Live data from Hacker News

SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

sec.gov

11–20 of 109 posts

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#11
I am going bet a pillow case of slightly squished mini candy bars that Tim Brown might have been a good technologist, but that he might have been told to sit down and color.

I am saying this because reading the interview notes:

> BROWN: It was crazy. So our CEO got a call in the morning from [Mandiant CEO] Kevin Mandia. And then he called me, and then the CTO for FireEye called me. That’s our nightmare moment. [Oct. 26, 2021 Cybersecurity Dive]

Was the Mandiant CEO friends with Solarwinds CEO, to make the call to the CEO instead of the person that (presumably) signed their vendor contract, the CISO?

> SolarWinds did almost immediately was create a cyber-specific committee on your board

I read this as "there was no one, not even the CIO at the board."

If you are a CISO, and you are have to decide between your livelihood for the rest of your life guaranteed by a company, or your livelihood for the rest of your life taken by regulators, where do you go?

If the CISO says to the Corp "no, I am going public/won't lie/[insert insubordination]", no one will hire them thereafter.

If the CISO says "okay, let me sit and color", go to jail, and no one will hire them thereafter.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#12

"As the complaint alleges, SolarWinds’ public statements about its cybersecurity practices and risks were at odds with its internal assessments, including a 2018 presentation prepared by a company engineer and shared internally, including with Brown, that SolarWinds’ remote access set-up was “not very secure” and that someone exploiting the vulnerability “can basically do whatever without us detecting it until it’s t…

You're not reading that right: the problem isnt that this engineer knew the problem, it s that he gave management presentations about it and they didnt fix it.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#13
Among other factors contributing to corporate/white-collar corruption & fraud, this is what happens when you have a culture of nepotism & nepotistic CEO.

The HR Chief of SolarWinds is the cousin of the CEO (Sudhakar Ramakrishna) of SolarWinds. Same was true at their previous company (Pulse Secure).

In many global cultures, this is completely normal-- and those are cultures which have high rates of endemic, prolific corruption, such as South Asia & Latin America.

I would like to see more insiders speak out & blow the whistle on corrupt trade practices under this CEO.

If any investigators or journalists would like more info, feel free to contact: anti.corruption.123@proton.me

"As they sow, so shall they reap."

"In human life seek justice, truth, temperance and courage, and you will profit from the supreme good that you have discovered." (Marcus Aurelius)

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#14

6 months ago: > SolarWinds CISO Tim Brown has been named CISO of the Year by Globee Cybersecurity Awards for his work overseeing our Secure by Design initiative. > "Through our Secure by Design initiative and our ongoing commitment to efficient information-sharing and public-private partnerships, ..." This is like China and Saudi Arabia sitting on the UN human rights council.

[flagged]

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#15

"As the complaint alleges, SolarWinds’ public statements about its cybersecurity practices and risks were at odds with its internal assessments, including a 2018 presentation prepared by a company engineer and shared internally, including with Brown, that SolarWinds’ remote access set-up was “not very secure” and that someone exploiting the vulnerability “can basically do whatever without us detecting it until it’s t…

This was likely Ian Thornton Trump: https://www.newsweek.com/ex-solarwinds-adviser-warned-compan...

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#16

I am going bet a pillow case of slightly squished mini candy bars that Tim Brown might have been a good technologist, but that he might have been told to sit down and color. I am saying this because reading the interview notes: > BROWN: It was crazy. So our CEO got a call in the morning from [Mandiant CEO] Kevin Mandia. And then he called me, and then the CTO for FireEye called me. That’s our nightmare moment. [Oct.…

Those latter two statements are no doubt about why Alex Stamos called being the CSO "the worst job in the world"

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#18

Among other factors contributing to corporate/white-collar corruption & fraud, this is what happens when you have a culture of nepotism & nepotistic CEO. The HR Chief of SolarWinds is the cousin of the CEO (Sudhakar Ramakrishna) of SolarWinds. Same was true at their previous company (Pulse Secure). In many global cultures, this is completely normal-- and those are cultures which have high rates of endemic, prolific c…

I'm somewhat confident that the cultural problems predate those folks taking over SolarWinds.

Putting the national spin on this issue is inappropriate and contrary to the guidelines of this site.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#19

Among other factors contributing to corporate/white-collar corruption & fraud, this is what happens when you have a culture of nepotism & nepotistic CEO. The HR Chief of SolarWinds is the cousin of the CEO (Sudhakar Ramakrishna) of SolarWinds. Same was true at their previous company (Pulse Secure). In many global cultures, this is completely normal-- and those are cultures which have high rates of endemic, prolific c…

lol. Let’s not throw Latin / Asian culture under the bus when the implicit alternative being posed is American culture. Pot meet kettle.

Remember what old mate says to Ryan Gosling in the Barbie movie? “We’re just better at hiding it.”

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#20
In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting.

If I recall correctly, at Apple, the CISO role was some guy reporting to the corp IT org, entirely separate from core products and services. And we're talking about one of the most valuable and sophisticated tech companies in the world.

Amazon had an even wackier model, with separate "CISOs" for different orgs, the term meaning not much more than "a senior manager that we can put in touch with clients if needs be." Google now has a "cloud CISO" who is a nice techie guy and talks to customers, but is not actually the person in charge of the overall Google security org.

I get it that the SEC wants to change this culture and have a designated person meaningfully responsible for infosec risk, but it feels that it's a case of stick before the carrot. They have the power to reinterpret their own rules to elevate CISOs before they start cracking down on them with personal liability lawsuits.

And I'm betting that just like in the case of Uber, the CISO will end up in trouble, while all the execs will get to claim ignorance and walk free.

Post reply on HN