Live data from Hacker News

SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

sec.gov

71–80 of 109 posts

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#71

6 months ago: > SolarWinds CISO Tim Brown has been named CISO of the Year by Globee Cybersecurity Awards for his work overseeing our Secure by Design initiative. > "Through our Secure by Design initiative and our ongoing commitment to efficient information-sharing and public-private partnerships, ..." This is like China and Saudi Arabia sitting on the UN human rights council.

> Globee Never heard of it, but it looks like a pay to play, with dozens of awards. Not impressed https://globeeawards.com/cyber-security/

The dirty secret is that almost every award for companies is pay to play. Some just obfuscate it better than others (e.g. gartner, forester or other big boys) rather than making it a straight up cash for award play.

If you aren’t paying to talk to analysts, sponsor events for their customers, etc… they aren’t going to pay attention to you or listen to what kind of products/services you provide. You do the same thing with customers, put them on bullshit advisory boards or whatever.

Boom! You are part of a wave or end up in one of the quadrants.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#72

Earlier quoted context omitted.

I lost a lot of respect for Matt Levine with the pretzels he contorted himself into trying to defend the Texas Two Step as "really, truly, better for the plaintiffs", ignoring the two elephants in the room: if it was beneficial to the plaintiffs, why would the defendant go out of their way to do it? And how is it, by magical coincidence, that every firm that has done the Texas Two Step has managed to get out of payin…

Or maybe as an expert, he understands the corporate bankruptcy process better than you and most of us here.

He was a lawyer in securities a long time ago. That doesn't automatically make him an expert in all areas of commercial law.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#73

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

So they're basically a whipping boy?

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#74
post #30

Earlier quoted context omitted.

If we're being critical here, I'd also argue that often the CISO's job and main concern is simply making sure they have the right paperwork and motions in place to pass a given set of industry audit standards. These people are not always even capable of understanding the technical security of a product. Paper security like this is often a minimum bar, and sometimes even below minimum when the audit checklists lag bes…

The password example feels egregious, but keep in mind that the investigators spent months if not years combing through corporate records and are now showcasing the most embarrassing finds in the framing of their choice. I bet there's not a single company in the world where some engineer didn't at one point set up a dumb password as a part of some one-off integration. The job of the security team is to systematically…

Nation states like anyone else have budgets. No company is immune to the full weight of a major nation state but most of the time that is not brought to bear. You don't need to be impossible to hack, you just need to be hard enough that the value provided is less than the effort required.

Still a pretty tall order, but a few steps down from impossible.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#75
post #68

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

>I get it that the SEC wants to change this culture and have a designated person meaningfully responsible for infosec risk, but it feels that it's a case of stick before the carrot. They have that already, it’s the CEO - he is supposed to have ultimate responsibility which is why he (or she) gets obscene compensation. They should be incentivized to hire the best CISO he can find because he’s facing jail time if he do…

It's somewhat wild: I remember as a kid being taught that those with the power are the ones with the responsibility. And yet once I entered the workforce, it turns out it's the opposite.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#76

"As the complaint alleges, SolarWinds’ public statements about its cybersecurity practices and risks were at odds with its internal assessments, including a 2018 presentation prepared by a company engineer and shared internally, including with Brown, that SolarWinds’ remote access set-up was “not very secure” and that someone exploiting the vulnerability “can basically do whatever without us detecting it until it’s t…

He is not C-level.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#77
post #30

Earlier quoted context omitted.

If we're being critical here, I'd also argue that often the CISO's job and main concern is simply making sure they have the right paperwork and motions in place to pass a given set of industry audit standards. These people are not always even capable of understanding the technical security of a product. Paper security like this is often a minimum bar, and sometimes even below minimum when the audit checklists lag bes…

The password example feels egregious, but keep in mind that the investigators spent months if not years combing through corporate records and are now showcasing the most embarrassing finds in the framing of their choice. I bet there's not a single company in the world where some engineer didn't at one point set up a dumb password as a part of some one-off integration. The job of the security team is to systematically…

The problem is not being hacked. The SEC doesn't want companies to be hack proof or to force them to dump millions into security.

They want companies to be more transparent and honest with shareholders about their current security gaps and for them to report hacks in a timely manner. It's fine to be insecure but honest, what is never fine is lying to investors.

Bad investments are fine, bad investments pretending to be good ones aren't.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#78

Earlier quoted context omitted.

That sounds like a startup opportunity.

Sounds like a whistleblower opportunity. The government pays big bucks when you bring major fraud to their attention.

While waiting for those life changing $$$, are whistleblowers in America generally treated well and their identify kept anonymous?

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#79
post #75
post #68

Earlier quoted context omitted.

>I get it that the SEC wants to change this culture and have a designated person meaningfully responsible for infosec risk, but it feels that it's a case of stick before the carrot. They have that already, it’s the CEO - he is supposed to have ultimate responsibility which is why he (or she) gets obscene compensation. They should be incentivized to hire the best CISO he can find because he’s facing jail time if he do…

It's somewhat wild: I remember as a kid being taught that those with the power are the ones with the responsibility. And yet once I entered the workforce, it turns out it's the opposite.

They do have the responsibility, the responsibility to appoint the appropriate fall guy in accordance with the wishes of the board.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#80

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

So they're basically a whipping boy?

P.L.E.A.S.E.
Post reply on HN