The US SEC charges SolarWinds for failing to disclose alleged cybersecurity failures ahead of a breach by suspected Russian hackers that began as early as 2019
The Securities and Exchange Commission charged the company with failing to disclose its problems ahead of a breach …
Washington Post Tim Starks
Context & Ripple Effects
The charge followed an expanding record around the intrusion: SolarWinds had confirmed that its Office 365 environment was accessed for at least nine months beginning in late 2019, making disclosure practices central to the company’s breach narrative. The regulator had already signaled personal exposure through Wells notices to the CISO and CFO.
The case became a test of how far securities-law enforcement could reach into cybersecurity communications. Its later arc also limits the precedent: a judge dismissed most of the SEC’s claims in 2024, and the SEC ultimately dropped the case against SolarWinds and Tim Brown in 2025.
First-order effects
- SolarWinds and the SEC entered a high-stakes enforcement dispute over whether the company’s cybersecurity disclosures adequately reflected known risks before the breach.
- Company security and finance leaders faced heightened scrutiny because the alleged disclosure failures were tied to internal knowledge and public investor communications.
Second-order effects
- Other public companies had reason to recheck whether risk disclosures, incident reporting, and internal security assessments aligned; the later SEC actions involving firms affected by the same supply-chain attack show that disclosure language became an enforcement focus.
- The case raised the compliance cost of translating technical security findings into investor-facing statements, putting CISOs, legal teams, and finance executives under closer coordination pressure.
Third-order effects
- The mixed litigation outcome suggests a durable tension rather than a settled rule: regulators can press cyber-disclosure theories, but courts may constrain claims that treat imperfect security posture or general risk language as securities fraud.
- If enforcement continues, cybersecurity governance is likely to become more closely integrated with public-company disclosure controls, while the boundary of individual CISO liability remains contested.
The trend: Cybersecurity incidents are increasingly being treated as disclosure-control and governance issues, even as courts test the limits of that enforcement approach.
Related: SolarWinds · SEC · SEC drops SolarWinds case against company and CISO · Judge dismisses most SEC claims against SolarWinds · SolarWinds confirms SEC Wells notices to executives
Related Coverage
- SEC Charges SolarWinds and Chief Information Security Officer with Fraud, Internal Control Failures US Securities and Exchange Commission
- Transparency, Information-Sharing, and Collaboration Make the Software Industry More Secure. We Must Not Risk Our Progress. Orange Matter · Sudhakar Ramakrishna
- SEC accuses SolarWinds CISO of misleading investors before Russian cyberattack TechCrunch · Zack Whittaker
- SEC sues SolarWinds and its CISO for fraudulent cybersecurity disclosures CSO Online
- Cyber Chiefs Worry About Personal Liability as SEC Sues SolarWinds, Executive Wall Street Journal · Kim S. Nash
- SEC claims SolarWinds misled investors about cyber practices before 2020 breach Axios · Sam Sabin
- SEC sues SolarWinds for misleading investors before 2020 hack BleepingComputer · Sergiu Gatlan
- SEC sues SolarWinds, alleging serious security failures ComputerWeekly.com · Alex Scroxton
- US SEC sues SolarWinds for concealing cyber risks before massive hacking Reuters
- Feds sue cybersecurity firm SolarWinds, its security exec over massive 2020 hack WRAL TechWire
- SEC sues SolarWinds and CISO for alleged deception over major cyberattack Stack Diary · Alex Ivanovs
- U.S. sues SolarWinds for fraud over alleged cyber security neglect ahead of stunning Russian hack into Justice and Homeland Security departments Associated Press · Frank Bajak
- SolarWinds faces SEC lawsuit after 2020 hack Financial Times
- SEC Sues SolarWinds Over 2020 Hack Attributed to Russians Wall Street Journal
- My take on the SEC complaint against SolarWinds and its CISO: — 1) Yes, it's wonderful that at long last we have a corporate regulator bringing a case against a company and its CISO for nonsensical cyber governance on market disclosure and internal controls grounds. This is HISTORIC. … @ravirockks@infosec.exchange · Ravi Nayyar
- So if SolarWinds is getting sued for being hacked by a nation state, who's next? It's hard to tell from those quotes ("Our remote access setup is not very secure" etc.) what the real situation is - especially when there are LOTS of companies that aren't even having those conversations. @Lee_Holmes@infosec.exchange
- There's also the SEC attacking SolarWinds's risk disclosures in its SEC filings as failing to convey the gravity of the risks. What's striking to me is - again - this is the kind of allegation private plaintiffs make (w/ mixed success). I don't think it's at all common to see it from the SEC: … @annmlipton@esq.social · Ann Lipton
- We just got a corporate letter from Solarwinds talking a little about this and mentioning that the SEC's charges are misguided. — It feels a little icky to have a company try to tell me that the SEC investigation is wrong rather than just saying due to X and X, we're under investigation, etc etc. … @glitch25@clacks.link · Marcos
- Regulators are signaling that the old model of underspending on security and instead dealing with breaches downstream may be obsolete. … Tony Rajakumar
- SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures Hacker News
Discussion
-
@zackwhittaker@mastodon.social
Zack Whittaker
on mastodon
New, by me: U.S. SEC has charged SolarWinds and its CISO Timothy Brown with fraud and internal control failures for allegedly misleading investors about the company's cybersecurity practices prior to the Russian hack in 2019. …
-
@dangillmor@mastodon.social
Dan Gillmor
on mastodon
Amazing, a software company may be accountable for incredibly shoddy security practices that have harmed countless companies and people directly and indirectly. Biden's SEC has sued, not specifically because of the crap security, but because, it says, the company lies about how …
-
@securepeacock
Christopher Peacock
on x
I believe SolarWinds was passing security compliance audits during the time frame referenced by the SEC. So is this further evidence that compliance does not equal security? Also, are security audits broken if they don't provide reasonable assurance to shareholders?
-
@quentynblog
Quentyn Taylor
on x
I wonder if given the news that the SolarWinds ciso is also being sued that people will be so keen to accept the ciso title without the ability to execute ? There are many with the title but not the seat on the board and no ability to actually discharge their responsibility
-
@bschne
Benjamin Schneider
on x
From the SolarWinds SEC complaint [image]
-
@securethisnow
MrBill
on x
Will <thisisfine.jpg> land your CISO in hot water? Guess I am not making any more jokes at the office 😬 [image]
-
@secgov
@secgov
on x
Today we announced charges against SolarWinds Corporation and its chief information security officer for fraud and internal control failures relating to allegedly known cybersecurity risks and vulnerabilities.
-
@myraccoonhands
@myraccoonhands
on x
Stuff like this makes me reconsider my goal to become a CISO... I don't wanna be the Chief Information Scapegoat Officer 👀 This isn't a comment on whether or not they're deserving of this, but more so that I don't know if I actually want this to be a possibility in MY future.
-
@uk_daniel_card
@uk_daniel_card
on x
This can't be so! Every company after they are pwn3d says they take security super cerial!
-
@kchoudhu
Kamil C
on x
I am excited for CISO salaries to go up by at least 50%.
-
@moonalice
Roger McNamee
on x
It is about time someone charged SolarWinds with a crime. We need to hold all corporations accountable for security and privacy ... but especially those whose business is security or privacy related.
-
@mattjay
Matt Johansen
on x
👀 [image]
-
@kimzetter
Kim Zetter
on x
SEC charges SolarWinds' CISO Tim Brown with fraud & failure to have internal controls. It makes me wonder how many software makers - Microsoft included - had sufficiently secured their build environments in 2020 to prevent a supply-chain hack. Anyone know? https://www.sec.gov/...
-
@rmhrisk
Ryan Hurst
on x
Regulatory actions like those against Uber's CSO and SolarWinds' CISO aim to enforce executive accountability, especially in cybersecurity. While beneficial, these actions may drive security discussions behind closed doors to evade scrutiny, for example, organizations may begin..…
-
@frankmcg
Frank McGovern
on x
The industry is rapidly changing. It's going to become increasingly difficult to lead a security team when you do not have security - or at least technology - experience. It made sense when security was infantile and the industry needed any leaders that could function.
-
@kimzetter
Kim Zetter
on x
There has also been a lot of criticism of Microsoft over its failure to fix the authentication problem with Active Directory that allowed the SolarWinds hackers to escalate access and steal email from victims. I'm wondering if SEC will address that. https://www.crn.com/...
-
@mattjay
Matt Johansen
on x
Holy crap - SEC Charges SolarWinds and Chief Information Security Officer with Fraud, Internal Control Failures https://www.sec.gov/...
-
@malwarejake
Jake Williams
on x
The SEC litigation against Solarwinds is going to do more to advance security than another decade of breaches would. CISOs are often beaten into submission under threat of losing their jobs. The SEC gave them the holy hand grenade to fight back against any pressure to mislead.
-
@mattjay
Matt Johansen
on x
Oh come on [image]
-
@stevewerby
Steve Werby
on x
Left: SolarWinds CISO named CISO of the Year in April. Right: Today the SEC charged the same CISO with fraud for actions taken during his tenure as SolarWinds CIS0. Globee is a dubious pay-to-play award mill. Ah, the irony of the press release 6 months before the SEC 💣🫳. [image]
-
@ohaiom
Jason Gottlieb
on x
https://sec.gov/ | SEC Charges SolarWinds and Chief Information Security Officer with Fraud, Internal Control Failures Let me explain how this is relevant to the SEC v Coinbase case. 1/ https://www.sec.gov/...
-
@frankmcg
Frank McGovern
on x
SEC is charging SolarWinds CISO for their breach due to hiding and inaccurately painting their security posture picture. I probably know a few “people-leader CISO's” that probably fall into this. Be warned. Know what you're doing or let someone else lead. https://therecord.media/…
-
@jgreigj
Jon Greig
on x
Here is what a #SolarWinds spokesperson told me in response to the #SEC action: “We are disappointed by the SEC's unfounded charges related to a Russian cyberattack on an American company and are deeply concerned this action will put our national security at risk.” cont.
-
@johnnysaks130
John Sakellariadis
on x
The SEC is suing SolarWinds and its CISO, Timothy Brown, “for fraud and internal control failures” stemming from the infamous 2020 hack that hit USG networks. Not sure this is going to sit well with many in the community... https://www.sec.gov/...
-
@jgreigj
Jon Greig
on x
The @SECGov charged SolarWinds CISO Timothy Brown with fraud for his role in allegedly lying to investors by “overstating SolarWinds' cybersecurity practices and understating or failing to disclose known risks.” @TheRecord_Media #SolarWinds #SEC https://therecord.media/...
-
r/technology
r
on reddit
SEC Charges SolarWinds and Chief Information Security Officer with Fraud, Internal Control Failures