Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

The SEC’s SolarWinds Case: What CISOs Should Do Now

By TheFinanceBase Team9 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The SolarWinds enforcement case is over, but it did not erase public companies’ cybersecurity disclosure duties or give CISOs a general safe harbor. On November 20, 2025, the SEC filed a joint stipulation dismissing its action against SolarWinds and CISO Timothy G. Brown with prejudice. The Commission described the dismissal as discretionary and said it did not necessarily reflect its position in other cases. For CISOs, the practical response is to make sure security controls, internal reporting, public claims, and incident decisions tell a consistent, well-documented story.

What happened in the SolarWinds case

The SEC’s 2023 complaint concerned the SUNBURST attack, in which attackers compromised SolarWinds’ Orion software build environment and inserted malicious code into updates distributed in 2020. The SEC alleged that SolarWinds’ internal security information painted a more troubling picture than its public statements about its security practices and risks. Among other things, the complaint alleged weaknesses involving remote access, privileged accounts, vulnerable assets, password practices, secure development, and escalation of security information to people responsible for disclosures. These were allegations, not findings after a trial. (SEC complaint; SEC case summary.)

The SEC also challenged SolarWinds’ disclosures, including a December 2020 Form 8-K and statements on its website Security Statement. It alleged that the company’s public risk language and descriptions of security practices did not match what the company knew internally. The SEC named CISO Timothy G. Brown, alleging his participation in aspects of the conduct. The case therefore raised questions about both corporate disclosure processes and an individual security leader’s potential exposure.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the court decided—and what it did not

In July 2024, the U.S. District Court for the Southern District of New York dismissed most of the SEC’s claims. The court rejected the SEC’s effort to use Exchange Act internal-accounting-controls provisions as a general mandate to police cybersecurity controls unrelated to accounting. It also rejected or narrowed major theories involving SolarWinds’ risk-factor disclosures and its December 2020 Form 8-K. A claim concerning the accuracy of the company’s online Security Statement remained pending at that stage, according to SolarWinds’ subsequent filing. The court did not find that SolarWinds’ security program was adequate or that every challenged statement was accurate. (2024 court order; SolarWinds 2024 Form 10-K.)

On November 20, 2025, the SEC and SolarWinds jointly stipulated to dismissal with prejudice, ending that enforcement action. The SEC said it exercised its discretion and that the dismissal did not necessarily reflect its position in other cases. The dismissal is not a judicial finding that the SEC’s allegations were false, a ruling that SolarWinds’ program was compliant, or a categorical bar on future actions against companies or individuals. (SEC dismissal release.)

The dismissal means It does not mean
This particular action is over. CISOs have blanket immunity from enforcement or litigation.
The SEC chose to end the case through a joint stipulation. A court disproved the allegations or endorsed SolarWinds’ security program.
The 2024 ruling remains relevant to the limits of one internal-accounting-controls theory. Cybersecurity controls, disclosure controls, antifraud rules, or other legal duties are irrelevant.

The practical lesson: consistency and escalation

The most useful takeaway is not that the SEC can pursue a CISO for every security failure. It is that risk grows when internal records, control operation, public claims, and escalation processes diverge. A company that describes a control as operating should be able to identify its owner, scope, evidence, exceptions, and validation date. A policy on paper is not the same thing as a control consistently implemented across the environments it claims to cover.

CISOs should pay particular attention to five alignments:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Internal knowledge and public claims. Review whether filings, investor materials, website statements, trust-center content, sales materials, and questionnaires accurately reflect current capabilities and known material limitations.
  2. Policy and implementation. Track exceptions, compensating controls, approvals, risk acceptance, and remediation dates. Avoid describing planned or partial work as fully operational.
  3. Security information and disclosure escalation. Ensure potentially material facts reach legal, finance, executive leadership, investor relations, and the appropriate board committee promptly. The CISO supplies technical facts; securities-law judgments belong in a cross-functional corporate process.
  4. Board reporting and operational risk. Give directors visibility into persistent weaknesses, overdue remediation, accepted risks, supply-chain exposure, and business consequences—not just counts of blocked attacks or tickets closed.
  5. Incident response and evidence. Preserve a contemporaneous record of what was known, when it was known, who was notified, what remained uncertain, and why the company made its materiality and disclosure decisions.

Public-company cyber disclosure rules still matter

For domestic SEC registrants, Form 8-K Item 1.05 generally requires disclosure within four business days after the company determines that a cybersecurity incident is material. The clock is tied to the materiality determination, not automatically to the date of discovery or the start of an attack. The company must make that determination without unreasonable delay. The filing describes material aspects of the incident’s nature, scope, and timing, and its material impact or reasonably likely material impact. Annual reports also include cybersecurity risk-management and governance disclosures under Regulation S-K Item 106. (SEC final rule; SEC compliance guide.)

The SEC rules do not require a company to publish technical details that would impede remediation or provide a roadmap to attackers. The goal is to give investors a truthful, useful account of material impact without turning a filing into an operational vulnerability report.

Discovery, determination, and filing are separate points

For example, if a company detects suspicious activity on Monday, it should immediately investigate and escalate relevant facts. If it later determines the incident is material, the four-business-day filing period runs from that determination. The company should not delay the determination unreasonably while waiting for every forensic detail; nor should it treat initial discovery alone as automatically triggering an Item 1.05 filing. Staff guidance permits a company to file before every detail is known, identify what remains unavailable or undetermined, and amend as information develops. If it chooses to disclose an incident voluntarily before determining materiality, SEC staff has encouraged using another item, such as Item 8.01, rather than prematurely labeling it material under Item 1.05. If the company later determines it is material, Item 1.05 timing applies from that determination. (SEC staff statement, May 21, 2024.)

Materiality is not limited to immediate financial loss. Assess financial effects and qualitative factors, including impact on critical services, sensitive data or intellectual property, regulated operations, customer trust, privileged credentials, build systems, and the company’s risk profile. Consider duration, scope, persistence, access or exfiltration, and whether related incidents should be assessed collectively. The SEC’s Form 8-K interpretations address aggregation of related incidents, which may be material in combination even if each event alone appears immaterial. (SEC Form 8-K interpretations.)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Resolution and law-enforcement contact do not automatically change the analysis

Restoring systems, paying a ransom, or seeing an attack stop does not by itself eliminate the need to assess materiality or disclose an incident that is material. A company may consult DOJ, the FBI, CISA, or other agencies while assessing an incident, but consultation alone does not suspend the filing clock. A delay is available only if the U.S. Attorney General makes and communicates the required written determination that disclosure would pose a substantial risk to national security or public safety. (SEC Form 8-K interpretations; SEC final rule.)

Companies may share additional information beyond an Item 1.05 filing, subject to other obligations such as Regulation FD, privacy, contracts, law-enforcement considerations, and litigation concerns. Coordinate those communications with counsel and investor relations to avoid selective disclosure or inconsistent descriptions. (SEC staff statement, June 20, 2024.)

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A CISO action plan

First 30 days: make disclosure readiness concrete

  1. Map the escalation route. Include security operations, incident response, general counsel, finance and controllership, the corporate secretary, investor relations, communications, business owners, and the board or audit committee as appropriate. Identify primary and backup contacts and how to convene them after hours.
  2. Agree on who decides materiality. Define who convenes the decision group, who has authority, what evidence is needed, how uncertainty and estimates are recorded, how related events are considered together, and how disagreements are escalated. Keep the CISO in the process as a source of facts and technical judgment, not as the sole owner of a securities-law decision.
  3. Exercise the filing timeline. Tabletop discovery, containment, legal hold, executive notification, materiality assessment, potential DOJ consultation, drafting, approvals, filing, and follow-up amendments. Test the process under incomplete information and a weekend or holiday.
  4. Inventory public security statements. Search SEC filings, investor presentations, website security pages and trust centers, customer questionnaires, product documentation, sales materials, certification descriptions, and executive remarks. Security representations outside SEC filings still create consistency and credibility risks.
  5. Map claims to evidence. For each high-risk factual claim, record its control owner, scope, supporting evidence, last validation date, exceptions, compensating controls, approval authority, and review or expiration date. Distinguish aspirations and plans from current operating facts.

By 60 days: reconcile control claims with operations

Prioritize controls that affect both security and the accuracy of public representations: privileged access and remote administration; MFA and service-account governance; secrets and credential rotation; network segmentation; software-build and CI/CD integrity; code-signing keys; identity and endpoint telemetry; vulnerability remediation; logging and retention; backup integrity and recovery testing; third-party and software-supply-chain monitoring; secure development; and incident escalation.

Use a status vocabulary that does not disguise gaps:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Status Meaning
Implemented and tested The control exists and evidence supports its operation.
Implemented with exceptions The control operates, but deviations are identified and managed.
Planned Work has been approved but is not yet operational.
Partial The control operates inconsistently or only in some environments.
Unimplemented No meaningful control is in place.
Unknown Ownership or reliable evidence is missing.

The objective is not to make every line green. It is to know the actual state, assign an accountable owner, document accepted risk, and set realistic remediation dates.

By 90 days: improve executive and board reporting

A board dashboard should show material open risks and trends, critical vulnerabilities past service-level targets, privileged-access exceptions, MFA and endpoint-detection coverage, logging and asset-inventory coverage, third-party and supply-chain exposure, exercise outcomes, detection and containment performance, recovery-test results, accepted risks, significant control failures, and overdue remediation. Explain what changed since the previous report and whether any issue could affect finances, operations, customers, regulation, or public disclosures. Activity measures such as attacks blocked can help, but they do not by themselves show whether material risk is rising or falling.

Build an evidence trail that reflects real decisions

Work with counsel and the disclosure committee to preserve a contemporaneous record of incident discovery; facts known and unknown at each decision point; affected systems, data, customers, and business functions; notifications; operational, financial, legal, and reputational impacts considered; related incidents assessed together; law-enforcement contact; any delay request; the reason for filing or not filing; the basis for the description selected; and facts that later prompted an amendment or follow-up. Record uncertainty and judgment as they existed at the time. Do not reconstruct a falsely certain narrative after the event.

Common mistakes to avoid

  • “We disclosed generic cyber risk, so we are covered.” Generic language may not adequately reflect a known material weakness or a concrete event that changes the risk profile. At the same time, the SolarWinds ruling underscores that risk disclosures are assessed in context and as a whole; boilerplate is not automatically unlawful.
  • “The incident was immaterial at first, so no filing can be required.” The assessment can change as facts develop. A voluntary early disclosure does not prevent a later Item 1.05 filing if the company determines the incident is material.
  • “The incident is fixed, so it need not be disclosed.” Resolution does not erase the materiality analysis.
  • “The SEC’s internal-controls theory is dead.” The court rejected a particular use of the accounting-controls provision as a broad cybersecurity mandate. That is not a blanket exemption from disclosure controls, books-and-records duties, antifraud rules, or other regulatory obligations.
  • “We should publish every technical detail.” Disclose the material picture; do not expose details that could impede remediation or help attackers.
  • “Calling law enforcement pauses the deadline.” It does not, absent the required Attorney General determination and notification.

Risk-factor language deserves particular care. Revisit it when known deficiencies, incidents, architecture, business operations, or critical suppliers materially change the company’s risk picture. The aim is not an exhaustive vulnerability list or a public incident-response playbook; it is a contextual, accurate description that does not leave investors with a misleading impression. The court’s 2024 ruling considered disclosures in context rather than treating a sentence in isolation. (SEC Commissioners Peirce and Uyeda statement.)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.