Live data from Hacker News

SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

sec.gov

41–50 of 109 posts

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#41
post #30

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

If we're being critical here, I'd also argue that often the CISO's job and main concern is simply making sure they have the right paperwork and motions in place to pass a given set of industry audit standards. These people are not always even capable of understanding the technical security of a product. Paper security like this is often a minimum bar, and sometimes even below minimum when the audit checklists lag bes…

The password example feels egregious, but keep in mind that the investigators spent months if not years combing through corporate records and are now showcasing the most embarrassing finds in the framing of their choice. I bet there's not a single company in the world where some engineer didn't at one point set up a dumb password as a part of some one-off integration. The job of the security team is to systematically track down stuff like that, but you never reach 100%. There are things you don't see.

What feels particularly weird here is that SolarWinds wasn't compromised by a Bulgarian cybercrime gang. They were compromised by a nation state. While the SEC is notionally focusing on other stuff, this is ultimately the company's original sin. How many businesses, no matter how strong their security posture, can really say that they're immune to that?

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#42
post #12

"As the complaint alleges, SolarWinds’ public statements about its cybersecurity practices and risks were at odds with its internal assessments, including a 2018 presentation prepared by a company engineer and shared internally, including with Brown, that SolarWinds’ remote access set-up was “not very secure” and that someone exploiting the vulnerability “can basically do whatever without us detecting it until it’s t…

You're not reading that right: the problem isnt that this engineer knew the problem, it s that he gave management presentations about it and they didnt fix it.

The problem isn’t that they didn’t fix it.

It’s that they knew about it and didn’t disclose it.

When a company IPOs the SEC requires it to file a document that contains all known risks to the business and all possible factors that could negatively impact the company’s value over time. It sounds like they failed to include this specific known incident in their filings with the government.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#43
post #25

The billion dollar question: do we think SEC filing disclosures are about to get a bit more interesting to read? Or is the standard boiler plate "we might get hacked, our controls may not be sufficient" going to remain?

According to wikipedia SolarWinds suffered one of the largest cyberattacks against a company in history - one that also directly affected thousands of consumer devices (not just a company backend). This might be a unique consequence of a unique situation. But who knows.

> In February 2021, Microsoft President Brad Smith said that it was "the largest and most sophisticated attack the world has ever seen".

https://en.wikipedia.org/wiki/2020_United_States_federal_gov...

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#44
post #18

Among other factors contributing to corporate/white-collar corruption & fraud, this is what happens when you have a culture of nepotism & nepotistic CEO. The HR Chief of SolarWinds is the cousin of the CEO (Sudhakar Ramakrishna) of SolarWinds. Same was true at their previous company (Pulse Secure). In many global cultures, this is completely normal-- and those are cultures which have high rates of endemic, prolific c…

I'm somewhat confident that the cultural problems predate those folks taking over SolarWinds. Putting the national spin on this issue is inappropriate and contrary to the guidelines of this site.

You mean the spin they themselves induced on a broad cultural scale, over the course of centuries, such that it has become prolific and engrained?

...No one is allowed to comment on it.. because... Fraudulent Activities should be Accepted, And Not condemned, And no one is allowed to discuss it? Just trying to understand your logic, truly in good faith.

... And other nations should just accept it eh? `Fraid not, ole chap.

...After all: Isn't that how they got there-- by silencing opposition to their activities?

______________

"Nepotism has been and remains one of the biggest curses of political development in South and Southeast Asia." [1]

"In the late 20th century, some Asian leaders including former Malaysian Prime Minister Mahathir bin Mohamad advocated "Asian-style capitalism," which meant a state- or family-led economy. But this system is showing signs of doing more harm than good to many Asian nations which have joined the ranks of middle-income countries." [2]

"When a leader gives his daughter a government contract, it’s nepotism. But it’s also cooperation at the level of the family, well explained by inclusive fitness, undermining cooperation at the level of the state. When a manager gives her friend a job, it’s cronyism. But it’s also cooperation at the level of friends, well explained by reciprocal altruism , undermining the meritocracy." [3]

... "It’s no surprise that family-oriented cultures like Mexico and Brazil are also high on corruption, particularly nepotism." [3]

[1] "The Curse of Nepotism". Blog Post by Joshua Kurlantzick. January 7, 2011. https://www.cfr.org/blog/curse-nepotism

[2] "Asia's emerging countries need to move away from nepotism, cronyism". Nikkei Asia - Business News. July 26, 2014

[3] "In Latin America as in the wider world, corruption is rooted in our relationships". London School of Economics and Political Science (Latin America and Caribbean Center). Michael Muthukrishna. October 23rd, 2017

[General Reference] "The Corruption Perceptions Index (CPI) is an index which ranks countries "by their perceived levels of public sector corruption, as determined by expert assessments and opinion surveys." https://en.wikipedia.org/wiki/Corruption_Perceptions_Index

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#45
post #26

Among other factors contributing to corporate/white-collar corruption & fraud, this is what happens when you have a culture of nepotism & nepotistic CEO. The HR Chief of SolarWinds is the cousin of the CEO (Sudhakar Ramakrishna) of SolarWinds. Same was true at their previous company (Pulse Secure). In many global cultures, this is completely normal-- and those are cultures which have high rates of endemic, prolific c…

You’re right if global cultures includes all cultures - even US. It’s how businesses and governments work worldwide unfortunately. The USA just (and has) had multiple presidents who were nepotistic.

[deleted]

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#46
post #10
post #8

Now do Kaseya!

If you have something interesting to say about Kaseya (and it's on topic) by all means say it. But please don't leave these kinds of contentless "now do X" posts here.

Oh sure - I could talk about how their CISO is a former FBI agent who, prior to joining the company, was responsible for investigating the distribution of ransomware via their VSA product. Nothing shady there.

Or perhaps that their (rapidly shrinking) security team has been told to communicate via Signal so their messages can't be subpoenaed successfully.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#47

Among other factors contributing to corporate/white-collar corruption & fraud, this is what happens when you have a culture of nepotism & nepotistic CEO. The HR Chief of SolarWinds is the cousin of the CEO (Sudhakar Ramakrishna) of SolarWinds. Same was true at their previous company (Pulse Secure). In many global cultures, this is completely normal-- and those are cultures which have high rates of endemic, prolific c…

And why should people trust you? You could just be someone looking to blackmail companies with damaging insider info.

[flagged]

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#48

Here is Matt Levine’s, of Bloomberg fame, famous article “Everything Everywhere is Securities Fraud.” https://www.bloomberg.com/opinion/articles/2019-06-26/everyt... Now cybersecurity included.

I lost a lot of respect for Matt Levine with the pretzels he contorted himself into trying to defend the Texas Two Step as "really, truly, better for the plaintiffs", ignoring the two elephants in the room: if it was beneficial to the plaintiffs, why would the defendant go out of their way to do it? And how is it, by magical coincidence, that every firm that has done the Texas Two Step has managed to get out of paying up an average of over 90% (approaching 98% in a few cases) of their anticipated liabilities for decades of malfeasance and injury?

Matt and these firms would like us to believe that we should just trust them, "it will be so much more convenient and cheaper for you to sue us this way - we want to make sure we look after you... now. And we, really, truly, honest-to-god, promise that we'll actually fund the liability-stricken new entity we create^".

^ Offer not valid in the United States.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#49

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

[dead]

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#50
post #25

The billion dollar question: do we think SEC filing disclosures are about to get a bit more interesting to read? Or is the standard boiler plate "we might get hacked, our controls may not be sufficient" going to remain?

The new 8-ks are already a response to this...
Post reply on HN