Unisys, Check Point, Avaya, and Mimecast to pay a combined $7M to the SEC, which says they negligently downplayed the impact of the SolarWinds supply chain hack
The companies fined are: Avaya, Check Point, Mimecast, and Unysis. — https://techcrunch.com/... X: Mike Swift / @swiftstories : The @SECGov is starting to hand out some real #cybersecurity fines, hitting four companies with penalties over lax disclosures. https://www.sec.gov/... Lisa Forte / @lisaforteuk : Keeping quiet isn't an option anymore. You have to have a plan and you have to be suitably transparent. Denying or misleading statements can get you in a world of trouble @weldpond : SEC fines the companies that minimized the severity of the attacks they were required to disclose. @vxdb : The SEC has charged four companies with making misleading disclosures regarding the SolarWinds supplychain attack in 2020. Unisys, Avaya Holdings, Check Point Software Technologies, and Mimecast are each mentioned in the filings and have agreed to pay the fines in order to Joe Tidy / @joetidy : “Downplaying the extent of a material cybersecurity breach is a bad strategy. In two of these cases, the relevant cybersecurity risk factors were framed hypothetically or generically when the companies knew the warned of risks had already materialized” says SEC [image] Joe Tidy / @joetidy : SEC just fined 4 cyber firms millions for deliberately misleading the public about the infamous SolarWinds cyber attack incident in 2020. Unisys, CheckPoint, Mimecast, Avaya failed to admit they too had been breached in the huge espionage attack allegedly carried about by Russia [image] @secgov : Today we charged four current and former public companies - Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies Ltd, and Mimecast Limited - with making materially misleading disclosures regarding cybersecurity risks and intrusions. https://www.sec.gov/... [image] Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: The SEC fined four tech companies with a combined $7 million fine for “negligently” downplaying and minimizing the impact of the SolarWinds supply chain hack. The companies fined are: Avaya, Check Point, Mimecast, and Unysis. https://techcrunch.com/... LinkedIn: Elizabeth Wharton : SEC Shots fired: “Materially misleading” disclosures - downplaying the risks & intrusions leads to civil penalties for four companies (ranging $900k - $4m). … Christopher Hetner : SEC Charges Four Companies With Misleading Cyber Disclosures — Folks this is getting real for corporate directors! … Melanie Ensign : I keep telling you all to stop treating security comms like run of the mill crisis comms. — According to the SEC's orders, Unisys, Avaya …
Context & Ripple Effects
This closes a regulatory arc that moved from SEC action against SolarWinds over alleged pre-breach disclosure failures to a broader inquiry into how technology and telecom companies handled the incident.
The settlements show that the enforcement focus extended beyond the compromised supplier to customers’ public characterizations of exposure and impact. That expands the practical significance of the SEC’s earlier case against SolarWinds over cybersecurity disclosures.
First-order effects
- Unisys, Avaya, Check Point, and Mimecast will pay $7 million collectively and must account for SEC findings that their SolarWinds-related disclosures were materially misleading.
- The four companies’ security, legal, and investor-relations teams face a clearer immediate requirement: align public incident statements with what internal investigations establish about impact.
Second-order effects
- Other public companies affected by shared-service or supply-chain incidents are likely to tighten review of preliminary breach statements, particularly where technical findings evolve after disclosure.
- Cybersecurity vendors and enterprise customers may place greater value on incident-response processes that preserve evidence and connect technical assessments to securities-reporting decisions.
Third-order effects
- The enforcement pattern points toward cybersecurity disclosure becoming a governance and controls issue, not solely an incident-response function, as regulators test whether public statements accurately reflect known risk.
- If this approach persists, supply-chain breaches could create disclosure exposure across an affected ecosystem rather than concentrating it on the initially compromised provider.
The trend: Cyber regulation is shifting toward accountability for how public companies communicate the business impact of interconnected security incidents.