On 30 October 2023 the US Securities and Exchange Commission announced charges against SolarWinds Corporation and its chief information security officer, alleging fraud and internal control failures relating to cybersecurity risks and vulnerabilities.
The complaint alleged that from the company’s 2018 initial public offering through its December 2020 announcement of the SUNBURST attack, SolarWinds and the officer overstated its cybersecurity practices and understated or failed to disclose known risks — disclosing generic risks while allegedly aware of specific deficiencies.
This File Records A Complaint, Not A Finding
Everything above is what the SEC alleged. A regulator filing a complaint is a claim being made in public by an institution with standing to make it, and it is not an adjudication.
The desk records the same distinction at 23-0814, where it declined to convert Clorox’s pleading against a service provider into a vector. This file names the officer’s role rather than dwelling on the individual, because the corpus names individuals only after conviction and no conviction is at issue here.
The Gap Alleged Is Between Two Documents
The substance of the allegation is not that SolarWinds was insecure. It is that its public statements and its internal assessments described different companies.
That is a disclosure case rather than a security case, and it is why it belongs in this database. The corpus argues at 26-0403 and 25-1121 that regulatory pressure on cybersecurity increasingly arrives through disclosure obligations rather than security standards — nobody is fined for being breached, and people are fined for what they said beforehand.
What It Changed For The Role
Charging a named security officer alongside the company put internal risk assessments into a different category. A frank internal memo about known deficiencies became, potentially, evidence about what the company knew when it published something else.
The corpus records at 26-0428 that organisations reported difficulty filling CISO roles and had stopped developing successors, and at 25-0219 that a majority of CISOs reported burnout. This file is one of the reasons those files exist.
Built on the SEC’s own press release announcing the charges, retrieved and read by this desk, and on contemporaneous legal analysis of the complaint. Every characterisation of SolarWinds’ conduct in this file is an allegation by the SEC and is recorded as such; this desk asserts no finding about the company or the officer. Subsequent procedural history — motions, rulings, settlements or dismissals — falls outside this file, which records the position at the date of the charges. The 2020 SUNBURST attack itself is not the subject of this file. Graded high on the existence and content of the complaint. Corrections: corrections@forensicpost.com.
- SEC Charges SolarWinds and Chief Information Security Officer with Fraud, Internal Control FailuresUS Securities and Exchange Commission
- SEC Charges SolarWinds and CISO with Fraud and Internal Controls FailuresWilmerHale