On October 30, 2023, the Securities and Exchange Commission (SEC) has taken action against software development company SolarWinds Corp., citing allegations of fraud and internal controls failures. This action is in relation to purportedly known cybersecurity risks and vulnerabilities which were observed from October 2018 until January 2021.
The complaint filed by the SEC denotes an instance of the regulatory body holding corporate officers accountable for security failures as it also implicates the Company’s Chief Information Security Officer (CISO).
This case underscores the elevated importance of cybersecurity measures and the potential legal ramifications for companies failing to adequately uphold these measures. The period of the alleged misconduct, encompassing more than two years, suggests that thought should be given to the longevity and consistency of a firm’s security practices.
While the penalties for SolarWinds and its CISO are as yet unspecified, it should be noted that sanctions imposed by the SEC can have serious financial and reputational consequences. This case serves as a reminder that more than ever, vigilance in maintaining strong cybersecurity practices and a culture of transparency within firms is not just prudent, but vital.
Please follow this story for updates on how the SEC’s actions will impact SolarWinds and potentially usher in new standards and expectations for cybersecurity in the corporate sphere.