SolarWinds confirms the US SEC sent Wells notices to its CISO and CFO, a rare move, signaling they may face legal action over Russia's 2020 hack of the company
With the security industry focused on the fallout from MOVEit … Mastodon: Ravi Nayyar / @ravirockks@infosec.exchange : As usual, a great write-up by Kim. — Two pertinent paragraphs: — 'This is because a CISO's activities in the past typically didn't materially impact a company's value or stock price [Wait, even after ops became computerised/otherwise computer-dependent?]. … Kim Zetter / @kimzetter@infosec.exchange : Last week the SEC sent Wells notices to SolarWinds employees warning they may face legal action over the company's 2020 hack. But it's slipped the attention of many that one of the people who got a notice was the company's CISO - a very rare and significant move that indicates more CISO's could face similar action in the future. … @metacurity@infosec.exchange : Zero Day has confirmed that the notices went to Chris Brown and Barton Kalsu. Brown, who is currently CISO of SolarWinds, was head of security architecture for the company at the time of the breach. Kalsu is the company's CFO. — https://zetter.substack.com/ ... Twitter: Austin Mooney / @austinjmooney : BFD. Not only CISO but CFO facing liability for data breach. Between this, Sullivan, Drizly, and other reported FTC matters, personal liability for privacy/cyber becoming a major trend. https://twitter.com/...
Context & Ripple Effects
The Wells notices arrive more than two years into the fallout from the Russia-linked supply chain hack that reached deep into US government networks, including DHS internal communications alongside Treasury and Commerce, and after SolarWinds hired ex-CISA Director Christopher Krebs to steady its crisis response as an independent consultant. What makes this move rare is the target: the SEC is warning named officers — CISO Tim Brown and CFO Barton Kalsu — that they personally may face legal action, not just the company.
The surrounding coverage shows the SEC treating the SolarWinds breach as a disclosure problem across the whole ecosystem: it later extracted a combined $7 million from Unisys, Check Point, Avaya, and Mimecast for negligently downplaying the hack's impact in customer disclosures, and Brown himself sat for an interview still facing those charges before they were largely dismissed in July 2024.
First-order effects
- Brown and Kalsu now face potential individual legal action over alleged concealment of vulnerabilities ahead of the 2020 attack, putting their personal liability — not just SolarWinds' corporate exposure — on the table.
- SolarWinds must defend a securities case built on its pre-breach disclosures while simultaneously managing the reputational aftermath of a hack that penetrated federal agencies.
Second-order effects
- Other vendors swept into the same breach are already paying: Unisys, Check Point, Avaya, and Mimecast settled with the SEC for a combined $7 million over disclosures that downplayed the incident's impact, showing the regulator pursuing every node that understated the damage.
- Rival software makers with federal customers face pressure to treat security posture as a material disclosure item, because the SEC has demonstrated it will read breach-related statements as investor-protection issues.
Third-order effects
- If the pattern held, breach disclosure would become a personal-liability matter for CISOs and CFOs at public companies, reshaping how security incidents get reported to investors — though the SEC's later dismissal of most charges and its eventual decision to drop the SolarWinds case entirely in November 2025 shows how contested and reversible this enforcement doctrine remains.
The trend: Regulators are increasingly treating corporate cyber incidents as securities-disclosure failures, testing whether individual executives — CISOs above all — should bear personal legal accountability for how breaches are disclosed.