SEC v. SolarWinds Corp. & Timothy G. Brown (Chief Information Security Officer)
Unprecedented SEC enforcement action charging a public software enterprise and its individual CISO with defrauding investors through misleading public cybersecurity statements prior to the historic SUNBURST supply chain breach.
The SEC alleged that SolarWinds and its CISO knowingly downplayed cybersecurity deficiencies in public filings while internal communications revealed acute security vulnerabilities. The case fundamentally transformed public corporate cybersecurity disclosure obligations, governance oversight, and legal exposure for corporate CISOs.
- [1]Securities Fraud (Section 17(a) of the Securities Act)
- [2]False and Misleading Disclosures (Section 10(b) of the Exchange Act & Rule 10b-5)
- [3]Internal Accounting Controls Violations (Section 13(b)(2)(B))
Deposition exhibits, internal Slack communications, and quarterly risk presentations.
Judge Paul A. Engelmayer ruling dismissing internal accounting controls claim while sustaining core Section 10(b) disclosure counts.
Historic judicial clarification establishing limits of SEC accounting control claims over internal IT policies while sustaining strict transparency rules for post-incident public disclosure.
- • SolarWinds Corporation
- • Timothy G. Brown (CISO, SolarWinds)