Earlier quoted context omitted.
he could have resigned
Exactly my point - if he resigned quietly, the company would hire a "yes man" that exactly fits the profile I described. If he resigned loudly, he probably would be pretty unhireable, at least as another CISO. In neither case do the customers at any company get the benefit of actual improved security.
SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures
81–90 of 109 posts
Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures
#82Earlier quoted context omitted.
The password example feels egregious, but keep in mind that the investigators spent months if not years combing through corporate records and are now showcasing the most embarrassing finds in the framing of their choice. I bet there's not a single company in the world where some engineer didn't at one point set up a dumb password as a part of some one-off integration. The job of the security team is to systematically…
Nation states like anyone else have budgets. No company is immune to the full weight of a major nation state but most of the time that is not brought to bear. You don't need to be impossible to hack, you just need to be hard enough that the value provided is less than the effort required. Still a pretty tall order, but a few steps down from impossible.
There's always going to be a curve and if anyone on the front side of the bell curve is below the threshold for "worth the effort" then this seems like a useless goal. I agree with other posters that this is more about transparency.
Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures
#83Among other factors contributing to corporate/white-collar corruption & fraud, this is what happens when you have a culture of nepotism & nepotistic CEO. The HR Chief of SolarWinds is the cousin of the CEO (Sudhakar Ramakrishna) of SolarWinds. Same was true at their previous company (Pulse Secure). In many global cultures, this is completely normal-- and those are cultures which have high rates of endemic, prolific c…
[0] https://investors.solarwinds.com/corporate-governance/board-...
[1] https://en.wikipedia.org/wiki/2020_United_States_federal_gov...
Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures
#84Earlier quoted context omitted.
I'm somewhat confident that the cultural problems predate those folks taking over SolarWinds. Putting the national spin on this issue is inappropriate and contrary to the guidelines of this site.
You mean the spin they themselves induced on a broad cultural scale, over the course of centuries, such that it has become prolific and engrained? ...No one is allowed to comment on it.. because... Fraudulent Activities should be Accepted, And Not condemned, And no one is allowed to discuss it? Just trying to understand your logic, truly in good faith. ... And other nations should just accept it eh? `Fraid not, ole c…
Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures
#85Earlier quoted context omitted.
Sounds like a whistleblower opportunity. The government pays big bucks when you bring major fraud to their attention.
While waiting for those life changing $$$, are whistleblowers in America generally treated well and their identify kept anonymous?
Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures
#86Among other factors contributing to corporate/white-collar corruption & fraud, this is what happens when you have a culture of nepotism & nepotistic CEO. The HR Chief of SolarWinds is the cousin of the CEO (Sudhakar Ramakrishna) of SolarWinds. Same was true at their previous company (Pulse Secure). In many global cultures, this is completely normal-- and those are cultures which have high rates of endemic, prolific c…
And why should people trust you? You could just be someone looking to blackmail companies with damaging insider info.
> why should anyone trust you
The statement clears opens the validation to a capable person, what’s your concern exactly
Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures
#87In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…
>I get it that the SEC wants to change this culture and have a designated person meaningfully responsible for infosec risk, but it feels that it's a case of stick before the carrot. They have that already, it’s the CEO - he is supposed to have ultimate responsibility which is why he (or she) gets obscene compensation. They should be incentivized to hire the best CISO he can find because he’s facing jail time if he do…
[1] https://open.spotify.com/episode/4fihCSOPKrIDXPB2azNgOc?si=3...
Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures
#88Earlier quoted context omitted.
If you have something interesting to say about Kaseya (and it's on topic) by all means say it. But please don't leave these kinds of contentless "now do X" posts here.
Oh sure - I could talk about how their CISO is a former FBI agent who, prior to joining the company, was responsible for investigating the distribution of ransomware via their VSA product. Nothing shady there. Or perhaps that their (rapidly shrinking) security team has been told to communicate via Signal so their messages can't be subpoenaed successfully.
https://www.bnnbloomberg.ca/kaseya-failed-to-address-securit...
Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures
#89Earlier quoted context omitted.
[flagged]
How do you even know where the previous poster does live? Nepotism is a staunchly human thing and very much visible in all societies. I grant you that there have been authors suggesting nepotisim is a problem in south america and south/east asia. Its also an issue in Europe, in fact it's an issue in North America as well. The national bent is unnecessary. The aggressiveness belies ulterior motives too easily.
I said: "Are you an Anarchist?" (i.e. someone who doesn't care about law enforcement) "If so, have you considered moving to Venezuela or Somalia-- You may find those societies preferable."
Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures
#90Earlier quoted context omitted.
How do you even know where the previous poster does live? Nepotism is a staunchly human thing and very much visible in all societies. I grant you that there have been authors suggesting nepotisim is a problem in south america and south/east asia. Its also an issue in Europe, in fact it's an issue in North America as well. The national bent is unnecessary. The aggressiveness belies ulterior motives too easily.
Unfortunately, it looks like they're proving my point. :( What potential whistleblower would want to involve an unknown person who just becomes hostile when asked to establish their credibility? :( Doesn't seem like an appropriate level of maturity. :( :( :( --- @that_aint_cool Instead of name calling and other crap like that, how about giving people a reason to trust you? You're a completely unknown person, asking t…
I am the one sharing details-- such as the current SolarWinds CEO's cousin being in charge of the HR department of SolarWinds-- both of whom are native Indians (known to be a culture with rife corruption, fraud, and nepotism as discussed throughout many sources of reputable literature and journals).