SolarWinds CISO Says "Security Execs Are Nervous"

March 12, 2025

SolarWinds CISO Tim Brown says security execs are ‘nervous’ about personal liability. Should they be?

Let’s talk about that ‘C’ and ‘O’ in CISO—mostly silent, right? Until a breach or an SEC inquiry. Where exactly does a CISO formally sit in corporate governance? Which corporate filings are they legally required to sign?

Oh, they’re not? Well, allow me to retort.

The real story here isn’t just about malfeasance—it’s about the fundamental disconnect between cybersecurity and corporate risk, compliance, and regulatory functions. The SEC sees internal security reports as evidence of fraud, but do those responsible for corporate filings even recognize them as “reportable material deficiencies”? Negligence or malfeasance—that’s the legal question.

CISOs, take note: SEC and DOJ whistleblower protections exist for a reason. If you report security issues internally but see your corporate filings misrepresent reality, you might be personally on the hook.

Boards, pay attention: cyber risk is business risk, security failures can be material deficiencies, and the SEC and FTC keep making one thing crystal clear—plausible deniability for cyber control deficiencies is dead.

hashtag#InfoSec hashtag#RiskManagement hashtag#CyberRisk hashtag#CISO hashtag#SEC hashtag#Compliance