The Securities and Exchange Commission filed charges against SolarWinds Corporation and its Chief Information Security Officer alleging that public representations about the company's cybersecurity program — made in the company's Security Statement and reflected in securities filings — materially misled investors by describing controls as robust and effective while internal documents acknowledged significant security deficiencies that the company's security leadership had identified but not resolved. The charges came after a sophisticated supply chain attack on SolarWinds' Orion network monitoring software affected thousands of customers including multiple federal government agencies.DOCUMENTED
The Orion compromise, publicly disclosed in December 2020, involved insertion of malicious code into legitimate software updates distributed to approximately 18,000 customers. Attackers attributed by U.S. intelligence agencies to a Russian foreign intelligence service used the access to move within victims' networks for months before detection. Affected organizations included the U.S. Departments of Treasury, State, and Homeland Security, along with major private-sector companies across multiple industries.
- The SEC charged SolarWinds and its CISO with misleading investors about cybersecurity practices and controls
- Internal presentations described security posture as insufficient to defend against major cyberattacks
- The Orion supply chain compromise affected approximately 18,000 customers including federal agencies
- Naming the CISO as an individual defendant marked a significant expansion of personal liability in cybersecurity disclosure
- SolarWinds contested the charges, arguing the enforcement theory would discourage candid internal security documentation
- The case contributed to the SEC's adoption of formal cybersecurity disclosure rules in 2023
The Alleged Gap Between Public and Internal Representations
The SEC's charges documented a specific divergence between the Security Statement posted on SolarWinds' website — which described the company's security program in terms implying comprehensive, tested controls — and internal documents that told a materially different story. A presentation by the CISO acknowledged that the company's security posture was insufficient to defend against significant cyberattacks. Internal analyses identified specific gaps in access controls, software development security practices, and vulnerability management that had been identified but not remediated at the pace or scale the public representations implied.DOCUMENTED
The second alleged disclosure failure involved statements made after the Orion compromise was discovered. The SEC alleged that SolarWinds' initial public descriptions of the attack overstated the novelty of the attack method and understated the extent to which it exploited known vulnerabilities — framing the incident as an unforeseeable attack on an otherwise sound program in ways that continued the pattern of misrepresentation.REVIEWED
The Security Statement described comprehensive controls. The CISO's internal presentation acknowledged the program could not defend against a major attack. Both existed at the same time. That divergence is what the SEC brought the case about.
Individual CISO Liability
Naming SolarWinds' CISO as an individual defendant was among the most significant aspects of the charges for the cybersecurity profession. Individual securities liability has historically focused on executives who certify financial reports under Sarbanes-Oxley. Extending personal liability to a CISO for cybersecurity disclosure failures raised the question of whether security professionals face personal securities liability when public representations about security prove inaccurate — and provoked concern that personal liability would chill candid internal documentation of security risks.REVIEWED
SolarWinds' Defense and the Resulting Policy Debate
SolarWinds contested the charges, arguing its public security representations were accurate descriptions of program goals and frameworks, that the internal documents reflected normal candid improvement discussions rather than knowing misrepresentation, and that the enforcement theory would impose unrealistic disclosure obligations on companies managing a constantly evolving threat environment. The policy debate the case provoked contributed to the SEC's adoption in 2023 of formal cybersecurity disclosure rules requiring public companies to report material incidents within four business days and to include annual disclosures about cybersecurity governance and risk management.DOCUMENTED
The SolarWinds case also has implications for how companies respond to major cybersecurity incidents. The SEC's allegation that the company's post-discovery communications about the Orion compromise understated the extent to which known vulnerabilities contributed to the attack suggests that incident disclosure should be reviewed by both cybersecurity counsel and securities disclosure counsel before it is finalized. The legal standard for post-incident disclosure is the same as for any other material information: the disclosure must accurately represent the facts as the company knows them at the time of disclosure, including the extent to which the attack exploited pre-existing conditions in the company's security program rather than entirely novel techniques. Companies that prepare post-incident disclosures without this dual review risk making the same type of incomplete-disclosure error that the SEC alleged in the SolarWinds matter.
The SolarWinds matter also has implications for post-incident disclosure practices. The allegation that post-discovery communications understated the extent to which known vulnerabilities contributed to the attack suggests that incident disclosures should be reviewed by both cybersecurity counsel and securities disclosure counsel before finalization. The legal standard for post-incident disclosure is the same as for any other material information: it must accurately represent what the company knows at the time, including the extent to which the attack exploited pre-existing conditions. Companies that prepare post-incident disclosures without this dual review risk the type of incomplete-disclosure error the enforcement case alleged.
The post-SolarWinds disclosure environment requires integrating cybersecurity risk management into the securities disclosure process. The security team's internal assessments must now be understood in the context of disclosure obligations — not because every internal security concern requires public disclosure, but because material gaps between internal assessments and public representations create securities law exposure that is now subject to active enforcement. The appropriate response is not to reduce the candor of internal security documentation but to ensure that public security representations accurately reflect the state of the program as internal assessments describe it. CISOs at publicly traded companies should ensure their relationship with the company's disclosure committee is formalized — that there is a clear process for elevating material cybersecurity information to the disclosure review function before each periodic filing.
The post-SolarWinds disclosure environment requires integrating cybersecurity risk management into the securities disclosure process. The security team's internal assessments must now be understood in the context of disclosure obligations — not because every internal security concern requires public disclosure, but because material gaps between internal assessments and public representations create securities law exposure that is now subject to active enforcement. The appropriate response is not to reduce the candor of internal security documentation but to ensure that public security representations accurately reflect the state of the program as internal assessments describe it. CISOs at publicly traded companies should ensure their relationship with the company's disclosure committee is formalized — that there is a clear process for elevating material cybersecurity information to the disclosure review function before each periodic filing.
Sources behind this report
Have documents relevant to this story? Reach us through our tips channel.