DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
BACK TO LEGAL DOSSIERS
CASE #23-CV-09518United States / Southern District of New YorkCOURT: US District Court for the Southern District of New York (SDNY)

SEC v. SolarWinds Corp. & Timothy G. Brown (Chief Information Security Officer)

CASE SUMMARY & JUDICIAL SCOPE

Unprecedented SEC enforcement action charging a public software enterprise and its individual CISO with defrauding investors through misleading public cybersecurity statements prior to the historic SUNBURST supply chain breach.

The SEC alleged that SolarWinds and its CISO knowingly downplayed cybersecurity deficiencies in public filings while internal communications revealed acute security vulnerabilities. The case fundamentally transformed public corporate cybersecurity disclosure obligations, governance oversight, and legal exposure for corporate CISOs.

INDICTED CHARGES & STATUTORY VIOLATIONS
  • [1]Securities Fraud (Section 17(a) of the Securities Act)
  • [2]False and Misleading Disclosures (Section 10(b) of the Exchange Act & Rule 10b-5)
  • [3]Internal Accounting Controls Violations (Section 13(b)(2)(B))
VERIFIED PROVENANCE TRAIL2 INDEPENDENT ATTESTATIONS
Evidentiary provenance supporting indictment counts and state attribution.
legal2023-10-30
SEC Complaint 23-CV-09518

Deposition exhibits, internal Slack communications, and quarterly risk presentations.

legal2024-07-18
SDNY District Court Opinion & Order

Judge Paul A. Engelmayer ruling dismissing internal accounting controls claim while sustaining core Section 10(b) disclosure counts.

JUDICIAL OUTCOME / STATUS

Historic judicial clarification establishing limits of SEC accounting control claims over internal IT policies while sustaining strict transparency rules for post-incident public disclosure.

DOSSIER METADATA
STATUS
settled
PROSECUTING AUTHORITY
US Securities and Exchange Commission (SEC)
NAMED DEFENDANTS
  • SolarWinds Corporation
  • Timothy G. Brown (CISO, SolarWinds)
FILING DATE
2023-10-30
INCIDENT EPOCH
2020-12-13