Civil actions brought by the SolarWinds Corp and its Chief Information Security Officer Timothy Brown have been dismissed with prejudice by the Manhattan federal court handling the case, the end result of a settlement negotiation process that began in July of this year.
The case was the first in the US in which a CISO was personally charged with fraud in this way, and could have made major changes as a precedent in breach responsibility should the ruling have gone against SolarWinds. The SEC had been seeking financial penalties and a prohibition against Brown, who has remained in his CISO role, working as an officer or director of any other public companies.
Dismissal of SEC civil actions preserves expected legal status quo for CISOs
The civil actions were first filed in late 2023 and accused SolarWinds and Brown of knowingly concealing the vulnerable state of the company’s cybersecurity from investors before and during the massive breach wave that took place from late 2019 throughout the length of 2020. A number of US federal agencies were compromised downstream after SolarWinds’ network management product Orion was compromised by Russian state-sponsored hackers.
The case differs from the 2022 conviction of Uber CSO Joseph Sullivan in that it involved civil actions rather than criminal charges, and Sullivan was convicted of knowingly obstructing an FTC investigation rather than misleading investors. Brown potentially faced personal financial penalties should the case have gone against SolarWinds, though the sums were never specified.
The civil actions were paused in July of this year as the parties requested a stay of proceedings as a potential settlement was hashed out, the paperwork for which was finalized in August. The judge in the case had previously expressed skepticism about the SEC’s charges of personal responsibility in knowingly concealing security weaknesses, saying that the claims appeared to be based on “hindsight and speculation.” The judge had previously dismissed the majority of the charges in July 2024, calling claims about the company’s internal control procedure failures and post-Sunburst malware infection disclosures “ill-pled.” The remaining charges related to public claims made by the company about its security capability well prior to the beginnings of the Orion breach.
In US courts, a dismissal with prejudice is essentially a final judgement; the same charges cannot be raised again as the case has been determined to be without sufficient merit. This does not impact any other cases in which similar charges have been raised, however.
SolarWinds case prompted fears of broader “chilling effects”
The announcement of the civil actions sent shockwaves through the CISO world, not the least of which was due to the obvious possibility of personal financial liability being levied in response to cybersecurity or disclosure issues. But there were also deeper layers of concern. One is the potential impact on hiring in a field that already struggles to recruit due to the very high requirements for the position and constant increase in complexity of regulations, with fear that qualified candidates would simply see the job as having become too risky due to circumstances beyond their direct control. A late 2024 survey conducted by BlackFog seemed to support this concern, finding that 70% of respondents would be at least be more hesitant to step into the role under these legal conditions.
At the time, this also seemed to signal a SEC enforcement focus in this area. In addition to SolarWinds the agency rapidly filed similar charges about misleading disclosures against Avaya, Check Point, Mimecast, and Unisys, all SolarWinds customers that were impacted by follow-on breaches. That was under the Biden administration, however, and the Trump-era SEC has thus far seemed disinterested in pursuing these cases.
Though there is now some relief and room to breathe, the SEC’s initial aggressiveness with civil actions did prompt many organizations to re-examine how they handle liability insurance. CISOs are typically outside of the C-suite, but are increasingly being offered the same personal liability protections that directors and officers get due to both this incident and changes in regulations around the world.
However, for those that are not protected in this way, this case does demonstrate that regulators and courts tend not to put the screws to CISOs so long as the basics of making all reasonable preparations for known cyber threats and being honest and consistent in official communications are clearly met. Other things that help security leaders are a record of audits, the establishment of strong governance protocols, and documentation of everything done to address vulnerabilities. The lone conviction in this area so far, of Uber CSO Sullivan, involved some clear misleading of both investigators and the company’s own internal lawyers and executives.
Legal bounds in this area are still far from being fully tested or developed via precedent. Dr. Kolochenko, CEO at ImmuniWeb, notes that there are almost certainly more civil actions forthcoming that will shape the terms CISOs work under: “The key message from the SEC’s motion to dismiss, signed on November 20, is that the SEC has exercised its full discretion to dismiss and that the dismissal does not, and shall not, reflect the SEC’s position on any other cases. While the US District Judge Paul Engelmayer dismissed many of the SEC claims in this landmark case in July 2024, the federal agency could proceed with the remaining claims that the court sustained. This would, however, weaken the overall SEC’s position and could possibly lead to a loss in court. For obvious reasons, the SEC did not want to take a risk in this highly publicized and closely watched case, instead preserving its resources for upcoming lawsuits where it can prevail in court with certainty. In sum, one should be prepared for new legal actions by the SEC that may lead to major victories of the federal agency.”
“As to cybersecurity professionals and executives, it would be imprudent to believe that the risk of personal liability for data breaches, implicating their employers, has now vanished. While the 2025 federal enforcement policy in the US is rather innovation and technology friendly, it does not mean that, for example, the FTC or FCC will turn a blind eye to major data protection violations by private corporations. The SEC has likewise made it crystal clear that it will not stop exercising its policing rights, while being much better prepared after its SolarWinds experience. Finally, private lawsuits from aggrieved investors or even victims of data breaches are perfectly plausible, while they will likely pay little attention to the current enforcement priorities or politics. This is not to mention that international businesses have a huge exposure to national laws in all countries where they operate. For instance, under the New Federal Act on Data Protection (nFADP) in Switzerland, private individuals – who are responsible for data security failures, and not their employers – may be fined up to 250,000 Swiss francs (Art. 61). In sum, cyber security community should stay prudent and vigilant, the new litigation era is just starting,” added Kolochenko.

