Lawfare Daily: Shoba Pillay and Jennifer Lee on the Dismissal of Charges Against the SolarWinds Corporation and Timothy Brown
Aug 21, 2024
auto_awesome
Shoba Pillay, a partner at Jenner & Block and former federal prosecutor, and Jennifer Lee, a legal analyst and ex-Assistant Director in the SEC’s Division of Enforcement, delve into the recent court ruling involving the SolarWinds case. They dissect the SEC's dismissal of charges against the company and its CISO Timothy Brown, highlighting the challenges of cybersecurity governance and enforcement. The conversation reveals the implications for corporate accountability and the legal landscape as it evolves in response to cybersecurity threats.
The dismissal of certain charges against SolarWinds indicates a nuanced view of liability in cybersecurity-related enforcement actions by the SEC.
The SolarWinds case could reshape future SEC cybersecurity strategies, emphasizing the distinction between regulatory compliance and actual security practices.
Deep dives
Overview of the SolarWinds Intrusion
The SolarWinds incident, often referred to as the Sunburst attack, involved a significant cyber intrusion where threat actors accessed SolarWinds' network and embedded malicious software into its Orion software updates. This breach affected approximately 18,000 of the 33,000 customers who installed the compromised updates, granting unauthorized access to sensitive networks, including major government agencies and private sector entities. The scale of this attack changed the landscape for supply chain cybersecurity, underscoring potential national security risks due to the sensitive data that could have been compromised. Notably, the attack illustrated how vulnerable even well-resourced organizations can be to sophisticated cyber threats.
SEC's Charges Against SolarWinds
The U.S. Securities and Exchange Commission (SEC) brought a significant case against SolarWinds and its Chief Information Security Officer (CISO), Timothy G. Brown, focusing on alleged misleading statements related to the company’s cybersecurity practices. The SEC argued that prior to the Sunburst attack, SolarWinds overstated its cybersecurity strength in its public disclosures, leading investors to believe the company was adhering to industry best practices. Furthermore, after the attack, the SEC claimed that SolarWinds downplayed the event's severity in their disclosures, which could have misled investors. This case represents a landmark move by the SEC in holding a company and its CISO accountable for allegations of intentional fraud based on cybersecurity lapses.
Court's Ruling on SEC Claims
The court dismissed several claims from the SEC against SolarWinds, notably the allegations regarding the company's incomplete risk factor disclosures and claims deemed as inactionable puffery. However, it allowed the SEC's fraud claims stemming from the security statement to move forward, indicating significant discrepancies between SolarWinds' public assertions and actual practices regarding access controls and password protections. The court ruled that the SEC's assertion regarding internal accounting controls violations related to cybersecurity was unfounded, emphasizing that the statute applied primarily to financial accounting. This decision reflects a nuanced understanding of the legal parameters surrounding cybersecurity claims and sets a precedent for future cases.
Implications for Future Cybersecurity Enforcement
The outcome of the SolarWinds case may shape how the SEC approaches future cybersecurity enforcement actions, potentially prompting a refinement of its theories in subsequent investigations. While the court's ruling confirmed the SEC's authority to pursue cases against companies for investor fraud related to cybersecurity practices, it also highlighted the complexities and difficulties in proving such cases. The SEC is likely to continue examining whether companies downplay cybersecurity risks in public disclosures while ensuring that its actions do not inadvertently compromise companies' security communications. As the landscape of cybersecurity evolves, organizations will need to navigate both the demands of regulatory compliance and the practical challenges of defending against cyber threats.
The fallout from the SolarWinds intrusion took a new turn with the U.S. Securities and Exchange Commission’s (SEC) decision to file a cybersecurity-related enforcement action against the SolarWinds corporation and its Chief Information Security Officer (CISO), Timothy G. Brown, in October of 2023. But In July, District Court Judge Paul A. Engelmayer dismissed a number of charges in the SEC’s complaint against SolarWinds and Brown.
To talk about this significant development in the case, Stephanie Pell, Lawfare Senior Editor and Brookings Fellow, sat down with Shoba Pillay, a partner at Jenner & Block and a former federal prosecutor, and Jennifer Lee, also a partner at Jenner & Block and a former Assistant Director in the SEC’s Division of Enforcement. They discussed the court’s rationale for allowing some charges to stand, while dismissing others, what stood out most in the dismissal of the case, and how this case may shape the SEC’s cybersecurity enforcement actions in the future.