Skirting the Tornado: Essential Strategies for CISOs to Sidestep Government Fallout
Unknown
Black Hat USA 2024 · Day 1 · Briefing
Overview
In an era of escalating cyber threats and increasingly stringent regulatory oversight, the role of a Chief Information Security Officer (CISO) has become one of immense responsibility and considerable personal risk. This presentation, "Skirting the Tornado: Essential Strategies for CISOs to Sidestep Government Fallout," delivered by defense attorney Jess, dives deep into the precarious position CISOs find themselves in following major cyber incidents. With a career spanning over two decades, Jess specializes in defending individuals and companies against federal government investigations and the ensuing private litigation, with a particular focus on information security professionals.

Key moments
- 0:00 Speaker introduction and focus on CISO defense
- 2:00 Talk overview: case studies, risks, SEC regulations, strategies
- 4:00 First case study: Yahoo breach by Russian FSB
- 6:00 Yahoo breach rediscovery, internal investigation, CISO scrutiny
- 7:00 Government response: prosecuting Baratov, CISO interrogations
Skirting the Tornado: Essential Strategies for CISOs to Sidestep Government Fallout
Speakers: Jess, Defense Attorney
Conference: Black Hat USA
YouTube: https://www.youtube.com/watch?v=nN98kwL35I8
Overview
In an era of escalating cyber threats and increasingly stringent regulatory oversight, the role of a Chief Information Security Officer (CISO) has become one of immense responsibility and considerable personal risk. This presentation, "Skirting the Tornado: Essential Strategies for CISOs to Sidestep Government Fallout," delivered by defense attorney Jess, dives deep into the precarious position CISOs find themselves in following major cyber incidents. With a career spanning over two decades, Jess specializes in defending individuals and companies against federal government investigations and the ensuing private litigation, with a particular focus on information security professionals.
The talk serves as a critical guide for CISOs and other security leaders, aiming to equip them with strategies to navigate the complex legal and regulatory landscape that inevitably follows a significant cyberattack. Drawing on her extensive experience, including high-profile cases like the Yahoo and Uber investigations, Jess illuminates the "chessboard" of corporate and government incentives, explaining why various players act the way they do in the wake of a breach. She emphasizes the dramatic worsening of the risk landscape due to new Securities and Exchange Commission (SEC) regulations, offering actionable advice to protect individuals before, during, and after an incident, ensuring they avoid becoming targets of federal government scrutiny.
Background
▶ Watch: Speaker introduction and focus on CISO defense (0:00)
Jess's motivation to become a defense attorney stemmed from an early conviction that the U.S. government wields excessive power, often using it to "steamroll over individuals for misguided reasons." This perspective was deeply influenced by her upbringing in Northern California, where she witnessed the destructive impact of federal law enforcement on individuals and families involved in the black market cannabis industry. This personal history fueled her dedication to fighting against what she perceives as "massive and capricious power."
After graduating from Harvard Law School at the age of 20, Jess dedicated her career to defending innovators in the tech industry against regulatory and criminal investigations brought by agencies such as the SEC, the Department of Justice (DOJ), and the Federal Trade Commission (FTC). For the past decade, her focus has narrowed specifically to defending information security professionals, including CISOs, in SEC and DOJ investigations. Her experience encompasses landmark cases like the massive Yahoo investigation and the subsequent Uber investigation, among others. She frames her role as a "hot shot firefighter," diving into the most serious cases, offering a unique, insider perspective on how government agencies apply hindsight to meticulously scrutinize every action (or inaction) taken during the high-pressure moments of a cyberattack. The context for this talk is further exacerbated by new SEC regulations that came into effect at the end of the previous year, which have significantly heightened the risk landscape for information security professionals.
Key Findings
▶ Watch: Talk overview: case studies, risks, SEC regulations, strategies (2:00)
The central theme of Jess's presentation revolves around the critical, and often perilous, position of CISOs in the aftermath of a significant cyber incident. Her "key findings" are less about technical discoveries and more about the socio-legal dynamics at play, offering a stark reality check for security leaders:
- The High Stakes of CISO Liability: Jess underscores that CISOs are increasingly vulnerable to personal liability, facing intense scrutiny from government agencies like the SEC and DOJ. These investigations often apply a "hindsight" lens, dissecting past decisions made under duress, which can lead to severe personal and professional consequences. The new SEC regulations have only intensified this risk, making it imperative for CISOs to understand the legal "chessboard."
- Corporate and Government Incentives Drive Actions: The talk highlights that the actions of various players—from corporate boards to government prosecutors—are not always aligned with the immediate technical needs of incident response. Corporate shifts, activist boards, and the desire for "heads to roll" can dramatically alter internal dynamics. Similarly, government agencies, unable to prosecute foreign state-sponsored hackers, often seek domestic "headlines" by pursuing individuals, even if their role was minor, as illustrated by the Kareem Baratov case.
- Communication Breakdown is Catastrophic: The Yahoo case study serves as a stark warning about the dangers of poor communication. The breakdown between information security teams and legal counsel, the use of off-platform or ephemeral messaging, and the failure to preserve critical communications proved detrimental during subsequent investigations. This lack of clear, documented communication hinders defense efforts and fuels prosecutor's narratives.
- Proactive Preparedness is Paramount: Rather than reactive damage control, Jess advocates for proactive strategies. This includes establishing effective, cross-functional reporting structures that involve legal and executive leadership, ensuring the CISO has a direct line to the C-suite, and meticulously documenting all decisions and communications. These measures are designed to "fireproof" CISOs against government scrutiny.
- The "New York Times Rule" for Communications: A crucial piece of advice is to operate under the assumption that all internal communications could eventually become public. Avoiding "breathless expressions of panic" or speculative comments in written form is essential, as these can be weaponized by prosecutors or plaintiff's lawyers to suggest negligence or cover-up.
Technical Deep Dive
▶ Watch: First case study: Yahoo breach by Russian FSB (4:00)
While the talk primarily focuses on legal and strategic implications, it provides a detailed technical overview of the Yahoo breach, which serves as a foundational case study for CISO liability.
The breach originated in late 2014, orchestrated by the Russian Federal Security Service (FSB), formerly known as the KGB. Their operative, a 28-year-old Latvian hacker named Alexi Belan, was initially arrested in Greece in 2013 on a U.S. Interpol red notice. He subsequently fled to Russia, where he was almost certainly coerced into working for the FSB, targeting U.S. entities.
Belan's method of initial access was a routine spear phishing email. This email was sent to a mid-level Yahoo employee who, unfortunately, clicked on it. This single action granted Belan initial access to Yahoo's corporate systems. From there, he employed lateral movement techniques to escalate his privileges and explore the network. His ultimate objective was to exfiltrate user data.
The core of the breach involved harvesting a backup of Yahoo's entire user account database from November 2014. This massive dataset contained sensitive information for an astounding half a billion Yahoo users. The compromised data included:
- Names
- Phone numbers
- Dates of birth
- Weakly encrypted passwords
The speaker notes that the Russian government leveraged this stolen information for years to follow, primarily to target dissidents, journalists, and other individuals of interest.
Crucially, the Yahoo information security team was aware of the compromise almost immediately and even identified Russia as the perpetrator, nicknaming the attack "Siberia." They began working with U.S. law enforcement, recognizing the national security implications and viewing it as "an act of war by Russia against the United States." However, a significant internal breakdown occurred: the details were kept quiet within the company. The CISO at the time reportedly briefed only one lawyer with the full scope of the attack, leading to a lack of awareness among others on the team regarding the need for user or shareholder notification. Communications between information security and legal teams were even taken "off platform," creating a critical gap in documentation.
The breach only came to wider corporate attention in October 2016, when a new CISO "rediscovered" the incident. This coincided with Yahoo's acquisition by Verizon and increased government scrutiny, further complicated by an activist board seeking accountability. This rediscovery triggered internal investigations and subsequent probes by the SEC and the U.S. Attorney's office.
Unable to prosecute the FSB hackers directly, the U.S. government pursued Kareem Baratov, a Canadian hacker-for-hire. Baratov's involvement was limited; the FSB had paid him to use stolen Yahoo credentials to hack into 80 user accounts at Gmail. Despite his peripheral role, the U.S. government branded him "the Yahoo hacker" to secure a headline and send a message of deterrence to the FSB. Baratov was arrested, extradited to the U.S., and sentenced to five years in prison, a stark example of how the government seeks a tangible outcome, even if it targets a minor player.
The technical specifics of the attack, from the initial spear phishing vector to the exfiltration of weakly encrypted passwords for 500 million users, highlight fundamental security vulnerabilities that, when combined with poor internal communication and corporate governance, set the stage for severe legal and financial repercussions.
Demo / Proof of Concept
▶ Watch: Yahoo breach rediscovery, internal investigation, CISO scrutiny (6:00)
This technical article is based on a security conference talk that outlines strategies and case studies related to CISO liability and government investigations. The speaker, Jess, a defense attorney, focuses on providing legal and strategic advice through the lens of past incidents like the Yahoo breach. As such, the presentation does not include a live demonstration or a proof of concept of any technical exploit or defensive tool. Instead, it relies on real-world incident analysis to illustrate the challenges faced by CISOs.
Defensive Implications
▶ Watch: Government response: prosecuting Baratov, CISO interrogations (7:00)
Jess's talk translates directly into a comprehensive set of defensive implications for CISOs and their organizations, designed to mitigate both technical and, crucially, legal risks. These strategies are broadly categorized into actions to take before, during, and after an incident.
Before an Incident:
- Insist on an Effective, Cross-Functional Reporting Structure: CISOs must ensure they are part of a reporting structure that regularly brings together key stakeholders from different departments. This includes legal counsel (especially those responsible for SEC disclosures) and high-level executives. The speaker strongly advocates for CISOs to be in the C-suite or, at minimum, report directly to it regularly. This ensures that security concerns are communicated at the highest levels and integrated into corporate governance, preventing the kind of communication silos seen in the Yahoo case.
- Establish Clear Communication Protocols: Proactive measures should include defining what platforms are acceptable for sensitive discussions. The speaker explicitly warns against the use of ephemeral messaging apps (like Signal, Wickr, Telegram) or SMS text for incident-related communications. While these might seem convenient in the heat of the moment, their lack of persistence means crucial evidence of due diligence and decision-making can be lost, making defense efforts significantly harder years later.
- Understand New SEC Regulations: CISOs must be intimately familiar with the latest SEC regulations concerning cybersecurity disclosure. These regulations have "dramatically worsen[ed] the risk landscape," placing new obligations on public companies to report material cybersecurity incidents and disclose their cybersecurity governance. Understanding these requirements is fundamental to proactive compliance.
During an Incident:
- Prioritize Communication Preservation: All communications related to an incident must be meticulously preserved. This includes emails, internal messages on approved platforms, and meeting minutes. The speaker highlights that the Yahoo investigation, which took three years, could have been resolved in three months if all communications had been preserved. This documentation is vital for demonstrating due diligence and transparency during subsequent investigations.
- Strategic Engagement with Law Enforcement: While collaboration with agencies like the FBI, Infragard, or CISA is often necessary and beneficial, CISOs must be acutely aware that "whatever you say can and will be used against you" by plaintiff's lawyers in civil litigation or even by government prosecutors themselves if scrutiny shifts towards the company or its executives. This means being factual, avoiding speculation, and ideally having legal counsel present during such disclosures to protect attorney-client privilege.
- Adhere to the "New York Times Rule": Every internal communication should be drafted as if it could be published on the front page of the New York Times. This means sticking to "just the facts" and avoiding "breathless expressions of panic" or emotional language aimed at spurring action. Such language, while understandable in a crisis, can later be misinterpreted as evidence of negligence, cover-up, or undue alarm, undermining the company's defensive posture.
- Leverage Attorney-Client Privilege: Where possible, communications should be channeled through legal counsel and explicitly labeled as privileged to protect them from discovery during litigation. This requires close collaboration between security teams and legal departments from the outset of an incident.
After an Incident:
- Prepare for Scrutiny: Anticipate that every decision and communication will be picked apart with the benefit of hindsight. This reinforces the need for meticulous documentation and adherence to the "New York Times Rule" throughout the incident response lifecycle.
- Be Aware of Corporate Shifts: Acknowledge that corporate leadership and agendas can change rapidly. A new board or management team may have different priorities, potentially seeking to assign blame. Proactive documentation and a robust, well-communicated security posture help protect individuals regardless of internal political shifts.
By implementing these defensive strategies, CISOs can not only enhance their organization's resilience against cyberattacks but also significantly reduce their personal exposure to legal and regulatory fallout.
Key Takeaways
- CISO Liability is a Critical and Growing Risk: New SEC regulations and past government investigations (e.g., Yahoo, Uber) demonstrate that CISOs face increasing personal legal exposure following cyber incidents.
- Proactive, Cross-Functional Communication is Essential: Establish clear reporting structures, ensure CISOs are in or report directly to the C-suite, and involve legal counsel from the outset to avoid communication breakdowns and information silos.
- Preserve All Incident-Related Communications: Avoid ephemeral messaging platforms. Every decision, observation, and action taken during an incident must be meticulously documented and preserved to defend against retrospective government scrutiny.
- Communicate Factually and Objectively (The "New York Times Rule"): Draft all internal communications as if they could become public. Stick to facts, avoid emotional language or speculation, and be mindful that anything written can be used against you.
- Strategic Engagement with Law Enforcement: While collaboration is important, be aware that information shared with agencies like the FBI or CISA can be used by plaintiff's lawyers or even government prosecutors. Consult legal counsel to manage disclosures and protect privilege.
- Corporate Dynamics Can Shift Dramatically: Be prepared for changes in corporate leadership or activist boards seeking accountability. A robust, well-documented security program and clear communication protocols offer the best personal protection regardless of internal politics.
About the Speaker(s)
The speaker, Jess, is a highly experienced defense attorney with a profound focus on federal government investigations and private litigation, particularly within the technology sector. She graduated valedictorian from two Northern California schools before attending Harvard Law School at the age of 20, obtaining her law degree 26 years ago. Early in her career, she defended innovators in the tech industry against regulatory and criminal investigations by the Securities and Exchange Commission (SEC), the Department of Justice (DOJ), and the Federal Trade Commission (FTC). For the past 10-plus years, Jess has specialized in defending information security professionals, including Chief Information Security Officers (CISOs), in SEC and DOJ investigations, citing her involvement in high-profile cases such as the Yahoo and Uber investigations. Her career is dedicated to fighting back on behalf of individuals against what she describes as the "unfairness of novel government investigations that apply hindsight to pick apart every action taken or not taken in the heat of the moment of an attack." She likens her role to that of a "hot shot firefighter," aiding in the most serious cases.