Live data from Hacker News

SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

sec.gov

31–40 of 109 posts

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#31

I am going bet a pillow case of slightly squished mini candy bars that Tim Brown might have been a good technologist, but that he might have been told to sit down and color. I am saying this because reading the interview notes: > BROWN: It was crazy. So our CEO got a call in the morning from [Mandiant CEO] Kevin Mandia. And then he called me, and then the CTO for FireEye called me. That’s our nightmare moment. [Oct.…

Yeah, I think you really hit the nail on the head with this one. I want folks to be held accountable, but considering the forces/incentives at play, I worry what you're left with is a CISO role that no sane person would take, so instead it's just taken by grifters who take the "gambling" route - let's just hope the chance that some major breach happens doesn't do so on my watch, but if it's "damned if I do, damned if…

he could have resigned

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#32
post #26

Among other factors contributing to corporate/white-collar corruption & fraud, this is what happens when you have a culture of nepotism & nepotistic CEO. The HR Chief of SolarWinds is the cousin of the CEO (Sudhakar Ramakrishna) of SolarWinds. Same was true at their previous company (Pulse Secure). In many global cultures, this is completely normal-- and those are cultures which have high rates of endemic, prolific c…

You’re right if global cultures includes all cultures - even US. It’s how businesses and governments work worldwide unfortunately. The USA just (and has) had multiple presidents who were nepotistic.

[deleted]

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#34
post #31

Earlier quoted context omitted.

Yeah, I think you really hit the nail on the head with this one. I want folks to be held accountable, but considering the forces/incentives at play, I worry what you're left with is a CISO role that no sane person would take, so instead it's just taken by grifters who take the "gambling" route - let's just hope the chance that some major breach happens doesn't do so on my watch, but if it's "damned if I do, damned if…

he could have resigned

Exactly my point - if he resigned quietly, the company would hire a "yes man" that exactly fits the profile I described. If he resigned loudly, he probably would be pretty unhireable, at least as another CISO.

In neither case do the customers at any company get the benefit of actual improved security.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#35
post #21

Earlier quoted context omitted.

Here it's worth remembering that CISO is a "specific" role; it does not necessarily connote "most senior security person in the company"; some companies have more than one; some companies have a "CSO" and/or a chief of "risk"; at Apple (for all I know) it might just mean "most senior security person in IS&T". Apple has a sprawling and multifunctional security team. If your claim is that all of security at Apple someh…

No, the bulk of security and privacy work at Apple happens elsewhere.

Oh, we're saying the same thing, and I misconstrued you; I thought you were making a comment about how lackadaisical Apple is about security, but you're just saying "CISO" isn't that big a thing. I agree! Sorry about that.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#36
post #25

The billion dollar question: do we think SEC filing disclosures are about to get a bit more interesting to read? Or is the standard boiler plate "we might get hacked, our controls may not be sufficient" going to remain?

I don't see this going in any direction other than a boilerplate that will become something that is ignored.

> SolarWinds and Brown defrauded investors by overstating SolarWinds' cybersecurity practices and understating or failing to disclose known risks.

In a nutshell, couldn't they say that in some way about any security software company?

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#37

Earlier quoted context omitted.

lol. Let’s not throw Latin / Asian culture under the bus when the implicit alternative being posed is American culture. Pot meet kettle. Remember what old mate says to Ryan Gosling in the Barbie movie? “We’re just better at hiding it.”

This, nepotism is rife in private American companies of all kinds from my own experiences and others. O God, there's at least one company, I personally have experience with that not only is a nepotistic hellhole, but is actively defrauding the government and a few big names. The result of spoiled brats getting control of a very niche private hardware engineering company after their father died.

That sounds like a startup opportunity.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#38

Among other factors contributing to corporate/white-collar corruption & fraud, this is what happens when you have a culture of nepotism & nepotistic CEO. The HR Chief of SolarWinds is the cousin of the CEO (Sudhakar Ramakrishna) of SolarWinds. Same was true at their previous company (Pulse Secure). In many global cultures, this is completely normal-- and those are cultures which have high rates of endemic, prolific c…

And why should people trust you?

You could just be someone looking to blackmail companies with damaging insider info.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#39

Earlier quoted context omitted.

lol. Let’s not throw Latin / Asian culture under the bus when the implicit alternative being posed is American culture. Pot meet kettle. Remember what old mate says to Ryan Gosling in the Barbie movie? “We’re just better at hiding it.”

The fact that some culture becomes better at hiding it usually means that it's less accepted by the society, hence hiding it is more important.

Alternatively, they make their behaviour legally acceptable through legislation changes.
Post reply on HN