Live data from Hacker News

SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

sec.gov

101–109 of 109 posts

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#101
post #69

I’m don’t like that this is being pursued by the SEC. Especially since the likely penalty will be a large chuck of money that gets paid to… the SEC. Too much like extortion. But as Matt Levine often reminds us - everything is securities fraud. If a bad thing happens and you did not warn investors about it beforehand, you can be sued for securities fraud by the SEC. It’s almost like it’s illegal for investors to lose…

This is like saying police officers shouldn't enforce speed limits because the ticket ends up back in the police department, and you could certainly make a point for a conflict of interest, but there is traceable proof. What actually happened in the SolarWinds instance seems to be actual deception and fraud . Plenty of companies go out of business due to competition, this isn't one of those instances.

Ticket money shouldn't end up back in the police fund. It should go into the general fund.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#102

Earlier quoted context omitted.

I lost a lot of respect for Matt Levine with the pretzels he contorted himself into trying to defend the Texas Two Step as "really, truly, better for the plaintiffs", ignoring the two elephants in the room: if it was beneficial to the plaintiffs, why would the defendant go out of their way to do it? And how is it, by magical coincidence, that every firm that has done the Texas Two Step has managed to get out of payin…

Or maybe as an expert, he understands the corporate bankruptcy process better than you and most of us here.

I have no doubt he understands the process better than me. Absolutely.

The outcomes speak for themselves though. Companies projecting $50B in liabilities for decades of injury to thousands of people funneling them into a shell company, "pledging" to fully fund that company, throwing maybe $100-300M into them, and then shuttering the company without fulfilling that pledge. That's the common outcome to each Texas Two Step story.

But Matt and these companies and the firms (I mean firm, there's essentially one firm whose livelihood is this process) all patronizingly try to convince us that that outcome is somehow "better for plaintiffs and consumers", when the only one that seems to actually win is the corporation that successfully shed the boat anchor it put around its own neck.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#103
post #63
post #16

Earlier quoted context omitted.

Those latter two statements are no doubt about why Alex Stamos called being the CSO "the worst job in the world"

Who holds the CSO-equivalent job in the government? It's the president or prime minister, isn't it? Because ultimately all decisions have an impact on security.

CISO =/= CSO.

The Federal Chief Information Security Officer, through the OMB is Chris DeRusha.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#104
The SolarWinds case ups the stakes for CISOs everywhere. Are you secure? Yeah? Would you bet your life on it?

How about a "dissenting opinion" envelope where a CISO lodges his most critical objections to the company's most egregious security sins? This can be discoverable as evidence if there is ever an incident. This clearly establishes that the CISO performed his function and warned of the risk but was overruled by the CEO or the Board. "Yeah? We can't afford MFA? No problem. I'm just going to note my dissenting opinion just in case this comes back to bite us."

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#105

Here is Matt Levine’s, of Bloomberg fame, famous article “Everything Everywhere is Securities Fraud.” https://www.bloomberg.com/opinion/articles/2019-06-26/everyt... Now cybersecurity included.

I lost a lot of respect for Matt Levine with the pretzels he contorted himself into trying to defend the Texas Two Step as "really, truly, better for the plaintiffs", ignoring the two elephants in the room: if it was beneficial to the plaintiffs, why would the defendant go out of their way to do it? And how is it, by magical coincidence, that every firm that has done the Texas Two Step has managed to get out of payin…

Do you have a link to Matt Levine's article? I've just skimmed his emails that have "Texas Two-Step" and don't see any defense thereof (mostly just explanations around J&J), but could well have missed it/before I started subscribing.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#106
post #18

Earlier quoted context omitted.

I'm somewhat confident that the cultural problems predate those folks taking over SolarWinds. Putting the national spin on this issue is inappropriate and contrary to the guidelines of this site.

You mean the spin they themselves induced on a broad cultural scale, over the course of centuries, such that it has become prolific and engrained? ...No one is allowed to comment on it.. because... Fraudulent Activities should be Accepted, And Not condemned, And no one is allowed to discuss it? Just trying to understand your logic, truly in good faith. ... And other nations should just accept it eh? `Fraid not, ole c…

None of this even faintly describes the problems at SolarWinds, which were in place before the current staff is in place.

Also, that which explains everything explains nothing.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#107

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

He's being sued for his actions not because of his position - he was responsible for acknowledging the issues internally and not acting on them, he was responsible for the language of statements made to shareholders that misled them about the state of security.

If he had sent an email to the CEO saying "we have a problem, we need to do something about this" and the CEO had overruled him, the CEO would be being sued directly.

It doesn't really matter what his role or how high up he was - he was found standing over the body holding the smoking gun.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#108
Well, when you are a CISO you also need to know your actual responsibility.

In Europe you are a normal employee with normal responsibilities and nobody sane would risk their future by going against the law. The IKEA CSO did that and was in jail.

I was asked twice to provide a statement for a US court (being European and living there). Just for the fun I asked or legal department to provide me with a full written explanation of the consequences, the risks and how much I would get paid to do something like that that is outside my contact. Everything stopped there and some poor fellow in the US did that instead.

I then asked why this isn't the legal dept that is issuing these statements in the name of the company. I got some complex explanation why they could not bear the risk.

Being a CISO means managing risks, including yours.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#109

Earlier quoted context omitted.

>> If any investigators or journalists > why should anyone trust you The statement clears opens the validation to a capable person, what’s your concern exactly

A brand new account fishing for confidential info, that when asked why people should do so has gone off the deep end and started calling me names. Telling me to move to a corrupt country where I'd be welcome, etc. To me (!), that doesn't seem like a level headed person that should be entrusted with anything important. You may feel otherwise of course. ;)

You imply investigators & journalists PROVIDE confidential info

when in actuality, they RECEIVE confidential info

you seem to be confused about how investigations work.

Post reply on HN