October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

What Happened to the SEC’s SolarWinds CISO Lawsuit—and What It Means for Cybersecurity Leaders

The SEC dismissed its SolarWinds action against CISO Timothy Brown with prejudice in November 2025. Here is why the case drew attention and what the court’s earlier ruling meant.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The SEC’s civil action against SolarWinds and its chief information security officer, Timothy G. Brown, was dismissed with prejudice on November 20, 2025. That ended this case, but it does not establish a general rule that CISOs are either personally liable or immune from SEC action. The case drew attention because Brown was named individually and, in July 2024, a court allowed claims tied to SolarWinds’ website Security Statement to proceed past the motion-to-dismiss stage.

What happened to the SEC’s SolarWinds lawsuit?

The SEC filed its action against SolarWinds and Brown on October 30, 2023. The agency alleged that the company made misleading cybersecurity statements and omissions before and after the SUNBURST compromise. The allegations concerned its public-facing Security Statement, risk disclosures and filings, public statements, incident-related Form 8-Ks, and internal controls. They were allegations, not findings that every challenged statement was false or misleading. The court’s opinion summarizes the claims and the later motion-to-dismiss ruling.

On July 18, 2024, Judge Paul A. Engelmayer granted in part and denied in part the defendants’ motion to dismiss. The case did not end with that order: claims tied to the Security Statement survived at the pleading stage.

On November 20, 2025, the SEC announced that it had filed a joint stipulation with SolarWinds and Brown to dismiss the action with prejudice. The SEC quoted the stipulation as saying the decision was made “in the exercise of its discretion” and “does not necessarily reflect the Commission’s position on any other case.” The SEC’s release states the disposition but does not give a reason for the decision.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can a CISO be sued personally by the SEC?

Brown’s inclusion shows that an SEC enforcement action can name an individual executive alongside a company. It does not establish that CISOs are automatically personally liable for a security failure, or identify a general standard for when the agency would pursue one. The claims in this case concerned alleged securities-law violations involving statements and disclosures, not simply the fact that a cyberattack occurred.

The outcome matters: the action against Brown, as well as SolarWinds, was dismissed with prejudice. But that case-specific dismissal is not a blanket protection for other executives. Nor did the 2024 order ultimately establish that Brown or SolarWinds violated securities law.

What did the judge actually rule in 2024?

The July 2024 opinion assessed whether the SEC had plausibly pleaded its claims, not whether the allegations had been proven at trial. The court divided the challenged claims rather than accepting or rejecting the SEC’s case as a whole. Read the court opinion for the ruling and its reasoning.

Claims at issue July 2024 result
SolarWinds’ website Security Statement Securities-fraud claims were allowed to proceed at the pleading stage.
Other challenged pre-SUNBURST statements and filings Claims were dismissed.
Post-SUNBURST disclosures All claims based on those disclosures were dismissed.
Internal accounting controls and disclosure controls and procedures Claims were dismissed.

“Allowed to proceed” was not a finding that the Security Statement was misleading. The later dismissal with prejudice ended the civil action without turning those allegations into proven violations.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why did the case unsettle cybersecurity leaders?

The case put a familiar governance question into a high-stakes securities-law setting: can a company’s description of its cybersecurity practices, its risk disclosures, or its incident reporting expose the company and an individual executive to enforcement? The personal naming of Brown made that question particularly salient to security leaders. The case also drew attention to the difference between general descriptions of security capabilities and statements made as risks or incidents evolve.

There is no population-level survey in the cited records measuring how many cybersecurity leaders were “spooked.” That word is a characterization of the reaction, not a measured finding. The concrete source of concern was the specific enforcement action and the 2024 ruling that allowed one category of claims to continue at that stage.

Did the court interpret the SEC’s 2023 cybersecurity disclosure rules?

No. The court said the later-adopted cybersecurity disclosure rules were not implicated because the case concerned alleged conduct predating their effective date. The SolarWinds opinion should not be treated as an interpretation of those rules. Its analysis addressed the earlier conduct alleged in that case. The opinion explains that distinction.

What separate SEC actions followed in 2024?

On October 22, 2024, the SEC announced settled charges against four companies—Unisys, Avaya, Check Point, and Mimecast—concerning disclosures about intrusions related to the Orion compromise. The SEC’s release said its orders found that the companies had learned of unauthorized access at different times and had minimized aspects of the incidents in public disclosures. The companies settled without admitting or denying the findings. These were separate administrative matters, not part of the SolarWinds civil action and not evidence of liability by SolarWinds or Brown. The SEC release lists the matters and penalties.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Company Penalty listed by the SEC
Unisys $4 million
Avaya $1 million
Check Point $995,000
Mimecast $990,000

Commissioners Hester Peirce and Mark Uyeda dissented from those 2024 proceedings. They argued that the SEC was second-guessing disclosures with hindsight and warned that enforcement could encourage companies to add immaterial detail. That was the commissioners’ dissenting view, not the Commission’s official holding or the SolarWinds court’s decision. Their statement quoted the 2023 rulemaking as saying incident disclosure should “focus…primarily on the impacts of…[the]…incident, rather than on…details regarding the incident itself.” Read the commissioners’ statement.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should companies and security leaders take from the case?

The records do not provide a formal SEC checklist or legal advice. They do point to distinctions that can help companies scrutinize cyber disclosures and escalation decisions:

  • General risk language versus incident-specific statements: A broad description of security practices and a disclosure about a particular incident address different matters. Review whether each statement is accurate in its context.
  • Known facts versus evolving details: Separate what the company has confirmed from what remains under investigation. Avoid presenting unverified scope or impact as settled.
  • Impacts versus technical details: Consider what is known about effects on the company, customers, or investors, rather than assuming technical detail alone answers the disclosure question.
  • Company decisions versus an executive’s role: Identify who made, reviewed, and communicated disclosure decisions, and what the individual actually said or approved. The SolarWinds action named Brown, but does not establish personal liability for CISOs generally.
  • Applicable time period and rules: Distinguish allegations about earlier conduct from later disclosure requirements and from separate enforcement matters.

Because the SEC did not state why it sought dismissal, the final disposition should not be read as an endorsement or repudiation of every enforcement theory raised in the case. It establishes that this particular action ended with prejudice; the July 2024 order remains a partial pleading-stage ruling, not the case’s final outcome.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.