It’s never the data breach

The obstruction of justice and misprision of a felony charges levied against Joseph Sullivan, former Uber chief security officer (CSO), sent shock waves through the cybersecurity community. CSO and chief information security officers (CISOs) rightfully wondered what these charges mean in terms of their own culpability for decisions made on the job.
CSOs and CISOs handle sensitive data, make difficult decisions, and consider their responsibility to the company and its shareholders when making those decisions. Legal, regulatory, and privacy issues also feature heavily in these decisions.
The narrative in the charging documents (Note: This is not yet a criminal indictment) issued by the FBI against Uber’s former CSO (Sullivan) paints him as actively masterminding and executing a plan to cover up a major data breach, obstruct federal regulators, and conceal activity from senior executives.
A data breach in 2014 exposed the records of 50,000 Uber drivers. In 2016, the Federal Trade Commission (FTC) investigated Uber for the 2014 data breach. Approximately 10 days after Sullivan provided sworn testimony to the FTC, he learned of a second data breach involving similar records but on a much larger scale. This time, the breach included millions of records. Uber and Sullivan cooperated with investigators, and the hackers were caught and charged.
According to the charging document, Sullivan, former Uber CEO Travis Kalanick, and others took the following steps after learning of the 2016 data breach:
In November 2016, Uber learned of a data breach. Hackers threatened to expose the stolen data. Uber paid a ransom to the hackers under its bug bounty program and made the hackers sign NDAs to avoid the breach becoming public knowledge.
Sullivan did not inform the FTC during the sworn investigative hearing because he couldn’t have: Sullivan learned of the 2016 breach 10 days later. To inform the FTC, Sullivan would have needed to reach out and inform them about a separate, new, but similar breach. There’s also some confusion as to whether Sullivan was under any legal obligation to do so.
Sullivan briefed the new CEO in 2017 but did not provide the details necessary for the new executive. This is not necessarily surprising since communication between senior security leaders and senior executives remains a challenge.
This version of the facts matches the case laid out in the charging documents but does so by examining the decisions without viewing them as linked to criminal activity. If this case goes to trial, Sullivan’s attorneys will have a chance to offer their own version of events.
Sullivan is innocent until proven guilty. But regardless of the outcome, for CISOs, there’s a critical lesson here. You must consider how decisions made in the moment can be interpreted, construed, or proven to be criminal after the fact.


