From federal cybercrime prosecutor to Big Tech security leader, Joe Sullivan has spent his career confronting cybercrime from both the public and private sectors.
From the earliest days of electronic crime investigations to leading security at some of the world’s largest technology companies, Joe Sullivan has had a front-row seat to the evolution of cybersecurity.
In Episode 50 of Detonation Point presented by Elastio, Joe sits down with Matt O’Neill to discuss nearly eight years as a federal cybercrime prosecutor and his later security leadership roles at eBay, PayPal, Facebook, Uber, and Cloudflare. Their conversation spans 9/11, international cybercrime, fraud, public-private collaboration, and what today’s security leaders need to succeed.

Cybercrime, 9/11, and the Patriot Act
Joe began working electronic-crime cases in the late 1990s, before “cyber” became the term we use today. That experience eventually led to his involvement in the 9/11 investigation.
As Joe explains, much of the plot left a digital trail, including flight school arrangements and airline tickets to communications and money movements. His work also contributed to a narrowly focused area of the Patriot Act addressing digital evidence and search warrants.
Fighting Cybercrime Across Borders
Joe’s work later took him to Romania while at eBay, where significant online fraud was targeting U.S. users. Building effective cases required more than technology. It required relationships with Romanian police, prosecutors, and judges.
Those partnerships helped create lasting cooperation between U.S. and Romanian investigators and demonstrated why international relationships remain essential to fighting borderless cybercrime.
From Prosecution to Prevention
Moving into the private sector changed Joe’s perspective on fighting cybercrime. Law enforcement gave him experience investigating offenders and holding them accountable. Inside technology companies, he gained another opportunity: designing products to reduce abuse before it occurs.
At eBay and Facebook, that meant combining investigations and close collaboration with law enforcement with efforts to identify how products could be abused and reduce those risks earlier.
Making Cybersecurity More Data-Driven
Joe also highlights a major challenge for security leaders: quantifying risk.
Fraud teams can often connect an investment directly to measurable financial losses prevented. Cybersecurity is different. A successful attack may be unlikely but extremely costly, making the return on security investments harder to demonstrate.
Joe argues that cyber leaders need to become more data-driven so they can communicate risk in terms business leaders can understand.
The Fraud Epidemic and “Squeezing the Balloon”
When discussing today’s fraud problem, Joe uses the analogy of squeezing a balloon. Reduce losses in one part of the system, and they often shift somewhere else.
Addressing fraud therefore requires coordinated incentives and accountability across financial institutions, technology platforms, government, and other organizations with the ability to prevent harm.
Earning a Seat at the Leadership Table
For Joe, effective security leadership also requires being involved before major business decisions are made.
Security leaders need to communicate without jargon, understand the broader business, and contribute beyond their own discipline. Otherwise, security becomes something added after decisions have already been made rather than incorporated from the beginning.
More From the Detonation Point Blog
Continue exploring conversations on cybercrime, investigations, and security leadership.
- Cybersecurity That Actually Works with CISO Elliott Franklin
- The Evolution of Cybercrime: Ransomware, AI & Global Investigations with Jim Meehan
- Going Undercover to Infiltrate Cybercriminal Networks with Rich LaTulip
Watch the Full Episode
Hear Joe Sullivan’s perspective on the evolution of cybercrime, the fight against fraud, and what it takes to lead security in the public and private sectors.
YouTube | Apple Podcasts | Spotify