In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…
If we're being critical here, I'd also argue that often the CISO's job and main concern is simply making sure they have the right paperwork and motions in place to pass a given set of industry audit standards. These people are not always even capable of understanding the technical security of a product. Paper security like this is often a minimum bar, and sometimes even below minimum when the audit checklists lag bes…
What feels particularly weird here is that SolarWinds wasn't compromised by a Bulgarian cybercrime gang. They were compromised by a nation state. While the SEC is notionally focusing on other stuff, this is ultimately the company's original sin. How many businesses, no matter how strong their security posture, can really say that they're immune to that?