federal banking regulators, HHS OCR, NYDFS, and multistate attorneys general related to data breaches, security incidents and cybersecurity and data privacy practices.

Complex breach response

Led investigations of and responses to numerous complex data breaches and data security incidents, including ransomware attacks, major business email compromise scams, supply-chain attacks, and state-sponsored hacking campaigns. 

CFIUS and international trade

Advised on development of data security policy to implement settlement with the Committee on Foreign Investment in the United States (CFIUS). Advised numerous clients in the financial services and information technology sectors on compliance with Department of Justice regulations restricting foreign access to Americans' sensitive personal data. 

Cyber preparedness

Led numerous tabletop exercises and advised clients on incident response and business continuity planning and policy development.

CFAA investigation*

Led technical investigation of web and network traffic for financial services company accused by competitor of web scraping in violation of the Computer Fraud and Abuse Act.
*Denotes an attorney's experience prior to joining Davis Wright Tremaine
Searching...

Admitted to Practice

  • Colorado, 2022
  • New York, 2011
  • District of Columbia, 2013

Education

  • J.D., Harvard Law School, 2010, cum laude
  • B.A., University of Notre Dame, 2005, magna cum laude

Memberships & Affiliations

    • Certified Information Privacy Professional/United States (CIPP/US), International Association of Privacy Professionals
    • Certified Information Privacy Manager (CIPM), International Association of Privacy Professionals
    • Certified Information Privacy Technologist (CIPT), International Association of Privacy Professionals

Professional Recognition

    • Named as one of the "Best Lawyers in America" by Best Lawyers in Media Law, 2025-present

Background

    • Vice President, Stroz Friedberg LLC, an Aon Company, Boston, 2018-2021
    • Legal Counsel, Cyber Security, Accenture LLP, Boston, 2016-2018
    • Associate, Jenner & Block LLP, Washington, D.C., 2012-2016
    • Judicial Law Clerk, Hon. Timothy J. Savage, U.S. District Court, Eastern District of Pennsylvania, Philadelphia, 2011-2012
Searching...
network of boxes
06.11.25
Insights
NSA Issues Cybersecurity Guidance and Best Practices for AI Systems Read More
Gavel and three-seat courtroom panel
05.16.25
Insights
5th Circuit Holds That Jarkesy Invalidates FCC Forfeiture Order Against AT&T Read More
Publications
05.01.25
News
Quoted in "New York's Latest Cyber Rules Pressure Small Companies, Vendors," Bloomberg Law Read More External Link
abstract digital grid
04.18.25
Insights
FedRAMP 20x Initiative Promises Major Changes for Federal Cloud Service Providers Read More
digital lock
04.15.25
Insights
DOJ Issues Guidance on Foreign Data Access Rule, Announces Conditional 90-Day Enforcement Pause for "Good Faith Efforts" Read More
Cybersecurity illustration with circuit patterns, padlock, cloud, globe, and binary code icons over a blurred office background.
04.09.25
Insights
Deadline Approaching: Covered Entities Must File Certifications of Compliance With Amended NYDFS Cyber Regulation by April 15 Read More
digital lock
03.20.25
Insights
Regulatory Reset? U.S. Cyber Incident Reporting Rules Face Congressional Scrutiny Read More
Ecommerce Online Pay Financial Services
03.07.25
Insights
PCI SSC Clarifies Obligations for Ecommerce Merchants That Outsource Payment Card Processing Read More
Webinar
02.27.25
Webinars
Privacy & Security
"Securing Americans' Sensitive Data: Understanding the DOJ's New Final Rule," Davis Wright Tremaine Webinar Read More
digital lock
02.04.25
Insights
Analyzing Biden's Ambitious Cyber EO—and What Comes Next Under Trump Read More
01.26.25
Presentations
Panelist, "When Not If: Data Breach Preparedness," Consumer Financial Services Committee Meeting 2025
digital shield
01.06.25
Insights
DOJ Issues Final Rule Targeting Foreign Access to Americans' Sensitive Data Read More
Your search returned no results. Please try another search or remove search criteria.
DWT logo
©1996-2025 Davis Wright Tremaine LLP. ALL RIGHTS RESERVED. Attorney Advertising. Not intended as legal advice. Prior results do not guarantee a similar outcome.
Media Kit Affiliations Legal notices
Privacy policy Employees DWT Collaborate EEO
SUBSCRIBE
©1996-2025 Davis Wright Tremaine LLP. ALL RIGHTS RESERVED. Attorney Advertising. Not intended as legal advice. Prior results do not guarantee a similar outcome.