
Rani Osnat at Aqua Security explains why the Uber breach is a game changer for CISOs
Late last year, the US Department of Justice announced that a verdict had been reached in the case against former Uber CISO Joe Sullivan, finding him guilty on two counts associated with covering up a 2016 data breach at the company.
This watershed moment marks the first time a data breach has been filed as a criminal charge against a CISO and raises the bar on the potential personal risk any CISO takes on when undertaking the role.
In addition to being responsible for the cyber security of the enterprise 24x7 and worrying about the regulatory impact and potential harm a breach may cause to a company’s brand or reputation, CISOs now need to be concerned about facing the possibility of personal fines and even jail time following a major security incident.
With this in mind, let’s take a look at the resources and protections every CISO should ensure are in place to minimise the risk of criminal charges following a significant breach.
Up until now a key protection requirement sought by many CISOs as part of their employment package has been solely severance protection which makes sense when you consider how the CISO is the most obvious fall guy to take the blame following a data breach. Even when everything from core security to disclosure has been done right.
Following the Uber data breach verdict however, CISO’s will need to gain assurance that their role is also covered by liability protection in the form of Directors and Officers (D&O) insurance. And that this coverage extends post-employment for a minimum of three years or more.
CISOs that are already in post should initiate discussions fast and request a copy of their organisation’s D&O policy from HR or the Chief Risk Officer. In addition to checking if their role is specifically covered, they should also review carefully what, if any, exclusions apply.
Should they discover they don’t have this protection in place, then they should immediately seek the support of their CEO and press for this to be rectified.
The discovery of a breach is always a stressful scenario. But it’s a situation made all the more distressing should CISOs find that decisions relating to disclosure are being made without their involvement.
Worse still, CISOs may find themselves on the receiving end of instructions that come from the executive management team directing them to limit disclosure.
The question of whether and what to disclose, and when, is a complicated decision that should be overseen by a legal team that is qualified to determine the most optimal approach.
In the event of a breach that exposes sensitive data, CISOs must strive to ensure they are present at any discussions related to disclosure, that legal counsel is also present at these discussions, and that all decisions are documented.
Building open lines of communication with legal teams, so that sensitive information on vulnerabilities can be confidentially shared on a regular basis. That’s especially the case when a breach occurs that may have exposed sensitive information. Alongside ensuring that legal are ‘on side’ and can jointly learn from past events, this will give CISOs a conduit for proactively managing any decisions relating to risk that are taken by the organisation.
From a technical perspective, security teams will have well documented processes in place for responding to incidents and breaches. But when it comes to demonstrating that they acted by the book, CISOs will need to go one step further and develop an operational framework that leaves nothing to the imagination.
This framework should include clear definitions that clarify in no uncertain terms what constitutes a material breach. Alongside eliminating confusion on any grey areas, these definitions will prevent any stakeholder disagreements from arising as to whether a breach is material or not.
Finally, the operational framework should feature well defined processes that cover both when legal is notified and when the board is informed.
Finally, developing a clear strategy of what to do in the instance of a breach is a ‘must have’. In other words, a strategy that sets out the processes for responding to a breach from a communication and legal perspective.
Ideally, CISOs should go beyond tabletop theoretical exercises and look to test these procedures out before having to do it ‘for real’. Undertaking security simulations that include the whole cycle of engaging legal, the board and undertaking external disclosure will call attention to areas that need further refining and reduce the likelihood of panic in the wake of a real breach.
Rani Osnat is SVP Strategy at Aqua Security. To learn more please register and listen to the webinar Uber Verdict: The Cisco, The Law and The Door
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543