Skip to content

Attribution and Active Defense, with a Former Prosecutor and CSO

A former cybercrime prosecutor turned Big Tech CSO on attribution, how far a company can legally push back, and the exposure leaders now carry

Podcast cover for InfoSec Leadership episode "Every CISO's Hardest Calls, from Attribution to Active Defense," featuring Joe Sullivan, former federal prosecutor and CSO.

Cybersecurity leadership used to be a job you could do in obscurity. That is over. Ransomware turned a security incident into an operational and economic event, AI compressed the time defenders have to respond, and the person making the hard call in the first hours of a breach now carries exposure the role never used to hold. Few people have seen that shift from as many sides as Joe Sullivan.

Joe Sullivan was the first federal prosecutor in Silicon Valley dedicated full-time to cybercrime, before crossing over to lead security as Chief Security Officer at Meta, Uber, and Cloudflare. Today, as CEO of Joe Sullivan Security, he advises companies and boards on security risk and the hard calls that come with it. In this conversation he walks through when attribution actually changes a defensive decision, how far a company can legally go to push back against attackers, who carries the legal exposure when that line is crossed, and what a security leader has to settle with the CEO and the general counsel before a crisis arrives.

This is the full conversation behind an issue of InfoSec Leadership, the newsletter from InfoSec Relations. He is speaking from his own experience, and the views he shares are his own. Connect with Joe Sullivan on LinkedIn.

Watch the full conversation below or read the interview.

The transcript below has been lightly edited for clarity.

Take us back to where you are now, and how you got started in security.

Sullivan: It's funny. I didn't go to school for cybersecurity, because there were no classes on cybersecurity back then. I got into it because I was curious about technology and its impact on humans, and that's one of the things I love about cybersecurity, that so many people in this profession come at it from that angle. We're technologists, we have to be, because we're dealing with an ever-changing environment driven by the pace of change in technology. But we come at it from a particular angle, which is how do we make sure human beings don't get hurt by technology? That's what wakes us up every day and gets us excited about work. We get to play with technology, we have to be innovative to do our job, but at the end of the day we're very mission-oriented people, because we care about protecting others.

When has knowing who was behind an attack actually changed a defensive decision you made?

Sullivan: It's happened a lot of times, and it's really interesting, this concept of attribution and how we think about it in cybersecurity. Every time the topic comes up in one of my CISO Slack groups, it's very polarizing. If you come from a background like I did, first as a prosecutor, you think about who's on the other side. When I was working for the government, companies would come to us and say, "We don't know, somebody hacked us, please do something about it." And we would investigate. When the FBI is doing an investigation, their focus is on one thing, who did it. Every spy story, every mystery we've read about a private eye or an investigator, is about who's responsible for the crime. So I came into cybersecurity from the world of law enforcement, and I automatically ask, who's on the other side? Some of my colleagues who came from a pure technology standpoint just think about how they can use technology to stop the problem from happening to their company. Both angles make sense. But when our job is inside the company, we don't get to think very often about attribution, because it's our job to prevent the company from getting hurt by anyone. There's a little bias against investing resources in trying to figure out who's on the other side, because we have finite resources, and I'd rather spend mine continuing to shore up my defenses. So it's shaped a lot by your background and experience when you get to the role. And a lot also depends on the type of company and the patterns of attacks you face. When I left the federal government, the first company I went to work at was eBay, overseeing a team responsible for fighting fraud. We would train users not to fall for phishing, put in automated defenses to catch account takeovers, look for fraudulent listings, use all our data to model and predict risk. But at the end of the day, that wasn't enough, so I ended up spending a lot of time on attribution. One of the things we figured out was that a large percentage of the attackers back then, between 2003 and 2006, were coming from one country, because one organized criminal group had figured out how to commit fraud on eBay there, got really good at it, made lots of money, and then their friends started doing it. Between 2004 and 2008 I ended up going to that country seven times, to train the police on this pattern of fraud. After I trained the police, they asked me to train the prosecutors, then the judges. We realized we couldn't stop the attacks just by sitting at eBay headquarters using technology. We had to create an environment where people worried they'd get in trouble with the law. That's the reason we have rule of law in general, to make people worried there will be consequences. And the thing eBay showed me was that in the world before the internet, most of the data police needed was easily accessible to them. Now all of that data is in the hands of private companies. We see the attacks, we know the IP addresses, we sometimes know the originating machines. We could invest and get attribution if we wanted to inside the company, and it's only if we do that and share it with law enforcement that there will be real risk to the attackers.

Most companies will never run a full threat intel program. For a mid-size company with no threat intel budget, what is the minimum attribution work still worth doing?

Sullivan: Part of what I do with my security consulting business is help companies think about how much they should invest in security. One thing you see over and over, and I hate to say it, is that companies invest the bare minimum. If you give the CEO of a company the equivalent of a hundred dollars, they'll spend it first on building a product, then on a sales team to get revenue, then they'll keep iterating on the product. They spend the least amount possible on the costs of doing business, whether that's lawyers or finance or physical security or cybersecurity. Those teams get what they need to do the job and not a penny more, because when you give money to the security team, your revenue doesn't grow. You fund the security team so something catastrophic doesn't happen and the company goes out of business. We've struggled as an industry to articulate the best case for getting the most money for our security teams. Sometimes when you're a small company with a particular risk profile, it makes sense to invest in threat intelligence. If you're in financial services, you're under attack all the time because there's money to be made stealing from you, so you have to invest more than a company that just sells software. But if you're a small or medium-sized business, I don't think you should invest a lot in threat intelligence. You should focus on getting your foundations in place, the defensive things, IT security, identity and access management, device management, cloud security. You have to do those first. It's almost like you have to invest a certain amount in prevention before you start investing in detection, and then attribution is a subset of your detection function. Only the most mature organizations really invest a lot in those areas.

Does AI make attribution easier, because there's more signal to work with, or harder, because anyone can copy another actor's tooling?

Sullivan: In the short term, we haven't seen a lot of impact on detection or attribution, but in the long term AI is going to help us a lot. If we put security work in two buckets, prevention on one side and detection and attribution on the other, what is AI really good at? Finding a needle in a haystack, getting through a large volume of data much more quickly than a human ever could. And what is detection and attribution all about? Finding needles in haystacks. I work part-time at a venture capital firm investing in cybersecurity startups, and one of the things I'm seeing now are really interesting threat intelligence startups using AI. Partly they're using it to analyze data that already existed that we were just never good at. But partly they're using AI agents to go out on the internet, pose as victims, pose as other bad actors, at a scale human teams could not manage before. We can send agents to engage on the dark web, which is stuff humans didn't have the bandwidth or patience or resources to do until now. So I'm optimistic about how detection and attribution are going to go in the future.

The White House has floated giving defenders more room to strike back. Where is the line between active defense and something you would have prosecuted as a crime?

Sullivan: This is a really interesting question, and it comes up every few years out of frustration. If we step back, the reality is that collectively we're not doing enough in cybersecurity. Too many attacks happen, too many people get hurt, too many companies suffer from ransomware, the bad actors are getting away with too much. Out of that frustration comes the question of what all the things we could do are, and one of them is to empower companies, because they do have resources, and sometimes when you keep getting punched in the face it feels good to punch back. Companies with a lot of resources ask for permission to do more offensively. Where you draw that line is a decision that should be made by people in the government. Companies shouldn't make it on their own. There have been lots of companies that have done interesting things that could be categorized as punching back. Microsoft, for example, has a long history of filing civil lawsuits against attackers, and they've done coordinated takedowns disrupting infrastructure that had been compromised. I think they do it very carefully. They have lawyers sitting next to their investigators and engineers making sure they don't cross the lines. They figure out how aggressive they can be, and then they stop. I've heard stories of companies going across the line. And there are things you can do that are perfectly legal. When I was at Meta, back when it was called Facebook, we were under an attack, and we realized the domain the attackers were using had an expired registration. So we registered the domain, took it over ourselves, intercepted the attack traffic, and were able to see that a bunch of other companies were being attacked and notify them about the compromises. So we don't have to be a hundred percent passive. But there are risks that come with going on full offense. One is that you don't fully understand the environment and the impact of what you're doing. I gave the example of companies stuffing fake usernames and passwords into a phishing site to create noise for the attackers. But what if the phishing site is hosted by a large ISP, and instead of five thousand entries you try to jam in a million in the next five minutes? You might take an ISP offline, and a bunch of regular people hosting through that ISP could have their businesses disrupted. The internet is a very connected and interdependent world, so we have to be thoughtful before we allow people to go on offense.

When a company crosses that line, who carries the legal exposure, the company or the individual who made the call?

Sullivan: That's a hard one, and it's what governments around the world are deciding right now. There have been trends where corporations were held liable for a lot of things, and then governments realized that employees were making bad decisions because there were no personal consequences. So we've seen enforcement actions, like the one the government in the United States brought against me, where they want to hold individuals accountable, and we're seeing laws starting to come onto the books around the world, not just in the United States. If you're going to hold individuals accountable, ideally you start at the CEO, the person who ultimately should be making the strategic decisions for the company on these things. Security leaders should never operate in a vacuum. They should always be coordinating with their board and their CEO on anything that gets into this category.

In the first hours of a breach, when legal, PR, and the technical team all pull different ways, what does a CISO anchor to?

Sullivan: The CISO is a technical and operational leader in the company. They're thinking about technical risk and operational risk, and they control operational teams. After my case, lots of security leaders said to me, "Joe, do you think I need to go to law school and learn the legal side of things?" My answer is always no. That's a different function's job. We should always have the legal team in the room during these conversations, and we should never be saying, "Legal said do A, but we're going to do B." That's not how we operate in security. We're experts on the technology, we're not experts on the law, so we need good lawyers who have the best interest of everyone in the company in the room with us. They should be the ones saying where the gray lines are from a legal standpoint, while we say where they are from a technology standpoint, and they should explain what's clearly across the line. Then the company makes a strategic decision. CEOs make decisions all day long to take risks, that's what they do. Any startup wouldn't exist if it weren't led by people comfortable trying something no one has succeeded at before, which means they're risk-takers. But they succeed when they figure out the right line, take the risk, and then figure out how to remediate it. Security leaders aren't trained on that, it's not what we're good at. So we have to focus on really understanding what our role is, and then make sure the legal team, the CEO, and everyone else involved is on the right side of the law.

Before an incident happens, what has to be settled between the CISO, the general counsel, and the CEO?

Sullivan: One of the things we should be doing as security leaders is getting our organizations to think through these hard situations before the crisis moment. Nobody performs well under pressure, and trust isn't built then. Trust is built ahead of an incident. A lot of times when I work with security leaders, I suggest they do tabletop exercises with their CEO and their lawyers. They should talk through how they'd operate if ransomware happens. Whose job is it to decide whether to pay? How much should we invest in attribution? What is our philosophy about transparency? Companies have a real choice in how transparent they are. I don't get to decide how transparent my company is, but I can encourage the conversation, and we'll have a much healthier one if we have it before the crisis. We need to set our values and North Star ahead of those times. The last company I worked at, Cloudflare, had a very strong culture of transparency. Every time there was an incident or outage, we'd put up a detailed technical blog post explaining what happened. That was the culture when I got there. The first major security incident I dealt with, I called my CEO and said, "We're dealing with this crisis, here's what we know, here's what we don't know, here's how bad it is, we think we've stopped the bleeding." The second question he asked was, "Who's writing the blog post?" And I said, "I don't know, I'm not thinking about a blog post, I'm thinking about stopping the bleeding and making sure the company's okay." But he was already thinking about transparency, because that was the culture, and he was setting the tone from the top. He had the CTO join the incident and write the blog post because I was too busy. By the next morning we had an article published on our website explaining exactly what we'd been through. That came from a tone at the top, the CEO setting the standard about transparency in the middle of a crisis, because he'd been through it and had a plan.

How should a company act on a nation-state suspicion it can't confirm but can't say publicly?

Sullivan: I'm a big fan of public-private partnerships and companies building relationships with law enforcement. Most bigger companies in the United States now, as part of their incident response plan, have already written in who in law enforcement they'd contact, and they've discussed what types of situations they'll escalate. I'm putting aside whether there's a legal obligation, that's legal's decision. But there are lots of situations where you see something and need a philosophy on whether to raise your hand. I think it's in our best interest, as a community of security people, to bias toward sharing information. I've seen so many incidents where one company experienced an attack and then a week later a competitor experienced the same one. When I was at Cloudflare, one of our best products was DDoS mitigation, so anyone under a distributed denial-of-service attack would call us. I saw a pattern where DDoS ransomware attackers would target one company in a vertical, say video conferencing companies using a particular technology for transmitting video, and figure out how to disrupt their traffic. First they'd go after one, then another, then another, holding each ransom, working their way through. If the first company keeps it in a vacuum and tells nobody, the attackers just keep working through their competitors. But if they share information about the attack and how to defend against it, the whole industry benefits. Companies don't want to be transparent about those situations because they don't want to show they're vulnerable. But if they felt that being transparent led to others being transparent with them, so that they'd get information and be in a better place, they'd be more likely to do it.

When you can't tell whether you're facing crime or statecraft, since criminal crews and state-linked groups now share tools and infrastructure, how should that change what you do?

Sullivan: It goes back to that initial topic of attribution. Our number one job in security is to prevent harm to our company and our customers. So to a certain extent it doesn't matter who's attacking us, as long as we can figure out how to stop it. Sometimes we stop it, they iterate, we stop them again, they iterate again. When we're under that kind of continued repetitive attack, where we get the sense they're never going away if we just keep playing defense, that's when it's time to start thinking about sharing information with law enforcement and with competitors, coming up with a collective defense approach to disrupt the attackers. No matter what size you are, at a certain point it helps to start working with others on defense. The bad actors have no trouble sharing information and approaches with each other, so the good actors need to get comfortable sharing with each other more as well.

What is something about defending a large platform that outsiders consistently don't get?

Sullivan: There are a couple of different types of attacks we have to defend against. There are the random ones, a lot of attacks on the internet are just spray and pray, sending phishing emails to thousands of people to see who falls for it. But then there are attackers who say, "I'm going to go after this specific platform." Because if they can steal advertisers' accounts, they can drain their banks. Or, "I'm going to go after this platform because if I can create a bunch of accounts, I can influence how people think about an issue that matters to me, I can cause violence, I can get a community riled up to attack their neighbor." You can't do that randomly, you have to target a platform. So when you work at a large company like a Facebook or an Uber, you're dealing with attackers very focused on your platform, who've figured out how to make money off it, and who are never going away unless you build your defenses so well that it's economically better for them to target someone else, or they're afraid of getting arrested. It's a different defensive mentality, because you're not just dealing with random attacks. It's not just about getting your foundations in place, it's about really understanding the attacker and thinking about them, and in those cases you need custom threat intelligence that really helps you as a company.

What has shifted about your personal liability that you wish every CISO would understand before they face it?

Sullivan: I think fundamentally the expectations of cybersecurity people have changed in the last few years. Cybersecurity used to be a team that never had an audience with the CEO or the board, but the world changed, for a couple of obvious reasons. One is the emergence of ransomware, and the second is the emergence of AI. Taking them one at a time. Ransomware fundamentally changed the impact of a cybersecurity incident. Incidents ten years ago were largely about data leaving the building. When Target announced they got hacked, it wasn't that their systems were offline and they couldn't operate the business, it was that customer data was stolen. Now, with ransomware, it's very much that our systems are offline and customers are suffering. Colonial Pipeline, people in the United States couldn't buy gas for their cars. Marks & Spencer, Jaguar Land Rover, you couldn't buy a car or shop at the store, the supply chain got impacted, people went out of business because they couldn't sell their parts. The economic impact of cybersecurity is much greater than it was a decade ago. There were one-off destructive attacks fifteen years ago, Saudi Aramco or Sony, but nothing like what we see now. So ransomware has us talking about operational resilience as a core part of our job. Then the second thing is AI. AI is giving attackers the ability to move at a much faster pace, which means we as defenders have to move faster too. You have top government officials worried about who has access to certain AI capabilities and how to get it into the hands of defenders. CEOs are getting called to Washington to talk about cybersecurity because of the risks AI is introducing. So if you're a CEO in 2026, you have to have a personal relationship with your head of information security. You have to trust that person, you have to have visibility into how they're running their function. It used to be the CEO only wanted to look over the shoulder of the chief revenue officer, because it's all about the money. Now they need to look over the shoulder of the security leader, and that's an uncomfortable thing for a security leader who, ten years ago, got to toil in obscurity. Now you have to be briefing the CEO regularly. The job has changed.

Now that you advise companies and boards, what is the first question you want them asking their security leaders?

Sullivan: I want them to push the security team to be more self-critical. I feel like in cybersecurity we've accepted a level of security that's not good enough, because we never got enough resources to do it well at most companies. When I go into lots of different companies, I only see them investing the minimum. It's a rare company that goes above and beyond, and I love working with those few because it's awesome to see a place where security has actually won the arguments. But in too many places, security was told, "You're the department of no, you can only have this much money." So security leaders have gotten used to living with not enough resources, and too many of them think, "I've done the best I can with the money I was given and the people I have." In their head they're doing a good job, because they got a lot out of a limited budget. But that doesn't mean the company is secure. There's a difference between doing a job with a limited set of resources and being secure, and we need boards to push on that and say, "Saying you're not secure is not saying you're not doing a good job." We as security leaders have to get comfortable with a menu approach. You say, "You gave me a hundred dollars, I built these things. If you gave me a hundred more, this is what else I'd do. Another hundred, I'd do this. And this is what I need to get to world-class." We don't have that honest conversation enough. We know what good looks like, we know what world-class looks like, but we don't hold ourselves to that standard. We hold ourselves to what we could do with the resources and risk profile we inherited.

As we wrap up, what is the one thing more CISOs and senior security leaders still consistently get wrong?

Sullivan: I think it's hiring. We've set up a bunch of compliance frameworks and verticals within security, so we think in terms of those verticals. When I go into security organizations, the biggest risks I see are the gaps between the teams they set up. Take an example of a risk that came along in the last five years, in the United States we've been talking about North Korean IT workers who've infiltrated companies, people getting jobs at US tech companies as remote workers and then using their access to steal data. Nobody talked about that as a risk, and it could have been people from anywhere, not just North Korea, but because of sanctions there have been a lot of these workers doing this. For whatever reason, it took about three years before companies caught it, and thousands got hired in. The main reason, I think, is that no sub-team in security was thinking holistically about risk, and this one slotted in between the existing functions. If you asked everybody on the security team whether they were doing a good job, they'd all say yes. But holistically the company was not doing a good job, because of the way the team was set up. So as security leaders we need to constantly step back and look at our teams and ask, are we creating a bunch of silos? Are we empowering people to think holistically about risk? Are we giving them the time and bandwidth to step back, or are we just putting everybody on hamster wheels? If people are just in narrow lanes, dealing with their endpoint alerts or reconfiguring their firewalls and calling the job done, they're not thinking holistically about risk. The world is too dynamic and changing too fast. We have to have people thinking about the big picture on our teams.

Where can people find and follow your work?

Sullivan: My website is joesullivansecurity.com. I also run a nonprofit helping kids in Ukraine called ukrainefriends.org. And I'm on all the social platforms too, like everybody these days.