The Future of Work · A Deep Dive

Outside the Blast Radius: Where Every CISO Must Stand BEFORE the Incident

A CISO’s exposure in a breach is decided long before the breach. Not by how well they handle the incident, but by whether their mandate, their allocation of responsibility, and their board relationship were built while things were still calm. A working guide to positioning the role before you need it, so that when the fire comes, you’re the one running toward it, not the one it’s pointed at.

A long read, built to be returned to. Opinion frames the argument; the evidence is grounded in federal court records in United States v. Sullivan and SEC v. SolarWinds and Brown, current SEC disclosure rules, the EU's NIS2 Directive, and 2025–2026 research from IANS/Artico Search, Heidrick & Struggles, Deloitte, and Accenture.

01 — THE FRAME

Two CISOs, two outcomes, and one difference that mattered

In October 2022, a jury convicted Joe Sullivan, Uber’s former chief security officer, of obstruction of justice and misprision of a felony. When hackers stole records on 57 million Uber users and drivers in 2016, while Uber was already under FTC investigation for an earlier breach, Sullivan arranged a $100,000 payment through the bug bounty program, had the hackers sign non-disclosure agreements, and let the incident go unreported to regulators for nearly a year. He was sentenced to probation, not prison. The Ninth Circuit upheld the conviction in March 2025. He remains, as of this guide, the only security executive in the U.S. ever criminally convicted over how he handled an incident.

In October 2023, the SEC charged SolarWinds and its CISO, Timothy Brown, with securities fraud. This time the allegation wasn’t about the response to the 2020 Sunburst breach. It was about what the company had said, in writing, about its security posture before the breach happened, while Brown’s own internal risk assessments allegedly told a different story. A judge dismissed most of the claims in July 2024, but let one survive: the pre-breach “Security Statement.” That single surviving claim hung over Brown for another sixteen months before the SEC finally moved to dismiss it with prejudice in November 2025. A named CISO had spent two years as an individual defendant in a securities fraud case, for something he’d signed off on before any incident occurred.

Read those two cases side by side and a pattern emerges that has nothing to do with how good either man was at incident response. Sullivan’s exposure was created in the room during the crisis: an improvised decision, made under pressure, with no documented mandate for making it. Brown’s exposure was created in a different room, months or years earlier: a public statement about the company’s security posture that his own internal knowledge should have qualified, and didn’t. Different moments, same lesson. By the time the incident happens, your legal and reputational exposure as a CISO has usually already been set. What you do during the fire barely moves the needle compared to what was, or wasn’t, built before it started.

Sullivan’s mistake was made in the crisis, with no mandate to fall back on. Brown’s was made years before the crisis, in a statement nobody had built the governance to properly check. Both prove the same point: the incident is not where a CISO’s exposure gets created. It’s where it gets revealed.

What actually separated the two outcomes Not talent, and not luck. The difference is whether the decision, at the moment it was made, had a documented mandate behind it. CONCEALED & IMPROVISED Decision made solo, inside security, under pressure No documented sign-off from legal or the board Materiality call delayed rather than made on criteria Story reconstructed from memory under oath, later Outcome: federal conviction, upheld on appeal DOCUMENTED & DEFENSIBLE Decision routed through a named, pre-agreed RACI Sign-off logged contemporaneously, not recalled later Materiality determined against pre-built criteria Decision log stands on its own, no reconstruction needed Outcome: case eventually dismissed, no admission needed The rule of thumb Being right doesn’t protect you nearly as much as being documented does. Brown’s case took two years to resolve, even with a defensible position, because the documentation trail had to be reconstructed and litigated rather than simply produced.
Even the better outcome, Brown’s eventual dismissal, took two years and a federal court case to arrive at. Documentation built in advance is what makes that process faster, or unnecessary.

This guide is about the work that happens in the calm period, so that when the fire comes, it doesn’t come looking for you personally. That means three things done properly, and done before anything happens: a clearly documented mandate that puts real authority behind the CISO title, a mesh of allocated responsibility so the CISO isn’t quietly holding accountability that belongs to legal, comms, or the business, and rehearsed muscle memory so the first hours of an incident run on a plan rather than improvisation. Get those three right and the CISO who walks into an incident room isn’t defending themselves. They’re leading.

Lead Form

Enter Your Details to Continue Reading

By submitting your details, you agree to receive emails from us, including resources, updates, and marketing communications. Unsubscribe anytime — your data stays private and is never sold, rented, or shared outside Eristotle.