CISO & CTOThe 2022 criminal conviction of Uber's former Chief Information Security Officer Joseph Sullivan marked a turning point in how courts, regulators, and boards view the personal legal accountability of security executives. This course uses U.S. v. Sullivan as a detailed case study, examining the specific facts, federal charges, jury verdict, and sentencing to draw out the legal principles that matter most for today's security leaders and the organizations they serve. Participants will gain a grounded understanding of the conduct the government found criminal, why the CISO rather than other executives bore personal liability, and what that precedent means for how security incidents are reported, escalated, and documented going forward. The course is designed to help organizations and their leadership teams make more informed decisions about governance structures, disclosure obligations, and the boundaries of a CISO's authority and accountability.
This course is most relevant for CISOs and security team leaders, board members, executives with incident-response oversight responsibilities, and legal advisors who counsel organizations on cybersecurity governance and breach disclosure.
None — designed for non-technical professionals, though a general familiarity with corporate incident response processes will be helpful.
1. CISO Criminal Liability: Understanding the US v. Joe Sullivan Trial
In this seminar, our expert panelists give a comprehensive overview of the U.S. v Joseph Sullivan case, beginning by introducing the facts of the case and explaining from a legal perspective the relevant technical information of the case. Next, our speakers discuss the charges against Mr. Sullivan and the issues considered in the case. Our speakers then review the ruling and provide observations about the outcome of the case, concluding with key takeaways about what this case means for criminal liability for CISOs. Topics covered in this webinar: CISO Criminal Liability: U.S. v. Joseph Sullivan Facts and Background Issues and Charges Ruling, Sentencing, and Observations Key Takeaways: Dispelling Cyber Criminal Liability Rumors
Free preview
CISO & CTO
CISO & CTOThis multi-part guidebook walks boards, CISOs, and their legal advisors through evolving regulatory responsibilities, fiduciary duties, and personal exposure, covering board-level cyber risk governance, SEC cybersecurity developments, the emerging criminal-liability landscape for CISOs, and practical guidance on CISO depositions.
CISO & CTOThis archive captures the 2023 beta cohort of Legal Cyber Academy's board-focused certificate program, delivered live over five weeks in September–October 2023 across six lectures organized into four modules covering cybersecurity fundamentals, regulatory oversight, risk management and incident response, and board oversight tools. The program prepared board members to understand core cybersecurity concepts, their individual responsibilities, and the regulatory landscape across SEC, FTC, NYDFS, and GDPR frameworks; core content and recordings are largely carried forward into the 2024 edition, with this beta distinguished by its live format, guest-speaker lineup, and supplemental materials.
Daniel B. Garrie