Four victims of the SolarWinds hack are suffering from something of a case of “insult to injury” as their insufficient cybersecurity disclosures will cost them even more money.
The Securities and Exchange Commission (SEC) has reached settlements with Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies Ltd, and Mimecast Limited. Each company was found to have been breached during the SolarWinds hack, but was accused of negligently minimizing the damage and impact in its public disclosures about the incident. The companies will each pay civil penalties ranging from $990,000 to $4 million.
Cybersecurity disclosures found to have materially misled investors
Unisys was hit with the largest penalty of the group, $4 million, due to added procedures violations charges. Avaya Holdings is paying $1 million, Check Point $995,000 and Mimecast $990,000.
The SEC conducted a broad investigation of the SolarWinds hack and the follow-up cybersecurity disclosures that public companies made. About 18,000 clients of SolarWinds were thought to have installed the malicious trojan, but the Russian state-sponsored hackers behind the breach were selective in the targets that they exploited (likely in the low hundreds of organizations).
Each of the fined companies learned that they had been breached during the SolarWinds hack in 2020, except for Mimecast which became aware of an intrusion in 2021. Each was found by the SEC to have negligently minimized its cybersecurity disclosures in ways that could mislead investors, but all using somewhat different language. Unisys couched the risks of the breach as being hypothetical, even though it knew at the time that the attackers had penetrated their system at least twice and exfiltrated tens of gigabytes of data in total. Avaya claimed that the attackers had only accessed some internal emails, failing to add that at least 145 cloud-hosted files had also been stolen. Mimecast failed to specify how many encrypted credentials the attacker had stolen and the nature of code that was exfiltrated. Check Point was accused of describing the intrusion and risk in overly generic terms.
All of the involved companies essentially pled “no contest” to the SEC findings and agreed to cease any future violations of this nature without admitting to the specific charges. The violations included provisions of the Securities Act of 1933 and the Securities Exchange Act of 1934. The SEC said that voluntary cooperation from each of the companies, including undertaking steps to improve cybersecurity controls, were a factor.
SolarWinds hack continues to make news, over four years on
It is coming up on half a decade now since the SolarWinds hack took place, and yet developments and fallout continue. The case also demonstrates that cybersecurity disclosures that involve potential negligence or downplaying of the circumstances have become an increasing enforcement priority for the SEC.
The actions follow new rules for publicly traded companies that went into effect toward the end of last year. The SEC now requires cybersecurity disclosures for expected material incidents within four business days of discovery, though smaller companies with under $100 million in annual revenue can receive a 180-day extension. In addition to monetary penalties of the sort seen here, in serious cases a company might see its CISO barred from serving as an officer or director of a public company. The SolarWinds hack led to its own CISO, Timothy Brown, being held to this level of account. However, Brown was cleared of this punishment in July when a US District Court found that the SEC had relied on impermissible hindsight and speculation in its charges.
The SolarWinds hack has been so devastating in no small part due to how long it went undetected. It is thought to have originated as early as January 2019, but the public did not begin learning of it until December 2020. The hackers were able to insert their malware code into three product updates during this time, which were disseminated to the company’s downstream customers. The attack was most damaging in the US, where impacted companies saw an average loss of 11% of their annual revenue. The UK was the second hardest-hit country, at an average loss of 8.6% of annual revenue.
The SEC has shown a willingness to look back at prior cybersecurity disclosures with this decision, at least in major cases that involve national security and/or massive and widespread financial damage. However, it has not experienced a complete record of success in this area. In addition to exonerating Brown, the July court decision also shot down the SEC’s justification for penalizing SolarWinds over its own disclosures. Two SEC commissioners, Hester Peirce and Mark Uyeda, also dissented with the current SolarWinds hack fines and expressed the opinion that the victims should not be treated as perpetrators.
Keith McCammon, CTO of Red Canary, notes that organizations should nevertheless anticipate similar actions in these high-profile cases: “This action is notable as the SEC is looking retroactively at major incidents such as the SolarWinds breach, and imposing fines based on violations of long-standing rules. This underscores the importance of clear, honest, and timely disclosure of material cybersecurity incidents to all stakeholders. One of the best things companies can do to prepare is to clearly define a material cybersecurity incident in the context of their business, where a key component of both the criteria and response plan is the identification of key stakeholders. We are starting to see more and clearer signals that the U.S. government at-large—via the National Cybersecurity Strategy, CISA, and other agencies—will continue to push for legislation and enforcement as it relates to cybersecurity preparedness, compliance, and reporting.”

