Ex-Uber CISO Requests a New, ‘Fair’ Trial

Share This Post

Former Uber CISO Joseph Sullivan, convicted in 2023 of trying to cover up a data breach, is seeking a new trial, citing procedures omissions from his original trial that his lawyers said tainted the verdict.

Sullivan was initially convicted on charges related to Uber’s 2016 data breach and was sentenced to three years of probation for his role in the subsequent coverup.

Sullivan was also ordered to pay a $50,000 fine and perform 200 hours of community service. These penalties were considered too soft by the prosecution, which argued that a 15-month prison term would have been more beneficial in deterring other executives in similar situations.

Now, Sullivan’s defense attorneys argued that the jury was not informed of two “key limitations” in the nexus requirement, when Sullivan was initially tried. To convict a defendant under section 1505, the government must prove there was an agency proceeding; that the defendant was aware of that proceeding; and that the defendant intentionally tried to corruptly influence, obstruct, or impede that proceeding. According to the defense, these requirements weren’t part of the jury’s instructions, which undermined the entire conviction and called for a reversal.

“But at a minimum, each of these errors infects one of the government’s core theories of guilt and require a new trial,” Sullivan’s attorneys argued during this week’s hearing.

The prosecution countered that any potential errors in jury instruction were harmless and, ultimately, Sullivan’s actions of falsifying documents and authorizing hush money in the form of bug bounties were a clear obstruction of justice.

The court made no decision today, but CISOs, boards of directors, and legal scholars will be watching the ruling, given how Sullivan’s conviction has led to more legal scrutiny of and charges against CXOs, especially where compliance with data-handling laws is concerned.

https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt68eed791d79d2ca5/66997f8dbe5399f6443f0371/judge_Tetra_Images_Alamy.jpg?disable=upscale&width=1200&height=630&fit=crop

This post was originally published on this site

More Articles

Article

Navigating SEC Regulations In Cybersecurity And Incident Response

Free video resource for cybersecurity professionals. As 2024 approaches, we all know how vital it is to keep up to date with regulatory changes that affect our work. We get it – it’s a lot to juggle, especially when you’re in the trenches working on an investigation, handling, and responding to incidents.