Dark Side Case: Decisive Moment for Uber’s Chief Security Officer
Nour Abdul Wahed, Prescott C. Ensign · Academy of Management Proceedings · 2023
In November 2016 Uber’s Chief Security Officer, Joseph Sullivan, was faced with making a critical decision. He had just learned that hackers were claiming they had gained access to the data 57 million users. They were also requesting $100k for their silence and the deleting of the private information they acquired. What should Sullivan do? Uber already has a negative reputation with the media related to a list of incidents including a large data breach in 2014. Uber did not need more negative publicity. Moreover, Uber’s CEO, Travis Kalanaik, and the organization’s culture would probably prefer hiding the breach and paying the hackers. Sullivan has a family and was fairly new in the job so he probably did not want to make any missteps and risk loss of his job. The case also raises the issue of whether to use a (retroactive) Bug Bounty Program – one in which he could hire (reward) the hackers to reveal how the breach was done and keep quiet about the breach. All in all, Sullivan had to decide if he should: pay or not pay the hackers ransom; hire the hackers on a Bug Bounty contract; publically disclose the breach or hide it; or even simplhy just ignore the whole thing and see what happens. Whatever decision Sullivan makes will have consequences for Uber, various stakeholders and him personally.