Analysis
CISO personal liability: what Uber and SolarWinds changed
How the Joe Sullivan conviction and the SEC's SolarWinds case reshaped CISO personal risk — and the protections security leaders now negotiate.
TL;DR: Two cases turned an abstract worry into a personal one. Sullivan showed a security chief can be criminally convicted for how a breach was handled; SolarWinds showed the SEC will name a CISO personally over what a company said about its security. The common thread is not being breached — it's concealment and misrepresentation. The rational response is not fear; it's negotiating protection and building a paper trail of honesty.
What actually happened in the two cases?
Uber / Sullivan. In 2023, Uber's former chief security officer was convicted of obstruction of justice and misprision of a felony for his role in concealing a 2016 breach while the FTC was investigating an earlier one — including routing a payment to the attackers through the bug-bounty program and keeping the incident from regulators. The conviction was about the cover-up, not the intrusion.
SolarWinds / Brown. In 2023 the SEC charged SolarWinds and its CISO with fraud, alleging the company's public statements about its security practices misled investors. In 2024 the court dismissed most of the case, leaving a narrower claim tied to the company's published "Security Statement." Narrowed or not, the precedent stands: a CISO's name can appear on an SEC complaint over security representations.
What is the actual liability theory?
Strip away the headlines and the exposure concentrates in three behaviors. Concealment: hiding an incident from regulators, investigators, or — for public companies — investors. Misrepresentation: signing or feeding public statements about security posture that internal evidence contradicts. Certification exposure: sub-certifications that roll up into SEC filings, customer attestations, and regulator submissions carry the signer's name. Being breached, making a defensible judgment call that ages badly, or losing an argument about budget are not, on the current record, what creates personal liability. Lying about any of them is.
How should a sitting CISO reduce personal risk?
Four practical moves. Write down risk decisions: when the business accepts a risk over your recommendation, record the recommendation, the decision, and the decider. Stay out of sole ownership of disclosure: materiality and notification decisions should run through a documented process with legal, finance, and the CEO — the CISO informs, a committee decides. Align public statements with internal reality: review what marketing, sales, and IR say about security; the SolarWinds theory lives in that gap. Never touch concealment: the moment an incident response plan bends toward "make this not have happened," the personal exposure begins.
What should a CISO negotiate before taking the seat?
The Sullivan and SolarWinds era moved three items from unusual to standard in serious CISO negotiations: written confirmation that the CISO is covered by the company's directors-and-officers insurance (with the policy actually reviewed, not just promised); an indemnification clause in the employment agreement covering legal costs from acts within the scope of the role; and structural clarity — reporting line, board access, and who owns disclosure calls — in writing. A company that refuses all three is telling the candidate exactly how the worst day would go.
Frequently asked questions
- Can a CISO be held personally liable for a breach?
- Yes, in specific circumstances. Uber's former CSO Joe Sullivan was criminally convicted in 2023 for obstructing an FTC investigation and concealing a breach, and the SEC charged SolarWinds' CISO in 2023 over security disclosures. Liability has attached to concealment and misrepresentation — not to being breached.
- What protections should a CISO negotiate?
- Written confirmation of coverage under the company's D&O insurance, indemnification in the employment agreement, clarity on who makes disclosure decisions, and the budget and authority proportionate to the accountability. Increasingly these are negotiated before accepting the seat.
- Did the SEC win the SolarWinds case?
- Partially and provisionally. In 2024 the court dismissed most of the SEC's claims against SolarWinds and its CISO, allowing a narrower securities-fraud claim tied to the company's public security statements to proceed. The narrowing relieved some fears, but the case established that a CISO can be personally named by the SEC.
Sources
- US DOJ, United States v. Joseph Sullivan (N.D. Cal., conviction 2023)
- SEC v. SolarWinds Corp. and Timothy G. Brown (S.D.N.Y., filed 2023)
CISO Tribune Editorial
Editorial Desk
The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.