Live data from Hacker News

SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

sec.gov

61–70 of 109 posts

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#61
post #43
post #25

The billion dollar question: do we think SEC filing disclosures are about to get a bit more interesting to read? Or is the standard boiler plate "we might get hacked, our controls may not be sufficient" going to remain?

According to wikipedia SolarWinds suffered one of the largest cyberattacks against a company in history - one that also directly affected thousands of consumer devices (not just a company backend). This might be a unique consequence of a unique situation. But who knows. > In February 2021, Microsoft President Brad Smith said that it was "the largest and most sophisticated attack the world has ever seen". https://en.w…

Brad Smith (https://news.microsoft.com/exec/brad-smith/) is a PR person at Microsoft. His role is to make loud statements on matters he has no knowledge of or qualifications to talk about.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#62
post #56

Earlier quoted context omitted.

I don't know security law at all but I have always seen CISO equivalent positions to be "Director" level, reporting typically to the CFO or to A C-level of some org who reports to another C-level and so on depending on size and complexity. But you are right in that they're just regular mid level managers, not directly accountable to the board.

"Directors and officers" are a special legal category, basically the highest-ranking people making material decisions about the business day-to-day. They are subject to special reporting requirements, such as having to file paperwork whenever selling or buying stock (which usually needs to happen under a trading plan). They often have specialized contracts, company-provided liability insurance, and a variety of perks…

This.

With respect to SolarWinds, we need only defer to their proxy statement to discover who the real shotcalling directors[1] and executives[2] are.

[1] https://www.sec.gov/Archives/edgar/data/1739942/000173994223...

[2] https://www.sec.gov/Archives/edgar/data/1739942/000173994223...

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#63
post #16

I am going bet a pillow case of slightly squished mini candy bars that Tim Brown might have been a good technologist, but that he might have been told to sit down and color. I am saying this because reading the interview notes: > BROWN: It was crazy. So our CEO got a call in the morning from [Mandiant CEO] Kevin Mandia. And then he called me, and then the CTO for FireEye called me. That’s our nightmare moment. [Oct.…

Those latter two statements are no doubt about why Alex Stamos called being the CSO "the worst job in the world"

Who holds the CSO-equivalent job in the government? It's the president or prime minister, isn't it? Because ultimately all decisions have an impact on security.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#64

Among other factors contributing to corporate/white-collar corruption & fraud, this is what happens when you have a culture of nepotism & nepotistic CEO. The HR Chief of SolarWinds is the cousin of the CEO (Sudhakar Ramakrishna) of SolarWinds. Same was true at their previous company (Pulse Secure). In many global cultures, this is completely normal-- and those are cultures which have high rates of endemic, prolific c…

lol. Let’s not throw Latin / Asian culture under the bus when the implicit alternative being posed is American culture. Pot meet kettle. Remember what old mate says to Ryan Gosling in the Barbie movie? “We’re just better at hiding it.”

Latin / Asian CORRUPTION ^* culture

It's not difficult to find tons of cases...

^* "Corruption continues to fester, aided by scandals surrounding the COVID-19 response, and is fueling popular outrage. In Peru, for instance, ministers received preferential treatment for vaccines, and in Argentina, government officials set up “VIP immunization clinics” for family and friends."

"Beyond these instances of favoritism and nepotism, the crisis has resulted in the further weakening of judicial independence and the rule of law. In Guatemala, President Alejandro Giammattei has presided over dramatic steps against judicial oversight in recent months, including the sacking of the country’s top anti-corruption prosecutor. These maneuvers—coupled with underperforming economies—have further dented public support for elected officials and trust in government."[1]

^* [1] https://www.atlanticcouncil.org/blogs/new-atlanticist/democr...

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#65
post #53

Earlier quoted context omitted.

How do you even know where the previous poster does live? Nepotism is a staunchly human thing and very much visible in all societies. I grant you that there have been authors suggesting nepotisim is a problem in south america and south/east asia. Its also an issue in Europe, in fact it's an issue in North America as well. The national bent is unnecessary. The aggressiveness belies ulterior motives too easily.

Unfortunately, it looks like they're proving my point. :( What potential whistleblower would want to involve an unknown person who just becomes hostile when asked to establish their credibility? :( Doesn't seem like an appropriate level of maturity. :( :( :( --- @that_aint_cool Instead of name calling and other crap like that, how about giving people a reason to trust you? You're a completely unknown person, asking t…

[flagged]

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#66

Earlier quoted context omitted.

This, nepotism is rife in private American companies of all kinds from my own experiences and others. O God, there's at least one company, I personally have experience with that not only is a nepotistic hellhole, but is actively defrauding the government and a few big names. The result of spoiled brats getting control of a very niche private hardware engineering company after their father died.

That sounds like a startup opportunity.

Sounds like a whistleblower opportunity. The government pays big bucks when you bring major fraud to their attention.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#67

I’m don’t like that this is being pursued by the SEC. Especially since the likely penalty will be a large chuck of money that gets paid to… the SEC. Too much like extortion. But as Matt Levine often reminds us - everything is securities fraud. If a bad thing happens and you did not warn investors about it beforehand, you can be sued for securities fraud by the SEC. It’s almost like it’s illegal for investors to lose…

Don't you count the following as "actual deception and fraud"?

> SolarWinds allegedly misled investors by disclosing only generic and hypothetical risks at a time when the company and Brown knew of specific deficiencies...

> SolarWinds’ public statements about its cybersecurity practices and risks were at odds with its internal assessments...

> SolarWinds and Brown engaged in a campaign to paint a false picture...

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#68

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

>I get it that the SEC wants to change this culture and have a designated person meaningfully responsible for infosec risk, but it feels that it's a case of stick before the carrot.

They have that already, it’s the CEO - he is supposed to have ultimate responsibility which is why he (or she) gets obscene compensation. They should be incentivized to hire the best CISO he can find because he’s facing jail time if he doesn’t.

Instead he has 0 responsibility because literally everything is an underlings fault.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#69

I’m don’t like that this is being pursued by the SEC. Especially since the likely penalty will be a large chuck of money that gets paid to… the SEC. Too much like extortion. But as Matt Levine often reminds us - everything is securities fraud. If a bad thing happens and you did not warn investors about it beforehand, you can be sued for securities fraud by the SEC. It’s almost like it’s illegal for investors to lose…

This is like saying police officers shouldn't enforce speed limits because the ticket ends up back in the police department, and you could certainly make a point for a conflict of interest, but there is traceable proof. What actually happened in the SolarWinds instance seems to be actual deception and fraud. Plenty of companies go out of business due to competition, this isn't one of those instances.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#70

Here is Matt Levine’s, of Bloomberg fame, famous article “Everything Everywhere is Securities Fraud.” https://www.bloomberg.com/opinion/articles/2019-06-26/everyt... Now cybersecurity included.

I lost a lot of respect for Matt Levine with the pretzels he contorted himself into trying to defend the Texas Two Step as "really, truly, better for the plaintiffs", ignoring the two elephants in the room: if it was beneficial to the plaintiffs, why would the defendant go out of their way to do it? And how is it, by magical coincidence, that every firm that has done the Texas Two Step has managed to get out of payin…

Or maybe as an expert, he understands the corporate bankruptcy process better than you and most of us here.
Post reply on HN