When Your Boss and the Public Disagree: The Ethics Rules That Actually Govern Security Work
In November 2016, Uber’s chief security officer got an email from a stranger: hackers had broken into Uber’s systems and stolen data on 57 million riders and drivers, including 600,000 driver’s license numbers. He had a choice — report it, or make it go away. He chose to pay the hackers $100,000, dress the payment up as a “bug bounty,” and have them sign a non-disclosure agreement falsely stating no data had been taken. The company’s users, and the regulator actively investigating Uber’s security practices at the time, found out more than a year later. In 2022, that security officer, Joseph Sullivan, was convicted in federal court. In 2023 he was sentenced to three years’ probation and a $50,000 fine. The Ninth Circuit later upheld the conviction.
That case is now the sharpest real-world illustration of a question every security professional eventually faces: when protecting your employer and protecting the public point in different directions, which one wins? It turns out the security industry has spent decades trying to answer that question in writing — and the answer, across nearly every professional body that has weighed in, is consistent.
Why security work gets its own ethics rules
Most jobs don’t come with a formally published, enforceable code of conduct. Security work does, and for a specific reason: the job hands practitioners access that almost no one else in an organization has — production databases, customer records, encryption keys, incident details, the ability to see exactly how badly something broke and choose who finds out. Customers, regulators, and coworkers can’t independently verify whether that access was used responsibly. They have to trust that it was. Professional codes of ethics exist to make that trust something other than blind faith — a documented, externally enforceable standard that a practitioner can be held to, and can be removed from the field for violating.
Several organizations publish one. They don’t use identical language, but they converge on the same shape.
What the major codes actually say
ISC2, the organization behind widely held security certifications, publishes a Code of Professional Ethics with a preamble and four ordered canons. The preamble states plainly: “The safety and welfare of society and the common good, duty to our principals, and duty to each other, require that we adhere, and be seen to adhere, to the highest ethical standards of behavior,” and that “strict adherence to this Code is a condition of certification.” The canons, in priority order, are: protect society, the common good, and the infrastructure; act honorably, honestly, justly, responsibly, and legally; provide diligent and competent service to principals (employers and clients); and advance and protect the profession. Members who knowingly violate the code face a peer review panel that can revoke their credential.
ISACA, which certifies auditors and governance professionals, lists seven duties in its Code of Professional Ethics: supporting sound governance standards, performing duties “with objectivity, due diligence and professional care,” serving stakeholders lawfully, maintaining confidentiality, staying competent, disclosing significant facts about one’s work, and supporting the profession’s education. Violations can be reported — including anonymously — and can trigger a formal investigation and disciplinary action.
ACM, the world’s largest computing society, structures its Code of Ethics and Professional Conduct around general ethical principles, professional responsibilities, and leadership responsibilities, and states outright that “the public good is always the primary consideration.” It also requires members to be honest about “any circumstances that might lead to conflicts of interest” when they give a professional evaluation.
GIAC, the certifying body tied to the SANS Institute, runs a four-part code — respect for the public, for the certification, for the industry, and for oneself — enforced by a standing Ethics Council that investigates reported violations and can revoke certifications, ban a practitioner from future programs, or report the violation to other certifying bodies.
EC-Council, which certifies penetration testers and ethical hackers, gets more operationally specific: keep client information confidential, never associate with malicious hacking, keep every penetration test authorized and within legal limits, and don’t engage in bribery, double billing, or other financial misconduct.
Five organizations, five different documents — and one repeated structural choice: protecting the public sits above loyalty to an employer, and above the practitioner’s own interest, whenever the two genuinely conflict. That’s not a slogan. It’s the operating instruction that Joseph Sullivan’s case shows can carry personal criminal liability when ignored.
When the code and the paycheck disagree
Sullivan’s case is unusual only in that it produced a criminal conviction. The underlying conflict — a security leader instructed to keep quiet while people remain at risk — is not unusual at all, and the codes above are explicit that “my employer told me to” is not an ethical escape hatch. Acting “honorably, honestly, justly, responsibly, and legally” and providing “diligent and competent service” to an employer are both real obligations, but none of the major codes treats employer instruction as license to conceal harm to the public the practitioner is also supposed to protect.
The other well-documented case in this space is a whistleblowing one. Peiter “Mudge” Zatko was hired as Twitter’s head of security in late 2020, after a high-profile breach in which attackers hijacked verified accounts belonging to Joe Biden, Elon Musk, and other prominent figures. He was fired in January 2022. In July of that year, working with the nonprofit Whistleblower Aid, he filed an 84-page complaint with the Securities and Exchange Commission, the Federal Trade Commission, and the Department of Justice, then testified under oath before the Senate Judiciary Committee. His allegations included that thousands of employee laptops carried complete copies of Twitter’s source code, that roughly a third of those had automatic security updates blocked and firewalls disabled, that around 5,000 employees had broad internal access without adequate monitoring, and that the company was experiencing roughly one reportable security incident a week — while, he alleged, violating an existing FTC consent order on data handling. Twitter disputed the characterization. The point for security professionals isn’t who was right; it’s that formal whistleblower channels to securities and consumer-protection regulators exist precisely because internal escalation sometimes fails, and a practitioner’s ethical duty to the public doesn’t stop at the edge of the org chart.
Conflicts of interest aren’t hypothetical
The same codes spend real space on a quieter problem: situations where a practitioner’s outside interests could color their professional judgment, even without any breach or cover-up involved. EC-Council’s code directly bars bribery and double billing. ACM requires disclosing “any circumstances that might lead to conflicts of interest” whenever giving a professional evaluation. ISACA requires serving stakeholders’ interests “in a lawful manner, while maintaining high standards of conduct.” In practice, this covers things like auditing a system you helped design, recommending a vendor’s product while receiving compensation from that vendor, or consulting for two organizations that compete on the same contract. The common answer across every code is the same: disclose the relationship to whoever is relying on your judgment, and let them decide whether it’s disqualifying — don’t quietly decide for yourself that it’s fine.
Policy has to back the code up — or the law steps in
A code of ethics governs the individual. Most security failures, though, happen inside organizations built from many individuals with different backgrounds and different instincts about what’s “reasonable.” That’s why every serious code also expects ethical principles to be translated into enforceable organizational policy — and why “due care” and “due diligence” are treated as more than internal habits. Due diligence is the fact-finding: understanding what risks actually exist. Due care is the follow-through: keeping reasonable protections in place based on what you found. ISACA’s code folds both into a single duty — performing work “with objectivity, due diligence and professional care.”
This isn’t just professional etiquette; it’s a legal standard regulators actively enforce. Between 2008 and 2010, hotel company Wyndham Worldwide suffered three data breaches in under two years, tied to failures the FTC later cited by name: unpatched known vulnerabilities, default usernames and passwords left in place, and no real monitoring for unauthorized access. The FTC sued, arguing Wyndham’s security practices were an “unfair” business practice under Section 5 of the FTC Act. Wyndham fought the case up to the Third Circuit, arguing the FTC had no authority to police security practices this way. In August 2015, the Third Circuit disagreed and affirmed the FTC’s authority to sue companies over inadequate data security — without first having to publish a specific rulebook of what “reasonable” security looks like. Wyndham settled in December 2015. The case is now the standard reference point for a simple fact: “reasonable security” isn’t just an aspiration in a code of ethics. Fail badly enough at due care, and a regulator can treat that failure as illegal on its own.
Ethics as daily practice: how vulnerability disclosure gets it right
Most ethical decisions in security work aren’t as dramatic as a breach cover-up. The most common one is smaller and happens constantly: a researcher finds a flaw in someone else’s software and has to decide how, and how loudly, to tell the world. The CERT Coordination Center’s Guide to Coordinated Vulnerability Disclosure lays out the principles the field has settled on for handling this well: reduce harm rather than maximize attention; presume the person reporting a flaw is acting in good faith; avoid surprising the parties involved in ways that escalate tension; reward constructive participation instead of punishing it; and apply the same professional codes of ethics discussed above to the disclosure process itself. It’s a concrete, everyday example of the abstract “protect society, act honestly, serve competently” language actually turning into a repeatable operating procedure.
Key Takeaways
- Security professionals across nearly every major certifying body — ISC2, ISACA, ACM, GIAC, EC-Council — are bound by published codes of ethics that share a consistent priority: protecting the public outranks loyalty to an employer or to the practitioner’s own interest when the two genuinely conflict.
- That priority isn’t symbolic. Uber’s former CSO was criminally convicted for concealing a breach on his employer’s instruction rather than disclosing it — a direct, real-world instance of choosing loyalty to a “principal” over duty to the public, with legal consequences.
- Formal whistleblower channels to regulators (SEC, FTC, DOJ) exist because internal escalation sometimes fails; Twitter’s former security lead used exactly that path when he believed the company’s own leadership wouldn’t act.
- Conflicts of interest are a daily hazard, not just a headline event. Every major code’s answer is the same: disclose the relationship rather than privately judging it to be immaterial.
- “Due care” and “due diligence” aren’t just internal ethics vocabulary — regulators like the FTC can and do treat a serious failure of reasonable security as an illegal business practice, independent of any published rulebook.
- Coordinated vulnerability disclosure shows how these abstract obligations get operationalized day to day: reduce harm, presume good faith, and avoid unnecessary surprise when handling someone else’s security flaw.
Sources & References
- ISC2 Code of Ethics
- ISACA Code of Professional Ethics
- ACM Code of Ethics and Professional Conduct
- GIAC Code of Ethics Policy
- EC-Council Code of Ethics
- U.S. Department of Justice — Former Chief Security Officer of Uber Convicted of Federal Charges for Covering Up Data Breach
- U.S. Department of Justice — Former Chief Security Officer of Uber Sentenced to Three Years’ Probation
- TechCrunch — Uber’s former security chief found guilty of covering up 2016 data breach
- TechCrunch — Ex-security chief accuses Twitter of cybersecurity mismanagement
- Federal Trade Commission — Third Circuit rules in FTC v. Wyndham case
- Federal Trade Commission — Wyndham Settles FTC Charges It Unfairly Placed Consumers’ Payment Card Information at Risk
- CERT/CC — Principles of Coordinated Vulnerability Disclosure
Image credit: https://www.rawpixel.com/image/6042704/photo-image-public-domain-free — cc0 1.0 (via Openverse)
This article is for general educational purposes only and does not constitute professional, legal, or security advice.