Joe Sullivan on What CISOs Need to Know About the Uber Trial episode artwork

EPISODE · Nov 13, 2023

Joe Sullivan on What CISOs Need to Know About the Uber Trial

from Info Risk Today Podcast · host InfoRiskToday.com

In this episode of CyberEd.io's podcast series "Cybersecurity Insights," former Uber CSO Joe Sullivan discusses the Uber trial and offers guidance to future CISOs. Was the Uber case a data breach or not. Sullivan explained why that making that distinction can be complicated.

Episode metadata supplied by the publisher feed · Published Nov 13, 2023

Embed this episode

NOW PLAYING

Joe Sullivan on What CISOs Need to Know About the Uber Trial

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Welcome to Cybersecurity Insights, the podcast for the CyberEd.io Learning Community. Our goal is to bring Cybersecurity practitioners the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern Cybersecurity world. Good day, everyone. This is Steve King.

I'm the Managing Director for CyberEd.io and with me today is Joe Sullivan, who is a CISO, and was the CISO for a variety of companies, up until recently, and that means last year when he had to go through a trial that, from my point of view, was inappropriately staged for what I consider to be doing his job. We'll talk about all that in a minute. Joe, in addition to being a CISO who had worked with the CISO at Facebook and Uber and Cloudflare, he was also a lawyer. He was the Associate General Counsel at PayPal, and verdict on his case was with regard to his alleged role in covering up a 2016 data breach at Uber and was convicted in October 2022 on federal felony charges of obstruction in this prison.

In January of 23, he took on the role of CEO of Ukraine Friends, which is a nonprofit focused on humanitarian aid to Ukraine, and that's pretty consistent with what I know of Joe and his history. He's always reaching out and trying to help other folks. He worked for the Department of Justice for eight years, too, and he founded or co-founded the computer hacking intellectual property unit at the Northern District of California. He's worked on multiple cyber crime cases, including digital evidence aspects of the 911 investigation, economic espionage, and child predator cases.

He served as a commissioner at the National Cyber Security Alliance, which is a nonprofit organization that promotes cyber security and privacy education and became a board member for the National Action Alliance for Suicide Prevention. He also co-authored the 2012 National Strategy for Suicide Prevention, Obama appointed him in 2016 as a commissioner on the commission of enhancing national security for the country, and then this obstruction of justice case was rolled out in August of 2020, I believe. The criminal complaint said that he had arranged with Travis College's knowledge, who was the CEO at the time, to pay a ransom for the breach as a bug bounty to conceal its true nature and falsifying non-disclosure agreements with the hackers to say they did not obtain any data. In December of 21, he faced additional charges he'd wire for on.

Two months later, Joe was convicted of one count of obstruction, one count of misprisoned, and sentenced to three years probation, and that already caused like a million hours of community service. This trial and this prosecution represented the first U.S. federal prosecution of the CISA for the handling of a data breach. So, a long introduction, but I've been anxious to sit down with you, Joe, and thank you for taking the time and granting me the opportunity to talk with you about this.

Thank you for having me on with you. I'm happy to be here and grateful that you're drawing some attention to this story. Well, so I will open. You're welcome.

And I will open with what my opinion is, and that is that between the Federal Trade Commission and the Department of Justice, they struck a critical, severe blow to the progress of cyber security defense by, I think, abusing the idea of fiduciary care and personal liability for the CISA versus a true officer of the company. And had they pursued instead the real culprits, who were not Joe Sullivan, but rather the people who were in executive management under over time, we would have a very different outcome and a lot of progress on pushing the card on the right path here, because it's not the CISA who prevents us from doing what is necessary to get done. It is the executive management and the leadership in our companies. That's my view.

It's also widely held among many of the people that I know in this business. But this isn't about me. It's about Joe. So tell us if you can, Joe, about what you thought when you were doing what they accused you of doing at the time.

Sure. I got to sit through with the trial. I got to have a front row seat in the trial. And the judge did as well.

And what the judge said at the end during the sentencing meant a lot to me and to the people in the courtroom and to the people watching and listening over Zoom. And there were many. The judge said it's something that I was really grateful for. He said that my team did a really good job in responding to the incident, that we were very professional and that we were very successful.

The government sarcastically said that we got lucky, and the judge was just dismissed out. And the audience in the room scoffed because my team did an excellent job responding in a way that was intended to protect our customers. We secured the data. When you hear about this case, everybody refers to it as a data breach and a quote unquote massive data breach.

And it's often listed on biggest data breaches ever because of the number of records that were potentially exposed. But if you look at those lists of biggest data breaches ever, there's only one case on the list where the data was protected, recovered, and ensured that it wasn't disseminated and out sitting on the dark web. That makes you will. My team executed really well.

And the judge said something very specific. He said the NDA wasn't a cover up. The NDA was part of the investigation because that was the thing that was shown during the case, during the trial. We didn't have an NDA put in place in order to silence someone.

The NDA was part of the attribution effort. And that's an attribution is kind of like a complicated concept that we think about in security. But my team and I wanted to know who was on the other side. Who are we dealing with?

We're we dealing with a nation's state. We're we dealing with these like, you know, the ransomware actors in Eastern Europe that were so accustomed to having to deal with these days. Or we're we dealing with, you know, 19 and 20-year-old kids in the United States and Canada who had never heard about bounty programs and who didn't have an intention of dumping the data on the Internet. And we got to the bottom of it and we protected our customers.

What I said to the judge at the sentencing, the thing that we failed to do is to take accountability and I failed to do was to make sure that what we did operationally was communicated correctly and appropriately. And so that's something I think about a lot, especially now is kind of things are swirling around that solar witness case. And I've heard the security leader from Solar witness talk about this situation. And there's one really striking similarity between the cases.

And that is this expectation that the security leader is accountable for the words that their company says about security to third parties, even if the security leader never actually personally saw the words and reviewed them and approved them. Because that was the government, in my case, presented a bunch of evidence of statements made by my company to the FDC. They had no evidence that suggested that I had even seen. And it sounds like there's something similar going on over it in that solar witness case, although I don't have a first-hand knowledge there.

So that's a long answer. I touched on a few different things, but those are some of the thoughts. Yeah, sure. And I watched the sentencing and I agree with you that I think the judge was trying to figure out a way to build you out because the case was, I thought you made the case your team very strongly.

But on the other hand, it's hard to do. We've got a couple of verdicts like that, I suppose. But I guess one of the things that we need to understand, and by the way, I think yours is the only case that I am aware of where somebody other than the FBI actually captured, if you will, or identified the herbs and was able to make a deal with them for the return of the data, which therefore does not qualify it as a breach. If it's exfiltrated and gone, that's a breach, if it's exfiltrated and gone, that's a breach, if it's exfiltrated and returned.

I don't think that's a breach. I think you have to have exfiltrated data before that, before that qualifies. So it's kind of a misnomer, at least in my mind. That's something that I think is worth kind of touching on for a second.

From the perspective of security leaders going forward, whether something is a data breach or not, it's one of the lessons here is it's a very complicated question that I don't think anyone says qualified to answer. In the trial, there was testimony and evidence that we had a data breach response plan. The plan said that legal was the decider on those things, that my team looped in legal following the plan before I even was involved. The legal was actively engaged and aware of the case.

The assigned lawyer, the one who was mentioned in the breach plan, was there working on it throughout the case. And his manager, the woman who ran the privacy team in legal, was fully informed about the incident. And she was the person who oversee the saw the lawyers who were engaging with the FTC. So we as the security leader, we shouldn't try and put on a legal hat and figure out what to reach and what's not.

We have to bring in the lawyers because it's a really complicated thing. Over the years, I don't know how many different data breach laws have been put in place. And a company like Uber was operating in our hundred countries. There's no possible way that any of us in operational roles could be able to keep up with that.

And so we shouldn't even try. I didn't even try and I wouldn't even try. I would expect the same way I would expect the AppSec engineer on my team to be looking to know AppSec a lot better than I do. I would expect the lawyer who was assigned to my team to know their space.

And we often come together as a team to get to the right outcome. Yeah. And none of those people faced any consequences for what they did and what they knew while it was going on either. The lawyer who advised my team throughout the process, he received immunity from the government.

Yeah. That's a good deal for him, bad deal for everybody else. What's the whole executive management team under some sort of a non-prosucute-torial agreement? The government entered into a non-prosecution agreement with Uber the company.

I don't know all the details of that. I don't think we get to see that or if I did, I don't remember. But I think that in exchange for the company fully cooperating in the case against me, the company wasn't charged with that. There's not something along those lines.

And the whole trial, you had the government seated at a council table. And then in the first row on their side of the courtroom was a team of Uber lawyers sitting there supporting them. Yeah. So what message does that send then to the community?

Well, I can only talk about what I've heard from security leaders. And it bugs me because I've tried to be someone who's been part of this community of security leaders for a long time. I've learned and had great mentors and I've tried to be a mentor to others. And the idea that my case has put sear into those people and anxiety into those people and maybe even undermine the dynamic between the private sector and the government are all bad things from my case that I partly at least caused.

And so we're in a place right now where there are a lot of people who have roles as security leaders who then feel quite belivered. Number one, they have a really hard job. They're the voice of the customer, the champion for risk mitigation in a field in which it's very hard to articulate the cost benefit of investments in security. So you have that hard job to start with.

Number one, number two, it's under a micro cell like it never was before in terms of expectations from your CEO, from your board and from the regulators and government and consumers on the outside. And number three, you're not just worried about like harm to your company, but you have to worry about it to harm to yourself personally from the role. So there's a lot of stress put on people's shoulders. No kidding.

And for what? $700,000 or whatever the cop is, you know, going controversy. So, you know, to face the outcome that you're now stuck with at least at the moment with probation, but convicted of a felony, you can't get a job as a CISO anywhere, I assume. And, you know, banks won't even take your money.

So it's, you know, the results of these things are insidious and hidden in many cases. But when you unfold all of that, you know, and I won't ask you to go through that here, but I know there's a lot of personal impact here. You know, and then you turn around and say, well, you know, what was I doing that for these guys that immediately, you know, ran toward protection for prosecution in exchange for their testimony against you. I mean, come on, yeah, something wrong with this picture.

In any event, you know, what I'd love to hear if you don't mind, could you, is it possible for you to describe which I thought was really clever, how you actually apprehended the bad guys? Sure. So my team had a lot of experience dealing with this concept of attribution. It was, you know, partially I had that philosophy that attribution matters from my time as a prosecutor.

You know, if you go back to the 1990s and early 2000s, I was a federal prosecutor. And what our job was, was to work with federal law enforcement after a crime had happened, to figure out who did it and should they be accountable. And so that's just kind of what I grew up in. And then I got to eBay and eBay was the most successful e-platform, e-commerce platform of that era, when I was there from O2 to O6.

And it was blooming and there was a lot of good stuff happening there, but there was also a lot of bad stuff. And so I was part of the leadership of the Trust and Safety Department. And we had to look at and scriptize sellers who sometimes were really malicious, but other times just bad communicators are not good at this whole e-commerce world, you know, because as eBay being a platform of advisors and sellers, a lot of the sellers back in the day were new to it. And they would oftentimes screw up.

The easy thing to do would be to jump to the conclusion that they were malicious. And then I went to Facebook and the security team already had, they had this wall where they would put up on the wall every successful kind of investigation outcome. And that wall became more popular and filled up during my time as a CSO there. And, you know, we dealt with all kinds of malicious activity.

And sometimes we would work with law enforcement and do a big takedown. Other times we would get frustrated because we couldn't get law enforcement to work on the case and we'd have to figure out other alternatives, especially for criminals overseas. It's been a lot of time in personally traveling to Eastern Europe and other parts of the world trying to convince law enforcement to prosecute cases. And we did a lot of the attribution in those cases.

And we would literally come to law enforcement with cases on a platter and ask them to follow up because we felt like there needed to be deterrent. And that was the culture at Uber. We, during my time at Uber, referred hundreds of cases to law enforcement or bad things that we saw happen, targeting both drivers and riders on the platform. And so we would package up cases to go to law enforcement.

So we had a whole team of investigators who were focused on attribution and things like that. And they worked in this case. And it was interesting it came out during the trial that these two young men had decided that they were going to find vulnerabilities in companies and then ask the companies to pay them. And I think they were successful in finding vulnerabilities in three or four companies, not just Uber.

And they contacted us and they wanted us to pay them. And we wanted to fix the vulnerabilities. But we weren't comfortable just sending money to some anonymous people because how would we know that they actually deleted the data? You know, they kind of have to download some data to validate that you actually have access to it.

And they did that. And they probably went further than they should have with that. But they did that with multiple companies. Now the interesting thing is one of those companies contacted the FBI, but the FBI were unsuccessful in finding them.

Another company just refused to cooperate and just kind of ignored the whole thing. And they deleted the data. So these guys, they got to experience from the outside three different responses from three different organizations. But only one of them, one organization put in the resources and effort to find them, meet with them in person.

We literally had, it was a testimony of a trial. A member of my team was former CIA operative, he was trained interrogator. And we had him personally interviewed each of the two young men went to their homes and met with them as part of our effort to make sure that all the data had been deleted. So we were able to find them, locate them and make sure that they were doing the right thing and felt like we had achieved the right outcome in terms of protecting our customers and their data.

Yeah, it sounded like it to me. When I say, you know, you're busted for doing your job, that's exactly what I mean. I don't know anybody else has ever successfully done what you just described. Yeah, my team used techniques that we've used in other cases.

There's actually a kind of famous one from a few years before when I was working at Facebook. It was actually documented in, I think, New York Times sort of story about it. And it's, for some reason, I ended up in the super pumped book, which is the story, which a book about Uber. There's a chapter on me.

And in that case, we were dealing with trying to get attribution. So I'd been contacted by a woman who was facing an extortion situation because she met someone on Match.com and she had shared a topless picture. And then the person on the other side turned out to not be an actual match match, but, you know, an extortionist who said I'm going to send that picture to your whole company. Yes, if you don't pay me $5,000.

And since I knew her professionally in other contexts, she asked if I would help. And a couple of friends and I had worked on the investigation and we were able to find a person responsible. And then we got remote access to the computer and we forced them to delete all the data that they had on all the other people they were sorting through Match. And we just went through that experience and we would never have been able to get out from law enforcement in that case because the individual responsible was over in Africa.

We were able to hire somebody to go meet with them in person and get the computer and stuff. And so we resolved that situation. I bring out that case because the attribution playbook was the same one we used, which is you just engage in contact communication with the people on the other side. And you forced them to go through different platforms as part of the communication and or payment.

And sooner or later, odds are that they're going to screw up and expose an IP address or something. And so we've gone through that playbook lots of times in different investigations and it worked in this one as well. And what came out in the trial was it was actually the NDA. We sent them an NDA through one of those online document signing services.

And it was the one thing in this case that they weren't able to figure out how to block their origin IP address that then kind of led to us being able to back them down. So there's tried and true ways that my team was expert at following for an investigation like that. Yeah, I guess that's great. It's your new career.

My old career. Yeah. Yeah. Let's talk to me a little bit about the Ukraine nonprofit that you that you're running.

Sure. So while the case was kind of going on, I was fortunate enough to be working as a CSO at cloud player, a really great company that, you know, provides cybersecurity resources for countries and businesses and people. And in early 2022, before the full-scale invasion of Ukraine by Russia, the United States government asked cloud player to get in front of a bunch of Ukrainian infrastructure private and public sector. And so I was working on that project and then kind of working on it even more after the invasion started and the cybersecurity side of the war kicked in fast forward at the end of 2022, October 2022, the verdict came out.

And there was just no way I could stay at cloud player and have that, you know, like I couldn't be a CSO with a felony conviction. And I'd already had seen the company have to deal with some really tough stuff because they were willing to employ me. Specifically, you know, there were customers who dropped cloud player because the cloud player was willing to have someone with a pending case against them. And so I knew that would just get worse for the company.

And so in the company, you know, I've been very supportive, but there's only so much you want to ask. And so after the verdict, I left cloud player and I was in the kind of like a rough spot there, not knowing what I'd be able to do with my future. But I knew the sentencing was going to be off for a ways. And so I reached out to some different people.

And I said, I would like to continue volunteering on the Ukraine war. You know, it's fascinating. I'm learning a lot from a cybersecurity standpoint and, you know, doing defensive work in context feels good. And the funny thing was, you know, my friend is a recruiter.

He's the same recruiter who'd placed me at an Uber and at cloud player and a couple of other advisory things over the years. And he said, Joe, I found the perfect one. I had my recruiting sorcerers call every nonprofit focused on Ukraine. And we found this when Ukraine friends that they actually need a new CEO.

I was like, what? I was looking to volunteer a few hours a week. And obviously, you know, we're not profitable. So I don't, you know, like, I don't know what's going to happen after the sentence thing.

You know, the government's arguing that I should go to prison for over a year. But, you know, they said, he said, talk to the founders of the board. It's a really compelling group. And what they're doing is fascinating.

And they talked to them and I said, look, I don't know how long I'll be able to do it. But I'd be happy to jump in and take it on as a volunteer. And they said, great, let's do it. Let's take that risk.

Maybe we'll just get six months of how loud of you. Maybe we'll get more. And so I, on January, I became the CEO of Ukraine friends. We're a small nonprofit.

We have a team on the ground in Ukraine and Poland. And one employee in the United States, other than myself. She's a refugee from Ukraine who came last year. And she kind of does all of our marketing, social media and operations stuff that I don't do.

And we do, we do, we're all funded by US donors. We do whatever we can to help in Ukraine. The big thing we're working on, you know, we've done a lot with medical equipment and refugee support over time. But the big thing now that we're focused on is mental health and education for kids.

You know, there are lots of people, lots of different points of view on whether the United States should be funding this war. Or lots of, you know, like we don't get involved in that. We just focus on the kids who are stuck in a war zone, not of their own making. And I had three daughters go through a pandemic and have to keep up with their education remotely.

And it was hard. And it was a setback for them. And every kid in Ukraine had to go through that. It's a pandemic too.

And then just as they came out of the pandemic, a war started. And so they're back in remote schooling again, except most of them can't afford a laptop of their own. You know, the average income for a family before the war, there was $2,000 a year. And we're sending our kids to, you know, our kids are in remote school with $2,000 laptops.

So we've been getting companies across the US to donate their used laptops. We bring them over. We set up kids with them for the remote schooling. Or even if they're in schools, if they're fortunate after to be in a school that's in session, we still help them out with that.

And we're trying to do some mental health support stuff as well. And it's been going really well and it's really rewarding work. Yeah, I'm sure it is. And if somebody wanted to participate with you, how do they reach Ukraine friends?

Yeah, one of two reasons. One of two ways, sorry. Ukraine friends.org is our website. We're actually just about to launch a refresh of it.

But it's pretty straightforward there. And that anybody can reach out directly to me on LinkedIn, send me a message. You know, a lot of people have heard me talk about it in different contexts and they've gone back to their own company and said, what do we do with our used laptops? And it turns out, you know, a lot of them are just sitting there waiting to be recycled.

Because, you know, we have an employee come into our company. They work for 18 months or two years. You give a brand new laptop. And then you have that two-year-old laptop and you're like, yeah, it's not quite what we want to give to the next new employee.

And it just kind of sits there. We've had companies, you know, small startups donate 10 laptops and big companies donate hundreds of laptops. And every single one makes a difference because it changes the life for one kid. And that's more than enough.

So a lot of people have reached out. You know, a lot of people have come back to the company and said, what do we do with our used laptops? You know, I've got to learn. There were also some recycling organizations that partnered with companies.

And we've been working with a couple of them because, you know, they make it even easier for us because they refurbished laptops and make sure that they're wiped and secure and all that. And fun to learn about that world. Yeah, yeah. Okay, that's great.

Thank you. One, let's see. I wanted to mention that you have since hired Oric, I believe, to represent you in the appeal. Is that correct?

Yes, that is correct. Okay. We do have an appeal kind and we'll see how that goes. Right.

If you had one, the last question I think, Joe, is if you had one piece of advice that you would offer to all of the CEOs out there today, what would it be? Yeah. Like, despite everything, I'm optimistic about the future for our profession. And it's because of the people in the profession.

I told the judge it by sentencing you, hopefully, or me say, this is a noble profession. It's full of people who go into it for the right reasons. They go into it because they want to help people. Because when you're a security leader, you get to build a team of people who are protecting your customers who are focused on trying to prevent bad things from happening to good people.

And so that's always going to be a hard and thankless job. But we all know it when we went into the profession. And you're not going to get the praise from the leadership when you succeed because nobody notices. But there's one thing I wanted to mention, which is there's one investment you can always make that you know will play off in the long run.

And that's the investment of people. Each security leader, sometimes they don't remember that they're a leader because they're fighting. They're under-resourced. They're pushing for those resources.

They're trying to build a team. The challenges and risks never stop getting more complicated. The technology platforms we're trying to protect get more convoluted. And so it's sometimes it's hard to remember that you're a leader.

There was this one silver lining on my case, which was between the period of the jury finding me guilty and the sentencing. Hundreds of people wrote letters to the judge. And they just started showing up within weeks of the verdict. People sending me letters saying, Joe, I want the judge to know this about you.

That about you. And I just got to read every one of them as they came in and each one changed that day for me and made that day a little better. And I ended up getting over 200 of these letters. You sat one.

A lot of people sent them. And you didn't send it because I asked you to send it. None of the people sent them because I asked them to send them, except my daughters. Everybody else sent them because they had a point of view on me as a person and our profession and where it's at.

And they wanted the judge to know that. And so the lesson I learned was that my investment in people and relationships paid huge dividends for me because it changed my life. And the judge said at the sentencing that he was not going to sentence me to prison because of my good character and because of the impact I'd had. And because this case was unprecedented.

And he knew those things because of the letters, because people took the time. I was so blessed to have people consider it a priority to take some time on a weekend and write a letter. I'll have to do the right letters anymore. And yet hundreds of people did that for me.

And so if you're a security leader, remember that you're a leader and the littlest thing you do to help someone else makes a huge impression on them. That was the thing that I came to appreciate from the case was I didn't remember half the things people wrote about in the letters, but they made impressions because I was a leader of their team or I was a leader of a department that was adjacent to theirs. Who said their son for lunch and explained to my profession or all those little things that you do add up and make differences for others and you should always make time to do them. That's what I learned.

Yeah. Well, that lesson is broad applicability to us beyond well beyond cybersecurity. So yeah, you're absolutely right. So thank you for that.

So I think we're going to wrap up here. I wanted to keep this to 30. We're over a little bit. Thank you, Joe, for taking the time to visit with us today.

I know our audience is going to appreciate this. And, you know, I'm very happy the judge realized that you are a great guy and a great CISO. And I hope that the appeal makes a dent. And I know you're represented by a high quality attorney.

So once again, this is Joe Sullivan to my audience. And thank you guys for spending whatever this has been of your day and listening here. I hope you enjoyed it as much as I did. And until next time, this is Steve King, your host signing up.

Thank you for joining us for another episode of Cybersecurity Insights. You can connect with us on LinkedIn or Facebook or send us an email at social at cybered.io. For more information about the podcast, visit cybered.io forward slash podcast. Until next week, stay safe and secure.

And we'll see you on the next episode of Cybersecurity Insights.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on November 13, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!