WSGR logoWSGR logo
WSGR logo
  • Experience
  • People
  • Insights
  • About Us
  • Careers

  • Practice Areas
  • Industries

  • Corporate
  • Intellectual Property
  • Litigation
  • Patents and Innovations
  • Regulatory
  • Technology Transactions

  • Capital Markets
  • Corporate Governance
  • Corporate Life Sciences
  • Derivatives
  • Emerging Companies and Venture Capital
  • Employee Benefits and Compensation
  • Energy and Climate Solutions
  • Executive Advisory Program
  • Finance and Structured Finance
  • Fund Formation
  • Greater China
  • Mergers & Acquisitions
  • Private Equity
  • Public Company Representation
  • Real Estate
  • Restructuring
  • Shareholder Engagement and Activism
  • Tax
  • U.S. Expansion
  • Wealthtech

  • Special Purpose Acquisition Companies (SPACs)

  • Environmental, Social, and Governance

  • AI and Data Center Infrastructure
  • Energy Regulation and Competition
  • Project Development and M&A
  • Project Finance and Tax Credit Transactions
  • Sustainability and Decarbonization
  • Transportation Electrification

  • U.S. Expansion Library and Resources

  • Post-Grant Review
  • Trademark and Advertising

  • Antitrust Litigation
  • Arbitration
  • Board and Internal Investigations
  • Class Action Litigation
  • Commercial Litigation
  • Consumer Litigation
  • Corporate Governance Litigation
  • Employment Litigation
  • Executive Branch Updates
  • Government Investigations
  • Internet Strategy and Litigation
  • Patent Litigation
  • Securities Litigation
  • State Attorneys General
  • Supreme Court and Appellate Practice
  • Trade Secret Litigation
  • Trademark and Copyright Litigation
  • Trial
  • White Collar Crime

  • Advertising, Promotions, and Marketing
  • Antitrust and Competition
  • Committee on Foreign Investment in the U.S. (CFIUS)
  • Communications
  • Data, Privacy, and Cybersecurity
  • Export Control and Sanctions
  • FCPA and Anti-Corruption
  • FDA Regulatory, Healthcare, and Consumer Products
  • Federal Trade Commission
  • Fintech and Financial Services
  • Government Contracts
  • National Security and Trade
  • Payments
  • State Attorneys General
  • Strategic Risk and Crisis Management
  • Tariffs, Customs, and Import Compliance

  • Antitrust and Intellectual Property
  • Antitrust Civil Enforcement
  • Antitrust Compliance and Business Strategy
  • Antitrust Criminal Enforcement
  • Antitrust Litigation
  • Antitrust Merger Clearance
  • European Competition Law
  • Third-Party Merger and Non-Merger Antitrust Representation

  • Anti-Money Laundering
  • Foreign Ownership, Control, or Influence (FOCI)
  • Team Telecom

  • AI in Healthcare
  • Animal Health
  • Artificial Intelligence and Machine Learning
  • Aviation
  • Biotech
  • Blockchain and Cryptocurrency
  • Clean Energy
  • Climate and Clean Technologies
  • Communications and Networking
  • Consumer Products and Services
  • Data Storage and Cloud
  • Defense Tech
  • Diagnostics, Life Science Tools, and Deep Tech
  • Digital Health
  • Digital Media and Entertainment
  • Electronic Gaming
  • Fintech and Financial Services
  • FoodTech and AgTech
  • Global Generics
  • Internet
  • Life Sciences
  • Medical Devices
  • Mobile Devices
  • Mobility
  • NewSpace
  • Quantum Computing
  • Semiconductors
  • Software

  • Offices
  • Country Desks
  • Events
  • Community
  • Our Diversity
  • Sustainability
  • Our Values
  • Board of Directors
  • Management Team

  • Austin
  • Boston
  • Boulder
  • Brussels
  • Century City
  • Hong Kong
  • London
  • Los Angeles
  • New York
  • Palo Alto
  • Salt Lake City
  • San Diego
  • San Francisco
  • Seattle
  • Shanghai
  • Washington, D.C.
  • Wilmington, DE

  • Law Students
  • Judicial Clerks
  • Experienced Attorneys
  • Patent Agents
  • Business Professionals
  • Alternative Legal Careers
  • Contact Recruiting
Demian Ahn
Partner
Data, Privacy, and Cybersecurity
Washington, D.C.
dahn@wsgr.com

D202-255-0937

Download vCard
Open PDF
  • Cyber & AI Incident Response and Crisis Management

    Demian represents clients through times of crisis, helping them respond to cyber, AI, online safety, insider threat, and whistleblower incidents, as well as a variety of other threats to the technology stack. He leads incident response and crisis management teams, manages internal and forensic investigations, and provides strategic advice concerning communications and disclosures.

  • Deep Experience Investigating and Defending Sensitive Matters

    Demian has 20 years of experience conducting and defending high-stakes government investigations and litigating cases before both trial and appellate courts. He served as a federal prosecutor in the U.S. Attorney’s Office for the District of Columbia, ending his federal career as a Deputy Chief of the Fraud Section (2021-2022), where he conducted and supervised innovative and high-impact investigations involving nation-state cyber threat actors, organized identity theft and cybercrime rings, cyber-enabled fraud and harassment, export control violations, health care fraud, and corporate and consumer fraud. He represents companies in connection with investigations by federal and state regulators, including DOJ, HHS, DoD, the FTC, the SEC, state attorneys general and departments of insurance, and inspector generals.

  • A Recognized Cyber and National Security Practitioner

    Demian regularly speaks about and presents on emerging technology risks and regulations and is a regular contributor to the WSGR Data Advisor. He has been named as one of the “Incident Response 50” by Cybersecurity Docket and one of Lawdragon’s 500 Leading Global Cyber Lawyers, and he received numerous awards for outstanding service as a prosecutor, including from the Federal Bureau of Investigation (2018 and 2021) and the U.S. Department of State (2022) for “elite” national security cyber expertise and “exceptional prosecutorial support and relentless efforts in combatting cyber threats” against the United States.

  • Practical Guidance for Start-Ups and Multinationals

    Demian advises companies that develop, deploy, and operate emerging technologies, providing practical guidance about rapidly changing regulations involving privacy, cybersecurity, online safety, and artificial intelligence (AI). He has extensive experience helping emerging companies develop and implement data privacy, content moderation, security, and AI governance and risk management programs, helping large and complex organizations adapt to significant regulatory shifts, and advising companies as they build internal governance structures, engage in partnerships with third parties, and engage in strategic corporate transactions.

Demian Ahn is a member of the firm’s data, privacy, and cybersecurity practice based in Washington, D.C. He leads the firm’s incident response practice and advises companies on compliance, regulatory, and crisis management matters relating to emerging technologies of all kinds.

Incident Response and Crisis Management. Demian advises companies in connection with cyber, privacy, AI, and online safety incidents, as well as insider threat events and allegations by purported whistleblowers and others. He leads incident response and crisis management teams, manages internal investigations, and advises companies on external communications and disclosures. During his federal career, Demian led investigations and supported incident response relating to data breaches at U.S. government agencies and led complex criminal investigations responding to crisis situations involving terrorism, cybercrime, and violent crime. At Wilson Sonsini, Demian leads incident response teams responding to cyber incidents and crisis management matters relating to AI, health, financial services, online platform, cloud computing and SaaS, defense, and security companies.

Internal Investigations and Regulatory Defense. Demian represents clients in connection with cybersecurity, privacy, and AI-related investigations by federal and state regulators, including the Department of Health and Human Services, Federal Trade Commission, Securities and Exchange Commission, Department of Justice, Department of Defense, and state attorneys general, as well as state financial regulators such as the New York Department of Financial Services. Demian also has extensive experience conducting, supporting, and leading sensitive internal investigations on a broad range of matters, including insider threat investigations, whistleblower claims, misappropriation of intellectual property, employee misconduct, alleged securities and financial fraud, health care fraud, and matters pertaining to the False Claims Act.

Cyber and AI Governance and Compliance. Demian advises clients on legal and regulatory compliance related to technology-driven products and services. He helps companies of all sizes navigate complex privacy, security, and AI-related regulations and requirements, including HIPAA, GLBA, NYDFS, PADFAA, the Take it Down Act, and the REPORT Act; government contracting regulations, including CMMC, DFARS, FedRAMP, CJIS; and laws and regulations pertaining to web scraping, data access, child safety, illegal content, and content moderation. Demian also advises companies on compliance as they explore IPOs and M&A transactions, and in connection with SEC reporting and corporate governance matters.

National Security, Surveillance, and Computer Intrusion Laws. As a Computer Hacking and Intellectual Property Prosecutor and National Security-Cyber Specialist, Demian gained extensive experience working with threat intelligence and security experts across the federal government and private industry. He conducted corporate investigations involving security researchers and cybersecurity-related export control violations, including a precedent-setting investigation into former U.S. intelligence officials who provided services to a foreign government. Now, in private practice, Demian advises surveillance and security companies on legal and regulatory compliance, including with respect to the Computer Fraud and Abuse Act, the Wiretap Act, U.S. sanctions and money laundering laws, security research on the dark web, and the Department of Justice’s Data Security Program.

Prior to joining the Department of Justice, Demian worked at a prominent multinational law firm, where he represented clients in high-stakes litigation and investigations, including matters before Congress, federal and state regulatory bodies, and federal and state trial and appellate courts.

Immediately following law school, Demian clerked for the Honorable Frederick J. Martone of the U.S. District Court for the District of Arizona. During law school, he also served as a law clerk for the South African Human Rights Commission in Durban, South Africa.

Experience

Demian Ahn is a member of the firm’s data, privacy, and cybersecurity practice based in Washington, D.C. He leads the firm’s incident response practice and advises companies on compliance, regulatory, and crisis management matters relating to emerging technologies of all kinds.

Incident Response and Crisis Management. Demian advises companies in connection with cyber, privacy, AI, and online safety incidents, as well as insider threat events and allegations by purported whistleblowers and others. He leads incident response and crisis management teams, manages internal investigations, and advises companies on external communications and disclosures. During his federal career, Demian led investigations and supported incident response relating to data breaches at U.S. government agencies and led complex criminal investigations responding to crisis situations involving terrorism, cybercrime, and violent crime. At Wilson Sonsini, Demian leads incident response teams responding to cyber incidents and crisis management matters relating to AI, health, financial services, online platform, cloud computing and SaaS, defense, and security companies.

Internal Investigations and Regulatory Defense. Demian represents clients in connection with cybersecurity, privacy, and AI-related investigations by federal and state regulators, including the Department of Health and Human Services, Federal Trade Commission, Securities and Exchange Commission, Department of Justice, Department of Defense, and state attorneys general, as well as state financial regulators such as the New York Department of Financial Services. Demian also has extensive experience conducting, supporting, and leading sensitive internal investigations on a broad range of matters, including insider threat investigations, whistleblower claims, misappropriation of intellectual property, employee misconduct, alleged securities and financial fraud, health care fraud, and matters pertaining to the False Claims Act.

Cyber and AI Governance and Compliance. Demian advises clients on legal and regulatory compliance related to technology-driven products and services. He helps companies of all sizes navigate complex privacy, security, and AI-related regulations and requirements, including HIPAA, GLBA, NYDFS, PADFAA, the Take it Down Act, and the REPORT Act; government contracting regulations, including CMMC, DFARS, FedRAMP, CJIS; and laws and regulations pertaining to web scraping, data access, child safety, illegal content, and content moderation. Demian also advises companies on compliance as they explore IPOs and M&A transactions, and in connection with SEC reporting and corporate governance matters.

National Security, Surveillance, and Computer Intrusion Laws. As a Computer Hacking and Intellectual Property Prosecutor and National Security-Cyber Specialist, Demian gained extensive experience working with threat intelligence and security experts across the federal government and private industry. He conducted corporate investigations involving security researchers and cybersecurity-related export control violations, including a precedent-setting investigation into former U.S. intelligence officials who provided services to a foreign government. Now, in private practice, Demian advises surveillance and security companies on legal and regulatory compliance, including with respect to the Computer Fraud and Abuse Act, the Wiretap Act, U.S. sanctions and money laundering laws, security research on the dark web, and the Department of Justice’s Data Security Program.

Prior to joining the Department of Justice, Demian worked at a prominent multinational law firm, where he represented clients in high-stakes litigation and investigations, including matters before Congress, federal and state regulatory bodies, and federal and state trial and appellate courts.

Immediately following law school, Demian clerked for the Honorable Frederick J. Martone of the U.S. District Court for the District of Arizona. During law school, he also served as a law clerk for the South African Human Rights Commission in Durban, South Africa.

Education
  • J.D., University of Michigan Law School
  • B.A., Cornell University
Honors
  • Named to the 2025 "Incident Response 50" and 2026 “Incident Response Elite” by Cybersecurity Docket
  • Selected for inclusion in the 2025-2026 editions of Lawdragon’s "500 Leading Global Cyber Lawyers" guide
Admissions
  • Bar of the District of Columbia
Credentials
Education
  • J.D., University of Michigan Law School
  • B.A., Cornell University
Honors
  • Named to the 2025 "Incident Response 50" and 2026 “Incident Response Elite” by Cybersecurity Docket
  • Selected for inclusion in the 2025-2026 editions of Lawdragon’s "500 Leading Global Cyber Lawyers" guide
Admissions
  • Bar of the District of Columbia

Select Publications

  • Co-author, “Department of Defense Issues Final Rule on Cybersecurity Maturity Model Certification Program for Its Contracts,” Wilson Sonsini Alert, September 12, 2025

  • Co-author, “White House Releases America’s AI Action Plan,” Wilson Sonsini Alert, July 25, 2025
  • Co-author, “The Busy Lawyer's Guide to the New "Data Export Control" Rules,” Wilson Sonsini Alert, February 4, 2025
  • Co-author, “Ransomware Attacks: UK Government Proposes Ransom Payment Ban and Mandatory Notification Requirements,“ Wilson Sonsini Alert, January 24, 2025
  • Co-author, “Not Just for DoD Anymore: New Proposed CUI Rule to Apply to All Federal Contractors,“ Wilson Sonsini Alert, January 23, 2025
  • Co-author, “HHS-OCR Announces Proposed Modifications to the HIPAA Security Rule,” Wilson Sonsini Alert, January 14, 2025
  • Co-author, “New Year, New Developments: 2025 U.S. Privacy, Cybersecurity, and Consumer Protection Predictions,” Wilson Sonsini Alert, January 7, 2025

  • Co-author, “Cybersecurity: A Critical Element in Your 2025 Business Forecast,” Wilson Sonsini Alert, September 30, 2024
  • Co-author, “SEC Expands Security and Breach Notification Requirements for Investment Firms,” Wilson Sonsini Alert, May 30, 2024
  • Co-author, “New Minor Safety Obligations for Online Services: REPORT Act Expands Child Sexual Exploitation Reporting Requirements,” Wilson Sonsini Alert, May 10, 2024
  • Co-author, “New Executive Order Restricts Certain Cross-Border Transactions Involving Sensitive Personal Data of U.S. Citizens,” Wilson Sonsini Alert, March 6, 2024
  • Co-author, “Cybersecurity: What to Watch for in 2024,” Wilson Sonsini Alert, January 3, 2024
  • Co-author, “FBI, DOJ, and SEC Provide Guidance and Requirements for Requests to Delay Form 8-K Disclosures for Material Cybersecurity Incidents,” Wilson Sonsini Alert, December 15, 2023
  • Co-author, “FTC Amends Safeguard Rule with Requirement for Non-Banking Financial Institutions to Report Data Security Breaches,” Wilson Sonsini Alert, November 6, 2023
  • Co-author, “SEC Adopts Cybersecurity Disclosure Rules for Public Companies,” Wilson Sonsini Alert, August 1, 2023
  • Co-author, “Executive Order 14028 Update: OMB Clarifies Cybersecurity Guidance for Federal Contractors; Delays Secure Software Attestation Requirement,” Wilson Sonsini Alert, June 30, 2023
  • Co-author, “SEC Adjusts Anticipated Action Date for Publication of Final Rules for Cybersecurity Reporting and Enhanced Standardized Disclosure,” Wilson Sonsini Alert, June 29, 2023
  • Co-author, “White House Releases National Cybersecurity Strategy: Key Takeaways for the Private Sector,” Wilson Sonsini Alert, March 14, 2023
  • Co-author, “DoD to Contracting Officers: Demand Compliance and Seek Consequences for Material Breaches of Cybersecurity Requirements by Contractors,” Wilson Sonsini Alert, August 08, 2022
  • Co-author, “DOJ Acknowledges Limits to the CFAA, but Questions (and Possible Civil Liability) Remain for Security Researchers and Others,” Wilson Sonsini Alert, May 25, 2022

Select Speaking Engagements

  • Panelist, “Data Privacy Compliance: Pre-Attack Risk Mitigation and Post-Attack Best Practices,” Incident Response Forum Masterclass 2024, April 18, 2024
Insights

Select Publications

  • Co-author, “Department of Defense Issues Final Rule on Cybersecurity Maturity Model Certification Program for Its Contracts,” Wilson Sonsini Alert, September 12, 2025

  • Co-author, “White House Releases America’s AI Action Plan,” Wilson Sonsini Alert, July 25, 2025
  • Co-author, “The Busy Lawyer's Guide to the New "Data Export Control" Rules,” Wilson Sonsini Alert, February 4, 2025
  • Co-author, “Ransomware Attacks: UK Government Proposes Ransom Payment Ban and Mandatory Notification Requirements,“ Wilson Sonsini Alert, January 24, 2025
  • Co-author, “Not Just for DoD Anymore: New Proposed CUI Rule to Apply to All Federal Contractors,“ Wilson Sonsini Alert, January 23, 2025
  • Co-author, “HHS-OCR Announces Proposed Modifications to the HIPAA Security Rule,” Wilson Sonsini Alert, January 14, 2025
  • Co-author, “New Year, New Developments: 2025 U.S. Privacy, Cybersecurity, and Consumer Protection Predictions,” Wilson Sonsini Alert, January 7, 2025

  • Co-author, “Cybersecurity: A Critical Element in Your 2025 Business Forecast,” Wilson Sonsini Alert, September 30, 2024
  • Co-author, “SEC Expands Security and Breach Notification Requirements for Investment Firms,” Wilson Sonsini Alert, May 30, 2024
  • Co-author, “New Minor Safety Obligations for Online Services: REPORT Act Expands Child Sexual Exploitation Reporting Requirements,” Wilson Sonsini Alert, May 10, 2024
  • Co-author, “New Executive Order Restricts Certain Cross-Border Transactions Involving Sensitive Personal Data of U.S. Citizens,” Wilson Sonsini Alert, March 6, 2024
  • Co-author, “Cybersecurity: What to Watch for in 2024,” Wilson Sonsini Alert, January 3, 2024
  • Co-author, “FBI, DOJ, and SEC Provide Guidance and Requirements for Requests to Delay Form 8-K Disclosures for Material Cybersecurity Incidents,” Wilson Sonsini Alert, December 15, 2023
  • Co-author, “FTC Amends Safeguard Rule with Requirement for Non-Banking Financial Institutions to Report Data Security Breaches,” Wilson Sonsini Alert, November 6, 2023
  • Co-author, “SEC Adopts Cybersecurity Disclosure Rules for Public Companies,” Wilson Sonsini Alert, August 1, 2023
  • Co-author, “Executive Order 14028 Update: OMB Clarifies Cybersecurity Guidance for Federal Contractors; Delays Secure Software Attestation Requirement,” Wilson Sonsini Alert, June 30, 2023
  • Co-author, “SEC Adjusts Anticipated Action Date for Publication of Final Rules for Cybersecurity Reporting and Enhanced Standardized Disclosure,” Wilson Sonsini Alert, June 29, 2023
  • Co-author, “White House Releases National Cybersecurity Strategy: Key Takeaways for the Private Sector,” Wilson Sonsini Alert, March 14, 2023
  • Co-author, “DoD to Contracting Officers: Demand Compliance and Seek Consequences for Material Breaches of Cybersecurity Requirements by Contractors,” Wilson Sonsini Alert, August 08, 2022
  • Co-author, “DOJ Acknowledges Limits to the CFAA, but Questions (and Possible Civil Liability) Remain for Security Researchers and Others,” Wilson Sonsini Alert, May 25, 2022

Select Speaking Engagements

  • Panelist, “Data Privacy Compliance: Pre-Attack Risk Mitigation and Post-Attack Best Practices,” Incident Response Forum Masterclass 2024, April 18, 2024
Focus Areas
  • Artificial Intelligence and Machine Learning
  • Board and Internal Investigations
  • Data, Privacy, and Cybersecurity
  • Government Investigations
  • National Security and Trade
  • State Attorneys General
  • Strategic Risk and Crisis Management
Recent Insights
Alerts
"Shadow AI" Triggers First SEC Form 8-K for Unauthorized AI Use: What Financial Institutions and Public Companies Need to Know
Key Takeaways
Learn More
News Articles
Wilson Sonsini Attorneys Named to 2026 Lawdragon Leading Global Cyber Lawyers Guide
On May 8, 2026, Lawdragon announced its 2026 Lawdragon 500 Leading Global Cyber Lawyers guide, recognizing world leaders in privacy, data, security, and incident response, as well as the deals and lawsuits that revolve around all things cyber. The Wilson Sonsini attorneys named to the list included:
Learn More
View All
Recent Events
Affiliated Programs
Incident Response Forum D.C. 2026
On April 22, 2026, Wilson Sonsini partner Demian Ahn will join fellow experienced panelists for the discussion, "The New Administration and Cyber: A Year in Review" at Cybersecurity Docket’s Incident Response Forum D.C. 2026. The panel will discuss current cybersecurity landscape, as well as changes made and still expected by this current administration.
Learn More
WSGR Events
RSA Cybersecurity Conference Networking Mixer
On March 25th, Wilson Sonsini is hosting an invite-only networking evening during RSA 2026.
Learn More
View All
  • people
  • insights
  • about us
  • careers
  • Binder
  • Alumni
  • Mailing List Signup
  • Client FTP Portal
  • Privacy Policy
  • Terms of Use
  • Accessibility
WSGR logo
Twitter
LinkedIn
Facebook
Instagram
Youtube
Copyright © 2026 Wilson Sonsini Goodrich & Rosati. All Rights Reserved.