CISO & Officer Personal Liability
A legal analysis of landmark federal actions against individual Chief Information Security Officers and corporate executives for breach concealment, fraudulent disclosures, and systemic security governance failures.
Key Facts
- Federal prosecutors and regulators increasingly pierce the corporate veil to target individual cybersecurity officers.
- Mischaracterizing extortion payments as white-hat bug bounties constitutes federal criminal obstruction.
- SEC enforcement targets discrepancies between public marketing statements and internal CISO risk registers.
- Directors and Officers (D&O) insurance policies may not cover fines or legal defense costs for intentional concealment.
Joseph Sullivan (Former Chief Security Officer, Uber)
Federal Criminal Prosecution (DOJ)Legal Context: Historic first criminal prosecution and conviction of a corporate CISO for breach response conduct. Sullivan arranged a $100,000 Bitcoin payment to hackers through HackerOne bug bounty, having them sign NDAs falsely certifying no data was copied while concealing the intrusion from the FTC.
Timothy G. Brown (Chief Information Security Officer, SolarWinds)
Civil Securities Fraud Enforcement (SEC)Legal Context: First time the SEC sued an individual CISO for securities fraud. The SEC alleged Brown made misleading statements in SolarWinds public Security Statement that contradicted internal presentations warning internal systems were vulnerable to widespread exploitation.
James Cory Rellas (Chief Executive Officer, Drizly)
Federal Trade Commission Administrative Consent OrderLegal Context: The FTC named the CEO personally, requiring him to implement comprehensive information security programs at any future business he leads, controls, or holds a majority ownership interest in for the next decade.