CISO Personal Liability After US v. Sullivan: What Lawyers Must Know
The Legal Landscape Has Shifted for Security Executives
The criminal conviction of Joseph Sullivan, Uber's former Chief Information Security Officer, marked a watershed moment in cybersecurity law. For the first time, a corporate security executive was held personally criminally liable—not for the breach itself, but for decisions made in its aftermath. For lawyers advising C-suite clients, boards, or companies navigating incident response, understanding the Sullivan precedent is no longer optional.
This article breaks down the key legal theories at play, the compliance obligations implicated, and the practical steps counsel should take to protect clients operating in CISO and adjacent executive roles.
What Happened in US v. Sullivan
In 2016, Uber experienced a significant data breach affecting millions of users and drivers. Sullivan, then serving as Uber's CISO, oversaw a response strategy that included paying the attackers approximately $100,000 through Uber's bug bounty program and requiring them to sign nondisclosure agreements. Critically, the breach was not reported to the Federal Trade Commission—an agency that was, at the time, actively investigating Uber's data security practices.
Sullivan was subsequently charged and convicted of obstruction of proceedings before the FTC and misprision of a felony (concealing a known felony from authorities). He was sentenced to three years of probation.
The conduct at issue was not hacking. It was the deliberate concealment of a known incident from a regulator already engaged in oversight of the company's security practices.
Core Legal Theories Counsel Must Understand
Obstruction of Agency Proceedings
Federal obstruction statutes extend beyond courts and grand juries. The Sullivan prosecution confirmed that ongoing regulatory investigations—including FTC civil investigations—can serve as the predicate proceeding for obstruction charges. If a client is under regulatory scrutiny at the time of a breach, every incident response decision is made in the shadow of that oversight.
Key counseling point: When a client faces both a cyber incident and an open regulatory matter, legal hold obligations and disclosure duties intersect in ways that require immediate, coordinated legal guidance.
Misprision of a Felony
Misprision under 18 U.S.C. § 4 requires that a person have knowledge of a felony, take an affirmative step to conceal it, and fail to report it to authorities. Sullivan's use of NDAs and the bug bounty mechanism was treated as the affirmative concealment step. This is an important distinction: silence alone is generally insufficient for misprision liability, but taking any active measure to suppress information may satisfy the concealment element.
Wire Fraud and Computer Fraud Exposure
While not central to the Sullivan verdict, prosecutors and civil plaintiffs have increasingly layered wire fraud and Computer Fraud and Abuse Act theories into breach-related litigation. Lawyers should anticipate that creative charging decisions in future cases may draw on Sullivan as persuasive authority for executive-level accountability.
Why CISOs Are Now Uniquely Exposed
Historically, personal liability in the corporate context attached most readily to financial fraud—think Sarbanes-Oxley certifications by CFOs and CEOs. The CISO role carried operational responsibility without equivalent legal exposure.
Sullivan changed that calculus in several ways:
- CISOs now own disclosure decisions at many organizations, even where legal or compliance teams share responsibility. Regulators and prosecutors will look to whoever functionally controlled the response.
- Regulatory disclosure timelines are compressing. The SEC's cybersecurity disclosure rules (effective 2023) impose strict materiality and timing requirements on public companies. State breach notification laws, HIPAA, and sector-specific rules add further layers. A CISO who delays or shapes disclosures to avoid reputational harm creates criminal and civil exposure.
- Indemnification and D&O coverage have limits. Most directors and officers policies exclude intentional misconduct and criminal acts. If a CISO's conduct is characterized as deliberate concealment, coverage may be unavailable precisely when it is most needed.
Practical Guidance for Lawyers Advising CISOs and Organizations
1. Clarify Decision-Making Authority Before an Incident
Advise clients to establish—in writing—who has authority over incident response decisions, particularly disclosure determinations. A CISO who acts unilaterally, or who fails to escalate to legal counsel and the board, assumes personal risk that could otherwise be distributed across the organization's governance structure.
2. Engage Counsel at the Earliest Sign of a Significant Incident
Attorney-client privilege and work product protection are most robust when counsel is involved from the outset of an investigation. Post-incident forensic reports commissioned through counsel may be protected; those commissioned operationally by IT or security teams often are not.
3. Audit Disclosure Obligations Proactively
Organizations subject to SEC rules, FTC jurisdiction, HIPAA, state breach notification laws, or sector-specific regimes (banking, energy, healthcare) face overlapping and sometimes inconsistent timelines. Lawyers should map these obligations in advance so that when an incident occurs, the compliance framework is already understood.
4. Review Indemnification Agreements and Insurance Coverage
Counsel representing CISOs individually—not just the company—should review employment agreements for indemnification scope, advancement of legal fees provisions, and the interaction with any D&O or cyber liability policy. Personal counsel is appropriate where the company's interests and the executive's interests may diverge.
5. Train Clients on What Constitutes "Concealment"
Sullivan illustrates that well-intentioned business decisions—using a bug bounty program, requiring an NDA—can be recharacterized as criminal concealment in the right (or wrong) fact pattern. Counsel should advise security executives and their teams that any payment or agreement with threat actors during an active regulatory inquiry requires legal sign-off.
The Evolving Standard of Care
Regulators, courts, and prosecutors are coalescing around a consistent message: cybersecurity is a governance issue, not merely a technical one, and executives will be held to the standard of care appropriate to their role. The SEC's rules now require companies to disclose material cybersecurity incidents and to describe management's role in cybersecurity oversight. The FTC has signaled continued attention to deceptive or unfair security practices.
For legal professionals, the takeaway is straightforward. The CISO is no longer insulated by technical complexity or organizational hierarchy. Counsel who understand the intersection of incident response, regulatory disclosure, and personal criminal exposure will be indispensable to the executives and companies navigating this terrain.
Bottom Line
US v. Sullivan is not an anomaly. It is a signal. Prosecutors have demonstrated both the willingness and the legal theory to pursue individual security executives for conduct that goes beyond negligence into deliberate concealment. Lawyers who advise companies, boards, and C-suite executives must integrate this reality into every engagement that touches data security governance, incident response planning, and regulatory compliance.