Earlier this week, a novel development in the Securities and Exchange Commission’s (SEC) enforcement of cybersecurity happened as accusations were laid against both SolarWinds Corporation and its Chief Information Security Officer (CISO). The allegations, as reported by Morrison & Foerster on JD Supra, were of scientist-based securities fraud and several other violations. The crux of the issue apparently revolved around the Company and its CISO allegedly providing misleading information to investors about SolarWinds’ security practices and risks.
SolarWinds Corporation, colloquially known simply as “SolarWinds”, and it’s CISO have found themselves in the crosshairs of the SEC due to what is cited as a discrepancy between their outward communications regarding security and the actual practices that were ongoing within the company.
The distinct aspect of these charges is not just the company being on the receiving end, but that its CISO as an individual has also been charged. It highlights a potentially shifting landscape where corporate officers directly tasked with managing and overseeing cybersecurity could face personal liability when things don’t go according to plan. This represents a shift towards more individual accountability in maintaining cybersecurity best practices and could set a precedent for similar cases in future.
The SEC, functioning as the sentinel of investor interests, seems to be sending a clear message. In an era where data breaches and cyber threats are paramount, corporations can expect a rigorous enforcement of regulations regarding cybersecurity transparency. As it stands, there’s arguably a greater onus than ever on corporations to bridge any gap between the intrepid promises made in public disclosures and the reality of their internal practices in maintaining robust and secure networks.