The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →The SEC’s civil action against SolarWinds and its chief information security officer, Timothy G. Brown, was dismissed with prejudice on November 20, 2025. That ended this case, but it does not establish a general rule that CISOs are either personally liable or immune from SEC action. The case drew attention because Brown was named individually and, in July 2024, a court allowed claims tied to SolarWinds’ website Security Statement to proceed past the motion-to-dismiss stage.
What happened to the SEC’s SolarWinds lawsuit?
The SEC filed its action against SolarWinds and Brown on October 30, 2023. The agency alleged that the company made misleading cybersecurity statements and omissions before and after the SUNBURST compromise. The allegations concerned its public-facing Security Statement, risk disclosures and filings, public statements, incident-related Form 8-Ks, and internal controls. They were allegations, not findings that every challenged statement was false or misleading. The court’s opinion summarizes the claims and the later motion-to-dismiss ruling.
On July 18, 2024, Judge Paul A. Engelmayer granted in part and denied in part the defendants’ motion to dismiss. The case did not end with that order: claims tied to the Security Statement survived at the pleading stage.
On November 20, 2025, the SEC announced that it had filed a joint stipulation with SolarWinds and Brown to dismiss the action with prejudice. The SEC quoted the stipulation as saying the decision was made “in the exercise of its discretion” and “does not necessarily reflect the Commission’s position on any other case.” The SEC’s release states the disposition but does not give a reason for the decision.
#1 Best Overall
Can a CISO be sued personally by the SEC?
Brown’s inclusion shows that an SEC enforcement action can name an individual executive alongside a company. It does not establish that CISOs are automatically personally liable for a security failure, or identify a general standard for when the agency would pursue one. The claims in this case concerned alleged securities-law violations involving statements and disclosures, not simply the fact that a cyberattack occurred.
The outcome matters: the action against Brown, as well as SolarWinds, was dismissed with prejudice. But that case-specific dismissal is not a blanket protection for other executives. Nor did the 2024 order ultimately establish that Brown or SolarWinds violated securities law.
Rank #2
What did the judge actually rule in 2024?
The July 2024 opinion assessed whether the SEC had plausibly pleaded its claims, not whether the allegations had been proven at trial. The court divided the challenged claims rather than accepting or rejecting the SEC’s case as a whole. Read the court opinion for the ruling and its reasoning.
| Claims at issue | July 2024 result |
|---|---|
| SolarWinds’ website Security Statement | Securities-fraud claims were allowed to proceed at the pleading stage. |
| Other challenged pre-SUNBURST statements and filings | Claims were dismissed. |
| Post-SUNBURST disclosures | All claims based on those disclosures were dismissed. |
| Internal accounting controls and disclosure controls and procedures | Claims were dismissed. |
“Allowed to proceed” was not a finding that the Security Statement was misleading. The later dismissal with prejudice ended the civil action without turning those allegations into proven violations.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
Why did the case unsettle cybersecurity leaders?
The case put a familiar governance question into a high-stakes securities-law setting: can a company’s description of its cybersecurity practices, its risk disclosures, or its incident reporting expose the company and an individual executive to enforcement? The personal naming of Brown made that question particularly salient to security leaders. The case also drew attention to the difference between general descriptions of security capabilities and statements made as risks or incidents evolve.
There is no population-level survey in the cited records measuring how many cybersecurity leaders were “spooked.” That word is a characterization of the reaction, not a measured finding. The concrete source of concern was the specific enforcement action and the 2024 ruling that allowed one category of claims to continue at that stage.
Rank #4
Did the court interpret the SEC’s 2023 cybersecurity disclosure rules?
No. The court said the later-adopted cybersecurity disclosure rules were not implicated because the case concerned alleged conduct predating their effective date. The SolarWinds opinion should not be treated as an interpretation of those rules. Its analysis addressed the earlier conduct alleged in that case. The opinion explains that distinction.
What separate SEC actions followed in 2024?
On October 22, 2024, the SEC announced settled charges against four companies—Unisys, Avaya, Check Point, and Mimecast—concerning disclosures about intrusions related to the Orion compromise. The SEC’s release said its orders found that the companies had learned of unauthorized access at different times and had minimized aspects of the incidents in public disclosures. The companies settled without admitting or denying the findings. These were separate administrative matters, not part of the SolarWinds civil action and not evidence of liability by SolarWinds or Brown. The SEC release lists the matters and penalties.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
| Company | Penalty listed by the SEC |
|---|---|
| Unisys | $4 million |
| Avaya | $1 million |
| Check Point | $995,000 |
| Mimecast | $990,000 |
Commissioners Hester Peirce and Mark Uyeda dissented from those 2024 proceedings. They argued that the SEC was second-guessing disclosures with hindsight and warned that enforcement could encourage companies to add immaterial detail. That was the commissioners’ dissenting view, not the Commission’s official holding or the SolarWinds court’s decision. Their statement quoted the 2023 rulemaking as saying incident disclosure should “focus…primarily on the impacts of…[the]…incident, rather than on…details regarding the incident itself.” Read the commissioners’ statement.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should companies and security leaders take from the case?
The records do not provide a formal SEC checklist or legal advice. They do point to distinctions that can help companies scrutinize cyber disclosures and escalation decisions:
- General risk language versus incident-specific statements: A broad description of security practices and a disclosure about a particular incident address different matters. Review whether each statement is accurate in its context.
- Known facts versus evolving details: Separate what the company has confirmed from what remains under investigation. Avoid presenting unverified scope or impact as settled.
- Impacts versus technical details: Consider what is known about effects on the company, customers, or investors, rather than assuming technical detail alone answers the disclosure question.
- Company decisions versus an executive’s role: Identify who made, reviewed, and communicated disclosure decisions, and what the individual actually said or approved. The SolarWinds action named Brown, but does not establish personal liability for CISOs generally.
- Applicable time period and rules: Distinguish allegations about earlier conduct from later disclosure requirements and from separate enforcement matters.
Because the SEC did not state why it sought dismissal, the final disposition should not be read as an endorsement or repudiation of every enforcement theory raised in the case. It establishes that this particular action ended with prejudice; the July 2024 order remains a partial pleading-stage ruling, not the case’s final outcome.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems




