DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

SEC Dropped Its SolarWinds Case in 2025 After a Judge Dismissed Most Claims

The July 2024 ruling narrowed the SEC’s case against SolarWinds but allowed a claim about its pre-breach Security Statement to proceed. The SEC dismissed the entire action with prejudice in November 2025.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A federal judge dismissed most of the SEC’s claims against SolarWinds and its chief information security officer, Timothy Brown, on July 18, 2024. One central theory survived: that SolarWinds’ pre-breach public Security Statement misrepresented its cybersecurity practices. On November 20, 2025, the SEC and defendants stipulated to dismiss the entire enforcement action with prejudice. Neither procedural event was a finding that the allegations were true or that SolarWinds’ security program was compliant.

What the SEC alleged in the SolarWinds case

The SEC sued SolarWinds and Brown in the Southern District of New York on October 30, 2023. Its complaint alleged that, from at least the company’s October 2018 IPO through its December 2020 disclosure of the SUNBURST attack, SolarWinds overstated its cybersecurity practices and understated known risks. The SEC brought claims under federal securities laws and reporting and internal-control rules, and sought injunctions, disgorgement, civil penalties and a possible officer-and-director bar against Brown. The SEC’s announcement of the case summarizes its allegations.

SUNBURST was the name used for the cyberattack disclosed in December 2020. The court’s opinion describes attackers, believed to be state-sponsored actors in Russia, compromising SolarWinds’ Orion software-development and update process. The opinion recounts the complaint’s allegations; those descriptions should not be mistaken for findings that resolved the SEC’s claims. The court’s July 18, 2024 opinion provides the case background.

What the judge dismissed in July 2024

Judge Paul A. Engelmayer granted SolarWinds and Brown’s motion to dismiss in large part. The ruling was about whether the SEC had adequately pleaded its claims, not whether a trial proved or disproved the underlying allegations. The court rejected several theories as insufficiently pleaded, including claims based on certain general promotional language, cybersecurity-risk disclosures, post-SUNBURST statements and Form 8-K disclosures, and disclosure controls and procedures. Related aiding-and-abetting theories against Brown also fell where the underlying claims failed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The opinion did not create a blanket exemption for incident reporting or declare that post-breach statements are immune from SEC scrutiny. It assessed the particular statements and allegations before it. The court’s reasoning and disposition are set out in the opinion.

The Security Statement claim that survived

The surviving theory concerned an online Security Statement describing SolarWinds’ cybersecurity program. The SEC alleged that the public description presented the company’s practices as stronger and more mature than internal assessments and presentations indicated. Those materials allegedly identified gaps in areas including access controls, security testing and monitoring.

The court concluded that the SEC had adequately pleaded a potentially misleading statement when the Security Statement was considered as a whole. Its claims included representations relating to the NIST Cybersecurity Framework, a secure development lifecycle, penetration and security testing, network monitoring, access controls and privilege management. The court also found the complaint sufficient at the pleading stage on material misrepresentation and scienter—the required fraudulent intent or recklessness. It did not decide that the SEC would prove those elements. See the opinion’s discussion of the Security Statement at pages 49–67.

The distinction was between specific claims about existing security practices, which can be assessed against internal records, and general expressions of optimism or commitment. The case was not simply about whether a company suffered a cyberattack or whether its security could have been better. The legal question was whether particular public statements and disclosures were materially misleading under securities law and whether the SEC adequately alleged the required elements.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the 2024 ruling did not decide

  • It did not find SolarWinds or Brown liable. The surviving claim was allowed to proceed; it had not been proven.
  • It did not establish a general rule of CISO liability. Brown remained exposed on the surviving theory because the SEC alleged his specific role in promoting or disseminating the Security Statement despite knowledge of contradictory information.
  • It did not make incident disclosures categorically safe. A company may describe what is confirmed and what remains uncertain, but material inaccuracies or omissions can still create legal risk.
  • It did not declare SolarWinds’ cybersecurity statements accurate or its program compliant. Dismissing claims for pleading deficiencies is not an endorsement of the underlying conduct.

How the case ended in 2025

On November 20, 2025, the SEC announced that it had filed a joint stipulation with SolarWinds and Brown to dismiss the entire civil enforcement action with prejudice. The Commission said it acted in the exercise of its discretion and that the dismissal did not necessarily reflect its position in other cases. The SEC release does not say that the agency conceded its allegations were false, that a court found SolarWinds compliant, or that the 2024 opinion was vacated. The SEC’s dismissal announcement states the terms and the Commission’s qualification.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Practical lessons for public companies and security leaders

Support specific security claims with current evidence

Statements that a company uses defined frameworks, runs particular tests or maintains specified controls are more concrete than broad promises to prioritize security. Companies should be able to substantiate such claims and reconcile them with assessments, remediation plans and known exceptions.

Align public, customer-facing and internal descriptions

Investor communications, public security pages and customer questionnaires can describe the same program in different ways. Review them against internal assessments so a confident external claim does not conflict with known gaps. The relevant question is not whether every control is perfect, but whether the description fairly reflects the state of the program.

Make cyber-incident disclosures precise about uncertainty

During an investigation, separate confirmed facts from preliminary assessments and unresolved questions. Update disclosures as material facts change, and avoid presenting tentative conclusions as settled. The SolarWinds ruling dismissed particular post-incident theories; it did not establish a safe harbor for incomplete or inaccurate reporting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build a clear escalation and review process

Security, legal, finance and disclosure personnel should have a defined route for escalating potentially material cyber information and reviewing high-risk statements. A formal process is useful only if relevant information reaches the people responsible for evaluating disclosures in time to act.

Keep the distinction between aspiration and fact clear

General statements of commitment may be treated differently from verifiable assertions about controls already in operation. Label goals and plans as such; do not describe intended or incomplete work as an established practice.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.