Cyber IncidentsLevel: Intermediate
Overview
The conviction of Uber's former Chief Information Security Officer in U.S. v. Joseph Sullivan marked a significant moment in how U.S. prosecutors approach the actions of senior security leaders following a data breach. This course walks through the facts of the case — including the 2016 breach, the subsequent concealment efforts, and the charges brought under federal obstruction and computer fraud statutes — and examines the reasoning behind the jury's verdict. Beyond the case itself, the course places the ruling in the broader context of regulatory obligations, breach disclosure requirements, and the accountability frameworks that now apply to CISOs and the organizations they serve. For executives, legal advisors, and security leaders, understanding what went wrong and why it resulted in criminal liability is essential for setting appropriate governance expectations going forward.
What you’ll learn
- ✓Explain the key facts, charges, and legal findings in U.S. v. Joseph Sullivan
- ✓Identify the specific actions that prosecutors argued crossed the line from incident response into obstruction
- ✓Distinguish between legitimate breach-management decisions and conduct that may give rise to criminal exposure
- ✓Describe the disclosure obligations that apply to organizations and security leaders following a data breach
- ✓Assess how this conviction affects the governance relationship between CISOs, executives, boards, and legal counsel
- ✓Recognize the organizational policies and communication practices that can help reduce personal and institutional liability after a breach
Skills you’ll gain
Explain the key facts, charges, and legal findings in U.S. v. Joseph SullivanIdentify the specific actions that prosecutors argued crossed the line from incident response into obstructionDistinguish between legitimate breach-management decisions and conduct that may give rise to criminal exposureDescribe the disclosure obligations that apply to organizations and security leaders following a data breachAssess how this conviction affects the governance relationship between CISOs, executives, boards, and legal counselRecognize the organizational policies and communication practices that can help reduce personal and institutional liability after a breach
Audience and prerequisites
Who this is for
This course is most relevant for CISOs and security teams, board members, executives, legal advisors, and cyber-insurance professionals who need to understand the personal and organizational liability implications of post-breach decision-making.
Prerequisites
None — designed for non-technical professionals, though security leaders with technical backgrounds will find the legal and governance analysis equally applicable to their roles.
Curriculum
1. Cybercrime and Punishment: Understanding U.S. v. Joseph Sullivan
In this seminar, our expert panelists give a comprehensive overview of the U.S. v Joseph Sullivan case, beginning by introducing the facts of the case and explaining from a legal perspective the relevant technical information of the case. Next, our speakers discuss the charges against Mr. Sullivan and the issues considered in the case. Our speakers then review the ruling and provide observations about the outcome of the case, concluding with key takeaways about what this case means for criminal liability for CISOs. Topics covered in this webinar: CISO Criminal Liability: U.S. v. Joseph Sullivan Facts and Background Issues and Charges Ruling, Sentencing, and Observations Key Takeaways: Dispelling Cyber Criminal Liability Rumors
Free preview Video coming soon