Trending
Media
Joe Sullivan Joins Costanoa Ventures as Venture Partner
Media
Read: AI Risk is Bigger than Us
Media
Read: The AI You Can't Take With You
Advisory
New security program for AI-native companies
Media
Read: Trust Us, We're the Experts
Impact
Delivering Technology and Hope, Joe Sullivan Returns from Sixth Humanitarian Trip to Ukraine
CORPORATE WORKSHOPS · CYBER & AI GOVERNANCE

Judgment is the job.
Checklist is not.

Most cyber and AI training teaches teams what the rules are. Joe Sullivan built his career being the person in the room when the rules ran out: as a federal cybercrime prosecutor, then as CSO at Facebook, Uber, and Cloudflare. These workshops teach the judgment underneath the frameworks: how to decide well, under real pressure, with incomplete information.
4
Workshop formats
1
Facilitator: Joe, every session
60 min – 1.5 days
Board briefing to full simulation
The Facilitator

What Joe Sullivan brings to the training

8 years as a U.S. Department of Justice cybercrime prosecutor
CSO at Facebook, Uber, and Cloudflare
Testified twice before the U.S. Congress
Trusted advisor to boards, founders, and investors on AI & security risk
The Program

Four workshops. One discipline: risk judgment in the age of AI.

Each is delivered live by Joe Sullivan, built around your business, your regulatory exposure, and your real incidents, not a generic deck. Open a workshop for the full brief. Fees shown are indicative; each engagement is finalized at scoping based on scope, audience size, and format, with travel billed separately.

01

Cyber Leadership in the Age of AI

The flagship full day for security leadership, fixing the ratio of leadership to management.
Full-Day · In-Person
Security & Exec Leadership
$75,000

“Leadership is vision, inspiration, and culture. Management is planning, process, and control.” Most security organizations are over-managed and under-led. This is the day that fixes the ratio.

  • The leader/manager distinction, and why security teams default to the wrong one
  • Why silos are a system failure, not a people problem, and how to fix the system
  • Real accountability: owning outcomes, cheerleading the behavior you want, showing up first in a crisis
  • The risk-judgment toolkit: separating reversible decisions from one-way doors, learning from how similar incidents actually played out, and stress-testing plans for failure before committing to them
  • Open floor: your team works a live, real risk decision using the framework

$75,000

*Indicative fee · up to 40 seats
Travel billed separately
AudienceCISO & security leadership, rising leaders · 15–40 people
FormatSingle company, on-site or off-site
DurationFull day (6–7 hrs)
Book a Workshop
02

AI Risk Briefing Webinar

A fast, sharp-edged 60–90 minutes for a wider audience that needs the picture, not the full day.
60–90 Min · Virtual or In-Person
Any Size Audience
$25,000

A fast, sharp-edged briefing for a wider audience that needs the picture, not the full-day workshop.

  • Where AI genuinely changes the threat and risk-judgment picture, and where it's the same problem in new clothes
  • The reality check: how AI-related incidents actually tend to go, versus how they're covered
  • Three questions every leader should be asking their team this quarter
  • Live Q&A, moderated

$25,000

*Indicative fee · Virtual delivery
In-person option quoted separately, plus travel
AudienceAll-hands, extended security org, customer/investor briefings
FormatVirtual or in-person keynote
Duration60–90 minutes
Recording & reuseRights agreed at contract stage; additional fee applies if the session is recorded for reuse
Book a Workshop
03

Boardroom Risk Judgment DirectorsAgentic AI

A private half day giving directors the vocabulary, questions, and named owners for AI-era oversight.
Half-Day · In-Person or Hybrid
Board & Audit Committee
$65,000

“A lot of bad decisions are actually undecided ones: made by drift, owned by nobody.” Boards don't need to learn to code. They need the vocabulary, the questions, and a named owner for every AI decision the board is now personally accountable for.

  • Fiduciary oversight of cyber and AI risk, translated out of engineering-speak
  • Reading a risk dashboard: what to ask, what "green" is hiding
  • Sorting decisions: which are reversible and should move fast, which are one-way doors
  • Ruling out ruin before chasing AI upside; setting the risk-appetite line first
  • Agentic AI accountability: who holds the pen when an autonomous agent acts on the company's behalf, a governance gap most boards have not yet closed
  • Personal liability, plainly stated: what fast-moving federal AI directives and the shifting state-law patchwork mean for individual directors and officers, and how to document defensible oversight rather than assumed oversight
  • Leaves with a concise board action checklist and a named-owner accountability map for AI decisions

$65,000

*Indicative fee · up to 15 seats
Travel billed separately
AudienceDirectors, audit/risk committee, GC, CFO · 8–15 people
FormatBoard meeting adjacent, private session
DurationHalf day (3–4 hrs)
Book a Workshop
04

Crisis Command Simulation

A 1.5-day immersive tabletop built on a custom scenario, with composure practiced before it's needed.
1.5-Day Immersive · In-Person
Executive Crisis Team
$100,000

“Their crisis is our job.” Composure isn't invented at 2am; it's practiced. This is the workshop that gets rehearsed before you need it for real.

  • Emotion as a tool: reading the room's temperature and setting it on purpose
  • The fire-department approach to incident command: show up fast, take command, leave it better
  • Naming decision authority in advance, so the crisis doesn't have to invent it
  • A live tabletop built around a scenario specific to your business: breach, AI model failure, deepfake fraud, or a scenario of your choosing
  • After-action review: what the group's real decision-making pattern was, and where it broke

$100,000

*Indicative fee · custom scenario
Travel billed separately
AudienceCEO, GC, comms, CISO, board liaison · 10–25 people
FormatCustom scenario design, on-site
Duration1.5 days
Book a Workshop
At a Glance

Choosing the right format

WorkshopDeliveryBest forDurationGroup sizeInvestment*
01 · Cyber Leadership in the Age of AIIn-personCISO & security leadership teamsFull dayUp to 40$75,000
02 · AI Risk BriefingWebinar (in-person option)Broad awareness, all-hands, LP/investor updates60–90 minUnlimited$25,000
03 · Boardroom Risk JudgmentIn-person or hybridDirectors, audit & risk committees (incl. agentic AI & personal liability)Half day8–15$65,000
04 · Crisis Command SimulationIn-personExecutive crisis / incident response team1.5 days10–25$100,000

*Indicative fees, finalized at scoping based on scope, audience size, and format. Travel is billed separately.

Common Questions

Before you reach out

How customized are Joe Sullivan's corporate workshops?

Every Joe Sullivan Security workshop is customized to the client. Each engagement starts with a scoping conversation about your business, your regulatory exposure, and the incidents or decisions actually on your plate. The risk-judgment frameworks are field-tested and consistent, while the examples, scenarios, and open-floor work are built for your room. The Crisis Command simulation goes furthest: the entire 1.5-day tabletop runs on a scenario designed specifically for your company.

Are the workshop fees fixed?

The fees published on this page are indicative. Every Joe Sullivan Security engagement is priced at the scoping stage based on the scope of customization, the number of participants, the format and location, and any add-ons, so the final quote may differ from the figure shown. Recording and reuse rights are agreed at the contract stage, with an additional fee if a session is recorded for internal reuse.

What does the workshop fee include?

Each Joe Sullivan Security workshop fee covers preparation and scoping, custom materials, and live delivery by Joe Sullivan. Travel is billed separately, on top of the fee shown. The AI Risk Briefing is priced virtual-first, with an in-person option quoted separately plus travel. International engagements are quoted separately.

What language are the workshops delivered in?

Joe Sullivan delivers all workshops and webinars in English only; delivery in other languages is not available. International audiences are welcome, and sessions are conducted in English wherever they run.

Can we combine multiple workshops?

Yes. Joe Sullivan Security offers multi-session bundles, quoted as a package and priced accordingly. A common pairing is the Boardroom Risk Judgment session for directors followed by the Crisis Command simulation for the executive team, so the board and operators build the same risk vocabulary before rehearsing it under pressure.

Who delivers Joe Sullivan Security workshops?

Joe Sullivan delivers every workshop personally; nothing is subcontracted to a facilitation team. Joe spent eight years as a U.S. Department of Justice cybercrime prosecutor, then served as Chief Security Officer at Facebook, Uber, and Cloudflare, and has testified twice before the U.S. Congress. That experience is the room you're booking.

How quickly can we book a workshop with Joe Sullivan?

Most Joe Sullivan Security engagements are scoped and confirmed within a week of the first conversation. Send your target window with your inquiry; delivery dates depend on Joe Sullivan's speaking and advisory calendar, so earlier is better for board-meeting-adjacent sessions.

Can the workshops run virtually?

Yes, one format is virtual-native: the AI Risk Briefing is a 60–90 minute webinar built for virtual delivery to any size audience. The Boardroom Risk Judgment session can run hybrid when directors can't all be in the room. The full-day Cyber Leadership in the Age of AI workshop and the Crisis Command simulation are designed to be in-person: the pressure of the room is part of Joe Sullivan's method.