Site navigation

The Joe Sullivan Case Highlights Importance of Transparency in Cyber

Ross Kelly

,

Uber Court Case
The trial could set an important precedent for senior security practitioners.

Former Uber chief security officer, Joe Sullivan, has been found guilty of criminal obstruction after it was ruled he failed to report a major cybersecurity incident to regulators.

After a high-profile trial, a San Francisco jury found Sullivan guilty on two counts – obstructing justice and deliberately concealing a felony.

Initially, the security chief also faced three counts of wire fraud. However, these charges were dropped by prosecutors in August.

Sullivan was brought to trial for his role in a major data breach which saw information belonging to more than 57 million passengers and staff exposed.

Information leaked in the incident included names, email addresses and phone numbers belonging to millions of customers and employees. Driver’s license information pertaining to more than half-a-million drivers was also exposed.

Withholding Information

Despite occurring in 2016, Uber failed to publicly disclose the security incident for around a year. The company’s failure to inform relevant authorities sparked major inquiries at both state and federal level, and eventually resulted in Uber paying $148m to settle a litany of claims.

In 2020, the US Justice Department filed criminal charges against Sullivan amidst allegations that he attempted to pay hackers $100,000 in cryptocurrency and sign nondisclosure agreements to prevent the incident from being made public.

Sullivan was also accused of withholding vital information on the breach from Uber officials, as well as the Federal Trade Commission (FTC) – which at the time was investigating a previous breach in 2014.

Commenting on the ruling, Stephanie Hinds, US attorney for the northern district of California said: “Sullivan affirmatively worked to hide the data breach from the Federal Trade Commission (FTC) and took steps to prevent the hackers from being caught.”

Throughout the trial, Sullivan’s lawyers had argued that the security chief had taken these actions to prevent the exposure of user data. Similarly, the defence also claimed that Uber’s CEO and a host of other executives were aware of the incident.

In a statement given to the New York Times, Sullivan’s lawyer David Angeli said: “Mr. Sullivan’s sole focus – in this incident and throughout his distinguished career – has been ensuring the safety of people’s personal data on the internet.”


A practitioner’s perspective on the Uber court case

The Uber court case has been watched closely by many in the cybersecurity community, with some going so far as to claim he has been “scapegoated” by executives at the ride-hailing giant.

Nonetheless, it could set an important precedent for those working in InfoSec as it represents the first time a security executive has been held liable for an incident of this kind.

Speaking to DIGIT, Check Point CISO and C-suite Advisor, Deryck Mitchelson, described the verdict as “surprising” but suggested it might make cyber leaders “raise their game around data privacy and transparency”.

Similarly, Mitchelson said the incident will emphasise the importance of cyber-risk at a board level and shed light on the critical role that security practitioners play at organisations globally.

He explained: “It should reinforce the need for cyber to be owned by the board, and for the cyber message to be relayed in clear business risk language. Boards may decide to accept the risk, but it is essential they understand impact and probability.

“Cybersecurity is regularly the top business risk, and our professionals need backing to deliver the resilience needed for successful business continuity. Every incident should raise awareness of the amazing job that they do.”


Recommended


Mitchelson also warned that incidents such as the Uber breach harm public confidence in business. As such, this verdict and the threat of legal accountability might alleviate public fears over how data is handled in the future.

He added: “There are a small number of huge digital and social organisations who hold and process our data. The public needs to push for much more transparency around any incidents – they shouldn’t be covered up, such as in this case. That is what lowers confidence.

“Regulation around reporting is critical here to hold organisations to account. The CISO role should be accountable, but that responsibility does come at a price if not managed correctly.”

An Edinburgh-based CISO – who wished to remain anonymous – echoed Mitchelson’s comments around transparency and trust, adding that the case could mark a “potential turning point for our industry”.

They said: “I hope positive change comes from the Joe Sullivan case, because regardless of what occurred in the courtroom, there are wide-ranging potential implications.

“If jail is a genuine threat as part of our careers, there are many grey areas we still need to improve, especially regarding incident handling & response.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Ross Kelly

Staff Writer & Researcher

Latest News

Cybersecurity Featured Security

Proposed Police Scotland Cyber Centre Raises Duplication Questions

Cybersecurity Editor's Picks Events

Microsoft, NBCUniversal and Admiral Group Experts Set for CymruSec 2026

AI Business Editor's Picks

Salesforce Agentforce Bugs Exposed Wider AI Agent Risk, Research Finds

AI Cybersecurity

Despite AI Hype, Traditional Identity Fraud Prevails