Home » What Smart CISOs Quietly Changed After Tim Brown and Joe Sullivan
By Michael Hiskey – Drawing on an extended conversation with veteran CISO Donna Ross and discussions held during recent CxO Security Forum executive gatherings.
Executive Summary
###
The experiences of former SolarWinds CISO Tim Brown and former Uber CSO Joe Sullivan have fundamentally changed how many cybersecurity leaders think about personal accountability. Drawing on an extended conversation with veteran CISO Donna Ross, this article explores six practical investments every CISO should make to better protect themselves, their organizations, and their careers. Rather than reacting out of fear, Ross advocates a more deliberate approach to executive leadership: confirm personal protections such as Directors & Officers insurance, carefully review all public statements about cybersecurity, collaborate with Legal and Marketing to ensure claims are evidence-based, communicate publicly with greater discipline, invest time in understanding governance and corporate disclosures, and embrace the broader responsibilities of enterprise leadership. Her central message is simple: today’s CISO is no longer judged solely on technical expertise, but on business judgment, governance, and accountability. The best time to strengthen those capabilities—and your own protections—is long before you ever need them.
I welcome your input on this article… please do that via the summary LinkedIn post on this same topic!
There are moments that permanently change a profession. They are rarely recognized in real time.
Not because a new technology emerges. Not because regulators issue another rule. Not because attackers become more sophisticated. Rather, because a few highly visible events force everyone else to quietly ask themselves:
“What would I do if that happened to me?”
For many Chief Information Security Officers, the experiences of Tim Brown, former CISO of SolarWinds, and Joe Sullivan, former CSO of Uber, became exactly that moment.
Their cases were different. The legal outcomes were different. The facts were different. Yet together they fundamentally changed how many experienced security executives think about personal accountability, executive leadership, public disclosures, and their own professional risk.
During recent CxO Security Forum executive discussions in New York, Boston, and at the Gartner Security & Risk Management Summit, Tim Brown spoke candidly about his experience, the SEC investigation, and the personal impact it had on his life. The conversations prompted a surprising number of CISOs to ask a simple question afterward:
“What did experienced CISOs actually change after watching Tim and Joe?”
One executive who had a particularly thoughtful answer was veteran CISO Donna Ross.
Ross has spent more than twenty-five years leading cybersecurity organizations and has served through multiple CEOs, organizational restructurings, changing boards, and changing regulatory environments. Following extensive conversations with both Tim Brown and Joe Sullivan after their respective cases, she quietly began changing the way she approached her own role—not because she feared becoming the next headline, but because she realized the profession itself had changed.
Her advice is not about fear. It is about leadership. More specifically, it is about making a deliberate investment in yourself before you ever need the protection.
“If you don’t have time for it,” Ross told me, “you’re not protecting yourself and your family.”
That simple observation became the foundation for everything that followed.
For years, most CISOs understood that a significant security incident might cost them their job. Boards lose confidence. Executives seek accountability. Organizations change leadership. That possibility has always existed. CISOs (similar to CIOs, COOs, etc.) could lose their jobs through absolutely no fault of their own.
What changed over the past several years was the realization that termination might no longer represent the worst possible outcome. Regulatory investigations. Civil litigation. Personal legal expenses… and biggest of all… criminal charges.
That means not only losing a job. It’s damage to reputation; potentially an inability to get another job. Health consequences. Stress placed on spouses, children, and families. Those became real—not theoretical.
“Maybe a CISO could do everything right and through no fault of their own could lose their job as the senior named person responsible for cyber,” Ross explained. “What I hadn’t fully appreciated was that I could lose much more.”
Watching both Tim Brown and Joe Sullivan navigate extraordinarily public legal battles fundamentally changed that calculation. Rather than simply sympathizing with two respected peers, Ross began asking a different question.
“What should I change today while everything is going well?”
That mindset ultimately led to six practical investments every CISO should consider:
The first investment has nothing to do with technology. It starts with governance.
One lesson has become increasingly clear: too many CISOs assume they are protected because they’re officers of the company. After studying what happened to Tim Brown and Joe Sullivan, Ross concluded that assumptions are no longer enough.
On Directors and Officers (D&O) insurance: the experiences of Tim Brown and Joe Sullivan have made these conversations far easier to have. Boards, CEOs, and General Counsel now understand that personal liability for security executives is no longer hypothetical.
CISOs who are on the D&O should still seek certainty. Are you personally named under the policy? Or is only the position covered? The distinction matters.
Rather than relying on broad language describing the “Chief Information Security Officer,” the practical advice is straightforward: the CISO should be listed as a named individual, consistent with other corporate officers. As opposed to requesting the entire policy, Ross recommends asking for the declarations page. For most executives, that provides sufficient documentation to understand the coverage in place should it ever become necessary.
That review quickly expands into broader questions every CISO should ask while relationships with leadership remain strong:
Perhaps her most important advice was surprisingly simple. Negotiate these issues while everything is going well. No one wants to begin discussing indemnification after receiving a subpoena.
The most striking part of Ross’s story began after some of her personal conversations with Tim Brown and Joe Sullivan: She went back and reread everything. Not just cybersecurity policies. Everything. Annual reports. Quarterly filings. Risk disclosures. Public communications.
She wasn’t looking for mistakes. She was looking for assumptions—statements that had become accepted over time but could not necessarily be supported by documented controls or operational evidence. Reviewed through the lens of an executive knowledgeable about cybersecurity, with an added focus to protect the firm.
Then she recommends going even further. Review marketing collateral, website content, conference presentations, social media, customer-facing materials—anywhere your organization makes claims about its cybersecurity capabilities or resilience. Pay particular attention to language that creates absolute expectations or makes claims that cannot be objectively substantiated. If a statement cannot be supported by documented controls, operational evidence, or established processes, consider whether it belongs there at all.
In short, read every sentence as though opposing counsel wrote it.
These are general descriptions that sound compelling but could not necessarily be mapped to an operational control. That changed her review process completely. Previously, she had reviewed documents primarily for factual accuracy. Now she asked a different question:
“Can I validate every one of these statements with an actual security control?”
If the answer was no, the language should be changed. Not because Legal required it. Not because Marketing objected. Because she wanted every public statement to withstand scrutiny from regulators, investors, opposing counsel, or a courtroom years later.
Ross approached public statements the same way an auditor approaches evidence. If a statement could not be traced to a control, supported by documentation, and demonstrated during an audit, she questioned whether it belonged in the document at all. Every claim should be traceable. Every assertion should be defensible. Every statement should be capable of being corroborated. That mindset fundamentally shifts cybersecurity from communications to governance.
It may be a surprise that Marketing wasn’t resistant. Quite the opposite. Once the objective was framed as protecting the company rather than watering down campaigns, marketers generally welcomed another set of eyes–which creates nuanced, intelligent references to information security in those corporate communications.
If a marketing claim says communications are secure, the underlying controls should demonstrably support that claim. If your organization publicly discusses resilience or recovery, the documented processes should withstand scrutiny during an investigation. If a capability is described publicly, Security should be able to demonstrate the controls supporting it.
For Donna over the years, the process became remarkably efficient. Legal already reviewed marketing materials. Cybersecurity simply joined the workflow in parallel whenever security-related language appeared.
These reviews rarely delayed campaigns. Changes are usually small. In her experience, Marketing appreciated having language that could survive executive scrutiny. Legal appreciated reducing unnecessary exposure. Security gained confidence that public statements accurately reflected operational reality. Everyone wins.
A conference presentation is over when the audience leaves the room. A recorded webinar, podcast, or interview may be replayed years later by regulators, attorneys, journalists, or investigators. Context disappears. The recording remains.
Ross recommends approaching every public appearance—from keynote presentations to podcasts—as though it may someday become evidence in a regulatory investigation. She suggests every presentation include appropriate disclaimers. Avoids discussing company-specific security practices publicly. When possible, speak in generalities. Recorded appearances should receive significantly greater scrutiny than live discussions. Whenever scripts are required, have Legal and Marketing review them beforehand.
Perhaps most importantly, discipline yourself to stay on message. Recognizes that context disappears once a recording lives online indefinitely. That discipline doesn’t make someone less authentic. It makes them more deliberate.
I pressed Donna on an objection I could clearly see coming from perhaps ⅗ of the CISOs in our Community: “I already have so much on my plate – how do you find the time?” Her response is direct:
“If you don’t have time for this, you’re not prioritizing yourself.”
That’s a provocative statement in a profession where every week brings another critical vulnerability, board presentation, vendor assessment, or incident response exercise. Yet her point is that protecting yourself is part of protecting the company. The two are no longer separate responsibilities.
Ross estimates that this discipline requires surprisingly little time—perhaps an hour each quarter to review filings, disclosures, and major public-facing communications.
The value of that hour extends far beyond legal protection. It improves business judgment. It deepens understanding of investor priorities. It reveals leadership concerns and focus areas. It exposes how the organization presents itself externally. It sharpens relationships with legal and communications teams. And it reminds the CISO that they are helping shape the company’s public narrative—not merely defending its infrastructure.
She characterized this as the necessary leadership work that every CISO, seeing themselves NOT as a “cyber person” but as a business executive, should invest their time and energy.
The most important lesson from our conversation had nothing to do with insurance, disclosure committees, or SEC investigations. It was about identity. One practical habit Ross has developed is reading important documents through multiple executive lenses: First as the CISO, but then reviewing it in the persona of her peers… How would the CEO interpret this? COO? CFO?
Why? Because leadership requires understanding how others interpret risk. Cybersecurity expertise remains essential. But it is no longer sufficient. Too many CISOs still allow themselves to be viewed as “the cyber person.” Ross rejects that characterization entirely.
The modern CISO should aspire to contribute to discussions about mergers, acquisitions, budgeting, strategy, operations, and enterprise risk—not simply answer security questions after decisions have already been made. “If they only ask you about cybersecurity,” she explained, “You’re limiting your value.”
Interestingly, this theme surfaced repeatedly during executive discussions at recent CxO Security Forums in National Harbor (Risk & Security Summit), Boston, and New York. Although speakers covered topics ranging from AI governance to SEC enforcement, one conclusion kept resurfacing: the role of the CISO is evolving from technical authority to enterprise executive. Technical credibility remains essential, but boards increasingly expect judgment, governance, communication, and business leadership.
None of this advice is about becoming fearful or reluctant to lead. Ross’s point is not that CISOs should speak less. It’s that they should speak more deliberately. Public statements deserve greater scrutiny. Governance deserves greater attention. Leadership demands greater intentionality.
As TIm Brown explained during the June CxO Security Forum discussions in Boston and New York, his and Joe Sullivan’s cases surfaced the willingness of the connected cybersecurity community to openly share difficult lessons. CISOs compared notes. Trusted peers reviewed contracts, disclosures, insurance policies, and public statements together.
Rather than retreating, the profession became more collaborative. The organized group talks by Gadi Evron, informal CISO group discussions – and even our own CxO Security Forum Community. Peers rallied around Tim and Joe: Private conversations. Support. Advice. Introductions. Commiserating, celebrating, and empathizing. Personal encouragement. Experienced leaders openly sharing painful lessons so others might avoid similar circumstances.
Tim Brown and Joe Sullivan never intended to become case studies. Yet their experiences have already reshaped how many seasoned CISOs think about leadership.
The smartest among them didn’t wait for another regulation or another lawsuit. They quietly changed how they reviewed public statements. They strengthened employment protections. They became more deliberate in their communications. And it accelerated them thinking of themselves not only as cybersecurity experts, but as business leaders with personal accountability.
As Ross puts it, “Take the time. Make the investment in yourself.”
It may prove to be the most valuable hour you spend all quarter. The return may one day protect not only your career, but your reputation, your family, and everything you’ve spent decades building.
This article was inspired by discussions held during recent CxO Security Forum executive gatherings, including Tim Brown’s candid conversations with cybersecurity leaders following his presentations at the New York and Boston CxO Security Forums. Its purpose is to share practical leadership advice with the broader CISO community as executive accountability continues to evolve.
I welcome your input on this article… please do that via the summary LinkedIn post on this same topic!