{"id":4536,"date":"2024-07-18T16:43:20","date_gmt":"2024-07-18T21:43:20","guid":{"rendered":"https:\/\/www.darkreading.com\/application-security\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec"},"modified":"2024-07-18T16:43:20","modified_gmt":"2024-07-18T21:43:20","slug":"solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/18\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec\/","title":{"rendered":"SolarWinds Charges Tossed Out of Court in Legal Victory Against SEC"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt68eed791d79d2ca5\/66997f8dbe5399f6443f0371\/judge_Tetra_Images_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A judge has dismissed a hefty swath of the Securities and Exchange Commission (SEC) litigation against SolarWinds and its chief information security officer (CISO), Tim Brown, ruling that they cannot be held liable for statements and filings made after the breach of the company&#8217;s flagship Orion product.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, the SEC can proceed with its <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/sec-charges-against-solarwinds-ciso-send-shockwaves-through-security-ranks\" rel=\"noopener\">charge against SolarWinds and Brown<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for misrepresentations made about the company&#8217;s cybersecurity posture leading up to the cyberattack, according to the ruling from US District Court Judge Paul A. Engelmayer released on July 18. Court filings refer to the cyber incident as &#8220;Sunburst.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The ruling is in response to SolarWinds&#8217; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/solarwinds-files-motion-to-dismiss-sec-lawsuit\" rel=\"noopener\">motion to dismiss the SEC lawsuit<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> filed in January of this year.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"SolarWinds Information-Sharing &quot;Vindicated&quot;\">SolarWinds Information-Sharing &#8220;Vindicated&#8221;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Legal and cybersecurity experts say the ruling is a positive move toward providing guidance to other publicly traded companies on how to deal with cybersecurity incident disclosure regulations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;For public companies rushing both to investigate an incident and make a materiality disclosure, the court&#8217;s opinion allows the totality of the disclosure to prevail over the nitty-gritty details,&#8221; says cyber attorney Beth Burgin Waller of Woods, Rogers, Vandeventer, Black PLC.&nbsp;&#8220;This decision vindicates SolarWinds&#8217; information sharing with the cybersecurity community post-incident.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While the ruling removes many of the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/3-years-later-solarwinds-ciso-shares-3-lessons-from-the-infamous-attack\" rel=\"noopener\">charges against SolarWinds and Brown<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, the SEC will be allowed to pursue action for statements and other claims made about the cybersecurity posture of the company prior to its compromise. Disclosures and statements made about the company&#8217;s security posture prior to the breach are &#8220;viably pled as materially false and misleading in numerous aspects,&#8221; the judge wrote.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">After joining SolarWinds in 2017, Brown internally highlighted deficits in the company&#8217;s defenses while delivering more rosy assessments to customers, the ruling explained. Notably, the SolarWinds &#8220;Security Statement&#8221; falsely claimed compliance with the National Institute of Standards and Technology (NIST) Cybersecurity Framework.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A SolarWinds spokesperson said the company was &#8220;pleased&#8221; with the ruling in a statement.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We look forward to the next stage, where we will have the opportunity for the first time to present our own evidence and to demonstrate why the remaining claim is factually inaccurate,&#8221; the statement said. &#8220;We are also grateful for the support we have received thus far across the industry, from our customers, from cybersecurity professionals, and from veteran government officials who echoed our concerns, with which the court agreed.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"CISO Hot Takes\">CISO Hot Takes<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Jessica Sica, CISO with Weave, was especially encouraged by the court&#8217;s decision to toss out internal communications evidence among SolarWinds employees.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Internally, you need to be able to discuss the state of security \u2014 for better or for worse \u2014 and not have that get out as if you weren\u2019t doing your job,&#8221; Sica says. &#8220;The SEC keeping that portion in could have led to more companies having a sort of &#8216;don\u2019t ask, don\u2019t tell&#8217; policy on security, and that would make things much worse.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The court ruling also loosens some constraints on CISOs, according to Fred Kwong, Ph.D., vice president, and CISO of DeVry University.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Holding CISOs personally liable, especially those CISOs that do not hold a position on the executive committee, is deeply flawed and would have set a precedent that would be counterproductive and weaken the security posture of organizations,&#8221; Kwong says. &#8220;While not out of the woods, I&#8217;m happy to see that the court has dismissed most of the charges, especially those post-Sunburst.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Regardless of the ultimate outcome of the SEC&#8217;s action against SolarWinds and Brown, Sica urges fellow CISOs to continue to be transparent.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I think this doesn\u2019t change the fact that you need to be honest about your security posture, and that\u2019s a good thing,&#8221; Sica says. &#8220;If you are promising publicly that you are doing it.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;As to post-Sunburst disclosures, the Court dismisses all claims,&#8221; the ruling said. &#8220;These do not plausibly plead actionable deficiencies in the company&#8217;s reporting of the cybersecurity hack. They impermissibly rely on hindsight and speculation.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/application-security\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A judge has dismissed a hefty swath of the Securities<\/p>\n","protected":false},"author":12,"featured_media":4537,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4536","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec-scaled.jpg?fit=2560%2C1455&ssl=1",2560,1455,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec-scaled.jpg?fit=300%2C171&ssl=1",300,171,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec-scaled.jpg?fit=640%2C364&ssl=1",640,364,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec-scaled.jpg?fit=640%2C364&ssl=1",640,364,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec-scaled.jpg?fit=1536%2C873&ssl=1",1536,873,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec-scaled.jpg?fit=2048%2C1164&ssl=1",2048,1164,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec-scaled.jpg?fit=1024%2C582&ssl=1",1024,582,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec-scaled.jpg?fit=2560%2C1455&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4536","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4536"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4536\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4537"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4536"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4536"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4536"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}