Live data from Hacker News

SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

sec.gov

91–100 of 109 posts

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#91

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

The problem wasn't that they had bad security and were hacked. The problem is that they lied to investors about their security and about the hack. So if a CISO was the one telling the lies (and you seem to acknowledge that their main purpose is talking to clients, but maybe its also talking to investors) then they seem to be the right person to charge even if they weren't responsible for the bad security.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#92

I’m don’t like that this is being pursued by the SEC. Especially since the likely penalty will be a large chuck of money that gets paid to… the SEC. Too much like extortion. But as Matt Levine often reminds us - everything is securities fraud. If a bad thing happens and you did not warn investors about it beforehand, you can be sued for securities fraud by the SEC. It’s almost like it’s illegal for investors to lose…

It's more like "if a bad thing happens and you knew about the risk and lied to investors about it".

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#93
post #77

Earlier quoted context omitted.

The password example feels egregious, but keep in mind that the investigators spent months if not years combing through corporate records and are now showcasing the most embarrassing finds in the framing of their choice. I bet there's not a single company in the world where some engineer didn't at one point set up a dumb password as a part of some one-off integration. The job of the security team is to systematically…

The problem is not being hacked. The SEC doesn't want companies to be hack proof or to force them to dump millions into security. They want companies to be more transparent and honest with shareholders about their current security gaps and for them to report hacks in a timely manner. It's fine to be insecure but honest, what is never fine is lying to investors. Bad investments are fine, bad investments pretending to…

I'm not here to defend SolarWinds, and it's entirely possible that they were a "bad investment pretending to be a good one", but I have some issues with this framing.

First, contrary to your assertion, there is no doubt that they're in trouble because of getting hacked by a nation state (and dutifully disclosed it). This wasn't some routine audit, wasn't a whistleblower complaint. The only reason the SEC went after them is that they had the misfortune of falling prey to an attack that few other businesses could conceivably repel. So, I'm not sure that's sending a great message.

Second, the complaint isn't showing that the company brazenly and deliberately deceived investors. It's not that the SEC peeked under the hood, immediately realized this is messed up, and had to act. No, they spend months poring over every email - and all they came up with is not exactly a smoking gun. The whole complaint is basically "the company only made generic investor disclosures, but we found instances where specific employees pointed out more specific deficiencies."

Ignoring the one-sided narrative of the complaint, the actual quotes they have don't paint the picture of a deliberate conspiracy. They paint the picture of normal day-to-day communications where people sometimes say dumb things, blow things out of proportion to try to get resources, etc.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#94

Earlier quoted context omitted.

While waiting for those life changing $$$, are whistleblowers in America generally treated well and their identify kept anonymous?

Yes. There are statutory protections for whistleblowers, as well: https://www.sec.gov/whistleblower/retaliation

I guess the real question is if they're generally effective?

For comparison, Australia theoretically has protections for whistleblowers. But it's unfortunately common for whistleblowers in practice to get royally shafted, have their life destroyed, (etc). :(

* https://www.abc.net.au/news/2023-03-27/richard-boyle-case-go...

* https://www.abc.net.au/news/2023-04-13/trial-date-for-afghan...

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#95

Earlier quoted context omitted.

And why should people trust you? You could just be someone looking to blackmail companies with damaging insider info.

>> If any investigators or journalists > why should anyone trust you The statement clears opens the validation to a capable person, what’s your concern exactly

A brand new account fishing for confidential info, that when asked why people should do so has gone off the deep end and started calling me names. Telling me to move to a corrupt country where I'd be welcome, etc.

To me (!), that doesn't seem like a level headed person that should be entrusted with anything important. You may feel otherwise of course. ;)

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#96
post #77

Earlier quoted context omitted.

The problem is not being hacked. The SEC doesn't want companies to be hack proof or to force them to dump millions into security. They want companies to be more transparent and honest with shareholders about their current security gaps and for them to report hacks in a timely manner. It's fine to be insecure but honest, what is never fine is lying to investors. Bad investments are fine, bad investments pretending to…

I'm not here to defend SolarWinds, and it's entirely possible that they were a "bad investment pretending to be a good one", but I have some issues with this framing. First, contrary to your assertion, there is no doubt that they're in trouble because of getting hacked by a nation state (and dutifully disclosed it). This wasn't some routine audit, wasn't a whistleblower complaint. The only reason the SEC went after t…

I think your stance is way more balanced, I was mostly speaking to what I believe is the message the regulator wants to send, regardless if it's fair in its essence. Thanks for balancing out the thread.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#97

Earlier quoted context omitted.

Unfortunately, it looks like they're proving my point. :( What potential whistleblower would want to involve an unknown person who just becomes hostile when asked to establish their credibility? :( Doesn't seem like an appropriate level of maturity. :( :( :( --- @that_aint_cool Instead of name calling and other crap like that, how about giving people a reason to trust you? You're a completely unknown person, asking t…

You seem to have a vested interest in de-railing the conversation. I am the one sharing details-- such as the current SolarWinds CEO's cousin being in charge of the HR department of SolarWinds-- both of whom are native Indians (known to be a culture with rife corruption, fraud, and nepotism as discussed throughout many sources of reputable literature and journals).

> You seem to have a vested interest ...

And again you're jumping right into name calling.

You have a brand new, unknown account here, and you're asking people to share confidential info with you.

You have no profile info, and instead of providing details about yourself when asked... you start calling people names.

What that looks like is someone immature attempting social engineering.

If you're actually legit though, then please do better.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#98

6 months ago: > SolarWinds CISO Tim Brown has been named CISO of the Year by Globee Cybersecurity Awards for his work overseeing our Secure by Design initiative. > "Through our Secure by Design initiative and our ongoing commitment to efficient information-sharing and public-private partnerships, ..." This is like China and Saudi Arabia sitting on the UN human rights council.

> Globee Never heard of it, but it looks like a pay to play, with dozens of awards. Not impressed https://globeeawards.com/cyber-security/

> H1. Thought Leadership | Cybersecurity Thought Leadership Awards

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#99
post #30

Earlier quoted context omitted.

If we're being critical here, I'd also argue that often the CISO's job and main concern is simply making sure they have the right paperwork and motions in place to pass a given set of industry audit standards. These people are not always even capable of understanding the technical security of a product. Paper security like this is often a minimum bar, and sometimes even below minimum when the audit checklists lag bes…

The password example feels egregious, but keep in mind that the investigators spent months if not years combing through corporate records and are now showcasing the most embarrassing finds in the framing of their choice. I bet there's not a single company in the world where some engineer didn't at one point set up a dumb password as a part of some one-off integration. The job of the security team is to systematically…

The thing that was so egregious about Solarwinds is that, given their line of business, they were obvious targets for nation state actors. This is similar to any business that itself is a supplier of highly privileged software to large numbers of clients (e.g. password managers or cloud providers are in the same boat).

And while the password example could have been a one-off, everything I've read about Solarwinds says they had a horrendously bad security culture. Bad security cultures are essentially unfixable without a top-down, CEO-driven initiative that places real carrots and sticks for individuals' security posture. Even then, 95% of these initiatives are bullshit, because they boil down to "Security is our top priority! Oh also if we miss our revenue targets a bunch of people are getting fired."

I think the CISO's actions were pretty bad, but I also think there are lots of other execs at Solarwinds who are quite happy he's now the sacrificial lamb.

Re: SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures

#100
post #56

In most public companies, CISOs are not "real" C-level positions. They're not considered "directors and officers" of the company in the sense of the securities law, they don't have special contracts, they don't rake in exorbitant salaries, they don't have golden parachutes. They don't routinely participate in board meetings or shareholder reporting. If I recall correctly, at Apple, the CISO role was some guy reportin…

I don't know security law at all but I have always seen CISO equivalent positions to be "Director" level, reporting typically to the CFO or to A C-level of some org who reports to another C-level and so on depending on size and complexity. But you are right in that they're just regular mid level managers, not directly accountable to the board.

The CISOs I've worked with were usually Directors, or VPs, and in 3 cases so far, lawyers who made it into IS/IT management. Their CISO duties/powers were thin. Head-nods and "let's set up a separate meeting for that" level.
Post reply on HN