Live data from Hacker News

SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

sec.gov

21–30 of 109 posts

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#21

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

Here it's worth remembering that CISO is a "specific" role; it does not necessarily connote "most senior security person in the company"; some companies have more than one; some companies have a "CSO" and/or a chief of "risk"; at Apple (for all I know) it might just mean "most senior security person in IS&T". Apple has a sprawling and multifunctional security team.

If your claim is that all of security at Apple somehow reports up through IS&T, I have some reason to believe that is not the case.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#22

"As the complaint alleges, SolarWinds’ public statements about its cybersecurity practices and risks were at odds with its internal assessments, including a 2018 presentation prepared by a company engineer and shared internally, including with Brown, that SolarWinds’ remote access set-up was “not very secure” and that someone exploiting the vulnerability “can basically do whatever without us detecting it until it’s t…

These are often times problems that sadly take a long time to fix. Were they at least trying? Or just straight up didn’t care?

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#23

Among other factors contributing to corporate/white-collar corruption & fraud, this is what happens when you have a culture of nepotism & nepotistic CEO. The HR Chief of SolarWinds is the cousin of the CEO (Sudhakar Ramakrishna) of SolarWinds. Same was true at their previous company (Pulse Secure). In many global cultures, this is completely normal-- and those are cultures which have high rates of endemic, prolific c…

lol. Let’s not throw Latin / Asian culture under the bus when the implicit alternative being posed is American culture. Pot meet kettle. Remember what old mate says to Ryan Gosling in the Barbie movie? “We’re just better at hiding it.”

This, nepotism is rife in private American companies of all kinds from my own experiences and others.

O God, there's at least one company, I personally have experience with that not only is a nepotistic hellhole, but is actively defrauding the government and a few big names. The result of spoiled brats getting control of a very niche private hardware engineering company after their father died.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#24

Among other factors contributing to corporate/white-collar corruption & fraud, this is what happens when you have a culture of nepotism & nepotistic CEO. The HR Chief of SolarWinds is the cousin of the CEO (Sudhakar Ramakrishna) of SolarWinds. Same was true at their previous company (Pulse Secure). In many global cultures, this is completely normal-- and those are cultures which have high rates of endemic, prolific c…

lol. Let’s not throw Latin / Asian culture under the bus when the implicit alternative being posed is American culture. Pot meet kettle. Remember what old mate says to Ryan Gosling in the Barbie movie? “We’re just better at hiding it.”

The fact that some culture becomes better at hiding it usually means that it's less accepted by the society, hence hiding it is more important.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#26

Among other factors contributing to corporate/white-collar corruption & fraud, this is what happens when you have a culture of nepotism & nepotistic CEO. The HR Chief of SolarWinds is the cousin of the CEO (Sudhakar Ramakrishna) of SolarWinds. Same was true at their previous company (Pulse Secure). In many global cultures, this is completely normal-- and those are cultures which have high rates of endemic, prolific c…

You’re right if global cultures includes all cultures - even US. It’s how businesses and governments work worldwide unfortunately. The USA just (and has) had multiple presidents who were nepotistic.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#27
”The volume of security issues being identified over the last month have [sic] outstripped the capacity of Engineering teams to resolve”… Rather than address these vulnerabilities, SolarWinds and Brown engaged in a campaign to paint a false picture of the company’s cyber controls

I read this is as we are sinking and we will take all of our customers down with us.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#28

I am going bet a pillow case of slightly squished mini candy bars that Tim Brown might have been a good technologist, but that he might have been told to sit down and color. I am saying this because reading the interview notes: > BROWN: It was crazy. So our CEO got a call in the morning from [Mandiant CEO] Kevin Mandia. And then he called me, and then the CTO for FireEye called me. That’s our nightmare moment. [Oct.…

Yeah, I think you really hit the nail on the head with this one. I want folks to be held accountable, but considering the forces/incentives at play, I worry what you're left with is a CISO role that no sane person would take, so instead it's just taken by grifters who take the "gambling" route - let's just hope the chance that some major breach happens doesn't do so on my watch, but if it's "damned if I do, damned if I don't", might as well collect a fat paycheck while I see what happens.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#29
post #21

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

Here it's worth remembering that CISO is a "specific" role; it does not necessarily connote "most senior security person in the company"; some companies have more than one; some companies have a "CSO" and/or a chief of "risk"; at Apple (for all I know) it might just mean "most senior security person in IS&T". Apple has a sprawling and multifunctional security team. If your claim is that all of security at Apple someh…

No, the bulk of security and privacy work at Apple happens elsewhere.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#30

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

If we're being critical here, I'd also argue that often the CISO's job and main concern is simply making sure they have the right paperwork and motions in place to pass a given set of industry audit standards. These people are not always even capable of understanding the technical security of a product.

Paper security like this is often a minimum bar, and sometimes even below minimum when the audit checklists lag best practices like "password rules" requirements did for so long.

I agree that if the CISO is liable, they should also actually be responsible, but making the CISO responsible won't by itself fix the industry's security issues.

Post reply on HN