A US federal court jury finds ex-Uber Chief Security Officer Joe Sullivan guilty for not disclosing a 2016 breach of customer and driver records to regulators
A jury found Joe Sullivan, who led security at the ride-hailing company, guilty on two different counts.
New York TimesCade Metz
Context & Ripple Effects
The verdict resolves a case that had moved from obstruction charges over the concealed breach to a judge’s decision that Sullivan had to stand trial on wire-fraud allegations. His defense had argued that Uber made him a scapegoat after Travis Kalanick’s exit, making the jury’s finding a clear rejection of that account.
The case had already drawn attention from security leaders who saw it as a test of personal criminal exposure for CSOs when breach response and regulatory disclosure overlap. The conviction turns that professional concern from a pending legal question into an immediate governance issue.
First-order effects
Joe Sullivan is convicted on two counts, creating direct personal liability for Uber’s former security chief over the handling of the 2016 incident.
Security executives now have a concrete federal-jury outcome to weigh when deciding how breach findings and regulator communications are documented and escalated.
Second-order effects
Companies employing CSOs face greater pressure to define who owns disclosure decisions, because a dispute over whether an executive acted for the company can now carry individual criminal consequences.
Boards and legal teams are likely to become more involved in breach-response records and regulator-facing decisions, reducing the latitude of security teams to resolve incidents internally.
Third-order effects
If this outcome becomes a durable reference point, cybersecurity leadership shifts further from a purely technical function toward a regulated executive role with explicit personal accountability for disclosure conduct.
The trend: Cybersecurity leaders are being held to more formal accountability for how organizations disclose and govern major security incidents, not only for preventing them.
This Uber verdict really is going to destroy CISO positions. If one can brief legal, obtain approval by the CEO, & still be hung out to dry for response actions that a hundred other firms have likely taken with far less structural cover, then there can't be enough $$ to sign on
A lot of people are conflating legal issues when discussing the Joe Sullivan/Uber - be careful of the red herrings. It's not about breach notification, it's not about bug bounties—it's about lying to a regulator about information responsive to an open investigation and subpoena.
Our updated story quotes stunned security pros who had already thought their jobs were nerve-wracking without the threat of prosecution. https://www.washingtonpost.com/ ...
Hey CISO! Is your company under investigation and under obligation to turn over responsive documentation related to security practices? No? Then this doesn't affect you. Yes? Don't lie. Be truthful in your documentation and work closely with in house counsel on everything. https:…
Agreed, though I do have questions about why the feds decided to go after Joe Sullivan alone. Seems to me there could have been at least three potential defendants, but Sullivan was the only person indicted. https://twitter.com/...
not in Europe :D paying a “bug bounty” after a hack for stolen PII is not compatible with GDPR for a variety of reasons, so the CEO and legal couldn't sign this kind of thing off. https://twitter.com/...
If you're a CISO and you're worried the Sullivan case might put a chill on future efforts to conceal thefts of customer data from coming to the knowledge of said customers, uh... Well, yes. That's almost certainly a kind of wrongdoing the feds are trying to deter here. 🤷
The press coverage on the Joe Sullivan/Uber outcome is driving me nuts. They're sinking their teeth into a bunch of red herring issues that will drive panic in the security community. https://twitter.com/...
Former Uber CISO Joe Sullivan has been convicted. As expected. Given that he's a former federal prosecutor, my first guess would be that a federal judge won't be too inclined toward leniency at sentencing. He betrayed the law. And his oath.
People keep taking the wrong lesson away from the Uber CISO case. The primary lesson is not to mislead FTC regulators when they're investigating you. The main company that has to worry about this next is Twitter if Mudge's allegations turn out to be true. https://twitter.com/...