Live data from Hacker News

SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

sec.gov

1–10 of 109 posts

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#2
It’s interesting to see SEC go after a CISO, yes he was at the helm but can’t the one to patch systems… yes they had an ongoing attack but disclosing that to shareholders is a sensitive affair… they were also a technology provider to the US government. I honestly think that is what got them the teeth of the SEC.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#3

  "As the complaint alleges, SolarWinds’ public statements about its cybersecurity practices and risks were at odds with its internal assessments, including a 2018 presentation prepared by a company engineer and shared internally, including with Brown, that SolarWinds’ remote access set-up was “not very secure” and that someone exploiting the vulnerability “can basically do whatever without us detecting it until it’s too late,” which could lead to “major reputation and financial loss” for SolarWinds. Similarly, as alleged in the SEC’s complaint, 2018 and 2019 presentations by Brown stated, respectively, that the “current state of security leaves us in a very vulnerable state for our critical assets” and that “[a]ccess and privilege to critical systems/data is inappropriate.”"
So I think if I'm reading that right, he knew things were “not very secure” and part of his role was to disclose that, and he didn't? I assume there's some rules in place that C level folks sign off on statements and he's the one to sign off on statements about security?

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#4
post #2

It’s interesting to see SEC go after a CISO, yes he was at the helm but can’t the one to patch systems… yes they had an ongoing attack but disclosing that to shareholders is a sensitive affair… they were also a technology provider to the US government. I honestly think that is what got them the teeth of the SEC.

They weren't charged for having deficiencies, they were charged for knowing about their deficiencies and lying about them:

> SolarWinds allegedly misled investors by disclosing only generic and hypothetical risks at a time when the company and Brown knew of specific deficiencies in SolarWinds’ cybersecurity practices as well as the increasingly elevated risks the company faced at the same time.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#5
post #2

It’s interesting to see SEC go after a CISO, yes he was at the helm but can’t the one to patch systems… yes they had an ongoing attack but disclosing that to shareholders is a sensitive affair… they were also a technology provider to the US government. I honestly think that is what got them the teeth of the SEC.

CISOs are still often not considered C-suite, and rarely get called to boardrooms.

Commensurating with the new risks for a CISO, a seat in the C-suite, E&O coverage, and nice parachute are the minimum CISOs should get.

Edit: I understand that in this case there were false statements made. That still does not remove the new risk for other CISOs to be dragged into quagmires they were not responsible for (see regulation discrepancies between various US, UK, or EU departments).

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#6
6 months ago:

> SolarWinds CISO Tim Brown has been named CISO of the Year by Globee Cybersecurity Awards for his work overseeing our Secure by Design initiative.

> "Through our Secure by Design initiative and our ongoing commitment to efficient information-sharing and public-private partnerships, ..."

This is like China and Saudi Arabia sitting on the UN human rights council.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#7
post #4
post #2

It’s interesting to see SEC go after a CISO, yes he was at the helm but can’t the one to patch systems… yes they had an ongoing attack but disclosing that to shareholders is a sensitive affair… they were also a technology provider to the US government. I honestly think that is what got them the teeth of the SEC.

They weren't charged for having deficiencies, they were charged for knowing about their deficiencies and lying about them: > SolarWinds allegedly misled investors by disclosing only generic and hypothetical risks at a time when the company and Brown knew of specific deficiencies in SolarWinds’ cybersecurity practices as well as the increasingly elevated risks the company faced at the same time.

[deleted]

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#9

"As the complaint alleges, SolarWinds’ public statements about its cybersecurity practices and risks were at odds with its internal assessments, including a 2018 presentation prepared by a company engineer and shared internally, including with Brown, that SolarWinds’ remote access set-up was “not very secure” and that someone exploiting the vulnerability “can basically do whatever without us detecting it until it’s t…

[deleted]
Post reply on HN