Live data from Hacker News

SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

sec.gov

51–60 of 109 posts

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#51
I’m don’t like that this is being pursued by the SEC. Especially since the likely penalty will be a large chuck of money that gets paid to… the SEC. Too much like extortion.

But as Matt Levine often reminds us - everything is securities fraud. If a bad thing happens and you did not warn investors about it beforehand, you can be sued for securities fraud by the SEC.

It’s almost like it’s illegal for investors to lose money, and the SEC enforces that requirement.

Investing is risky, bad things can happen, including execs that make mistakes (not talking about actual deception and fraud here) and investors should not be surprised when they sometimes lose money, or seek the strong arm of the government for relief.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#52
post #46
post #10

Earlier quoted context omitted.

If you have something interesting to say about Kaseya (and it's on topic) by all means say it. But please don't leave these kinds of contentless "now do X" posts here.

Oh sure - I could talk about how their CISO is a former FBI agent who, prior to joining the company, was responsible for investigating the distribution of ransomware via their VSA product. Nothing shady there. Or perhaps that their (rapidly shrinking) security team has been told to communicate via Signal so their messages can't be subpoenaed successfully.

Ah yes, drivel. What i come to HN for.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#53

Earlier quoted context omitted.

And why should people trust you? You could just be someone looking to blackmail companies with damaging insider info.

[flagged]

How do you even know where the previous poster does live?

Nepotism is a staunchly human thing and very much visible in all societies. I grant you that there have been authors suggesting nepotisim is a problem in south america and south/east asia. Its also an issue in Europe, in fact it's an issue in North America as well.

The national bent is unnecessary. The aggressiveness belies ulterior motives too easily.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#54

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

[deleted]

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#55

6 months ago: > SolarWinds CISO Tim Brown has been named CISO of the Year by Globee Cybersecurity Awards for his work overseeing our Secure by Design initiative. > "Through our Secure by Design initiative and our ongoing commitment to efficient information-sharing and public-private partnerships, ..." This is like China and Saudi Arabia sitting on the UN human rights council.

> Globee

Never heard of it, but it looks like a pay to play, with dozens of awards. Not impressed

https://globeeawards.com/cyber-security/

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#56

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

I don't know security law at all but I have always seen CISO equivalent positions to be "Director" level, reporting typically to the CFO or to A C-level of some org who reports to another C-level and so on depending on size and complexity. But you are right in that they're just regular mid level managers, not directly accountable to the board.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#57
post #56

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

I don't know security law at all but I have always seen CISO equivalent positions to be "Director" level, reporting typically to the CFO or to A C-level of some org who reports to another C-level and so on depending on size and complexity. But you are right in that they're just regular mid level managers, not directly accountable to the board.

"Directors and officers" are a special legal category, basically the highest-ranking people making material decisions about the business day-to-day. They are subject to special reporting requirements, such as having to file paperwork whenever selling or buying stock (which usually needs to happen under a trading plan). They often have specialized contracts, company-provided liability insurance, and a variety of perks you associate with "real" executives at public companies - from corporate jets to eight-figure salaries. We're talking about the CEO, CFO, CTO, and so on.

This is similarly-sounding but completely separate from the "director" job level at a typical tech company, which is basically just a senior manager of a large team or maybe the lead of a mid-size department. Your average CISO is probably in this ballpark, commonly at least 2-3 reporting levels below real C-leadership.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#58
post #53

Earlier quoted context omitted.

[flagged]

How do you even know where the previous poster does live? Nepotism is a staunchly human thing and very much visible in all societies. I grant you that there have been authors suggesting nepotisim is a problem in south america and south/east asia. Its also an issue in Europe, in fact it's an issue in North America as well. The national bent is unnecessary. The aggressiveness belies ulterior motives too easily.

Unfortunately, it looks like they're proving my point. :(

What potential whistleblower would want to involve an unknown person who just becomes hostile when asked to establish their credibility? :(

Doesn't seem like an appropriate level of maturity. :( :( :(

---

@that_aint_cool Instead of name calling and other crap like that, how about giving people a reason to trust you?

You're a completely unknown person, asking to be let in on confidential details.

Do you think your behaviour - as demonstrated here so far - would be viewed well by a potential whistleblower or judge?

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#59

Earlier quoted context omitted.

lol. Let’s not throw Latin / Asian culture under the bus when the implicit alternative being posed is American culture. Pot meet kettle. Remember what old mate says to Ryan Gosling in the Barbie movie? “We’re just better at hiding it.”

This, nepotism is rife in private American companies of all kinds from my own experiences and others. O God, there's at least one company, I personally have experience with that not only is a nepotistic hellhole, but is actively defrauding the government and a few big names. The result of spoiled brats getting control of a very niche private hardware engineering company after their father died.

What kind of hardware engineering are they into?

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#60
post #18

Earlier quoted context omitted.

I'm somewhat confident that the cultural problems predate those folks taking over SolarWinds. Putting the national spin on this issue is inappropriate and contrary to the guidelines of this site.

You mean the spin they themselves induced on a broad cultural scale, over the course of centuries, such that it has become prolific and engrained? ...No one is allowed to comment on it.. because... Fraudulent Activities should be Accepted, And Not condemned, And no one is allowed to discuss it? Just trying to understand your logic, truly in good faith. ... And other nations should just accept it eh? `Fraid not, ole c…

Wow, this could be a new copypasta.
Post reply on HN