An interview with SolarWinds CISO Tim Brown on the 2020 breach, facing SEC charges that were largely dismissed in July 2024, global cyber regulations, and more
SOX for cyber? … Federico Charosky : Yes, we need better cyber laws, but I don't think the lack of them was the fundamental problem behind SolarWinds (or any other high-profile supply chain issue) …
Context & Ripple Effects
The interview follows an unusually personal regulatory escalation: the SEC first sent Wells notices to SolarWinds executives, then filed disclosure-related cybersecurity charges over the breach. A court’s dismissal of most of that case shifted the immediate discussion from alleged failures toward the limits of securities-law enforcement as a cyber-governance tool.
SolarWinds’ response had already included bringing in former CISA director Christopher Krebs as an independent crisis adviser. The interview places that breach legacy alongside Tim Brown’s views on global cyber rules and Federico Charosky’s argument that stronger laws alone do not resolve supply-chain security failures.
First-order effects
- The largely dismissed SEC claims reduce the immediate legal pressure associated with the broadest allegations against SolarWinds and Brown, while leaving the company’s breach-era disclosure and security practices under public scrutiny.
- The interview gives the former target of the enforcement action a platform to distinguish regulatory compliance from the operational causes of supply-chain compromise.
Second-order effects
- Other public tech companies facing cyber-disclosure scrutiny gain a prominent example that securities-law claims can face meaningful judicial limits, even as the SEC’s prior outreach to tech and telecom companies showed the inquiry had spread beyond SolarWinds.
- Security leaders may push for cyber rules that clarify reporting and accountability while emphasizing ecosystem controls, rather than treating disclosure obligations as a substitute for supply-chain defense.
Third-order effects
- If regulators and courts continue to test the boundary between cyber incidents and securities disclosure, cyber governance is likely to develop through a mix of targeted rules, enforcement precedent, and operational standards rather than a single “SOX for cyber” model.
- The durable challenge is shifting accountability across software vendors, customers, and public authorities: legal obligations can shape incentives, but they cannot by themselves eliminate interconnected supply-chain risk.
The trend: SolarWinds is one data point in the shift from treating cyber incidents as isolated technical failures to treating them as board-level disclosure, accountability, and ecosystem-risk issues.