Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The SEC’s civil action against SolarWinds and its chief information security officer, Timothy G. Brown, was dismissed with prejudice on November 20, 2025. That is the case’s final disposition—not the result of the court’s July 2024 ruling, which had allowed some claims tied to SolarWinds’ website security statement to proceed while dismissing others. The case drew cybersecurity leaders’ attention because it put an individual security executive in an SEC enforcement action over alleged public disclosures, but it did not establish a general rule that CISOs are personally liable for security failures.

What happened to the SEC’s SolarWinds lawsuit?

The SEC filed its action against SolarWinds and Brown on October 30, 2023. It alleged that the company made misleading cybersecurity statements and omissions before and after the SUNBURST attack. The case ended on November 20, 2025, when the SEC announced it had filed a joint stipulation with SolarWinds and Brown to dismiss the civil action with prejudice.

The SEC quoted the stipulation as saying the decision to seek dismissal was “in the exercise of its discretion” and “does not necessarily reflect the Commission’s position on any other case.” The release did not explain why the SEC chose to dismiss. Dismissal with prejudice ends this action; it is not a ruling that the allegations were proven, nor does the release establish a general position on future enforcement actions. SEC release, Nov. 20, 2025

Why did the case concern cybersecurity leaders?

Brown was named individually alongside SolarWinds in an enforcement case involving alleged public statements about cybersecurity practices, risk disclosures, and incident reporting. That raised a practical concern for security leaders: whether a company’s public disclosures—and an executive’s role in them—could draw securities-law scrutiny when the company faces a cyber incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

The title’s word “spooked” describes the reaction the case could provoke; the available records do not quantify how many cybersecurity leaders reacted that way. Nor does the case establish that a CISO is automatically liable for a breach or for ordinary security shortcomings. It shows that Brown was named in this particular action and that some claims against the defendants survived an early motion-to-dismiss stage before the SEC later dismissed the case.

What did the judge actually rule in July 2024?

On July 18, 2024, Judge Paul A. Engelmayer granted in part and denied in part SolarWinds’ and Brown’s motion to dismiss. The court assessed whether the SEC had plausibly pleaded its claims at that stage; it did not decide that the disputed allegations were true.

Claims challenged July 2024 ruling
Statements in SolarWinds’ website Security Statement The court allowed the pleaded securities-fraud claims to proceed.
Other challenged pre-SUNBURST statements and filings The court dismissed the claims.
Post-SUNBURST disclosure claims The court dismissed all claims.
Internal accounting controls and disclosure controls and procedures The court dismissed the claims.

The SEC’s theory, as summarized by the court, was that SolarWinds’ Security Statement and other communications overstated cybersecurity practices or understated risks, and that immediate post-attack disclosures minimized the incident. Those were allegations. The court’s decision to let the Security Statement claims proceed meant only that the SEC had plausibly pleaded them—not that those statements were ultimately found misleading. The SEC later dismissed the entire action with prejudice. Court opinion, July 18, 2024

Did the SolarWinds opinion interpret the SEC’s cybersecurity disclosure rules?

No. The court said the later-adopted 2023 SEC cybersecurity disclosure rules were not implicated because the case concerned alleged conduct from before those rules’ effective date. The SolarWinds opinion therefore should not be read as a judicial interpretation of those rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Were there other SEC actions related to Orion?

Yes. In a separate set of matters announced on October 22, 2024, the SEC charged Unisys, Avaya, Check Point, and Mimecast over disclosures concerning cybersecurity risks and intrusions related to the Orion compromise. The SEC said its orders found that the companies learned of unauthorized access at different times and minimized aspects of the incidents in public disclosures. These were separate administrative matters, not consequences of the SolarWinds civil action, and they do not establish liability for SolarWinds or Brown.

The SEC release listed civil penalties of $4 million for Unisys, $1 million for Avaya, $995,000 for Check Point, and $990,000 for Mimecast. The companies settled without admitting or denying the findings. SEC release, Oct. 22, 2024

Commissioners Hester Peirce and Mark Uyeda dissented from those proceedings. They argued that the SEC was using hindsight to second-guess incident disclosures and warned that enforcement could encourage companies to add immaterial detail. That was the commissioners’ dissenting view, not the court’s ruling or the Commission’s holding. Their statement quoted the 2023 rulemaking as saying incident disclosure should “focus…primarily on the impacts of…[the]…incident, rather than on…details regarding the incident itself.” Commissioners’ statement, Oct. 22, 2024

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What can companies and security leaders take from the case?

The case is over, but the distinction between security operations and public-company disclosure decisions remains useful. The following are practical questions for organizing disclosure discussions, not a formal SEC checklist or legal advice:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • General risks versus a specific incident: Separate standing risk-factor language from statements about a particular intrusion.
  • Known facts versus evolving details: Identify what is confirmed, what remains uncertain, and how facts may change as an investigation continues.
  • Impact versus technical detail: Consider the incident’s effects alongside technical description; do not assume more technical detail automatically makes a disclosure more useful.
  • Company decisions versus individual roles: Clarify who gathers incident facts, who reviews proposed public statements, and what role each executive—including the CISO—has in the disclosure process.
  • Applicable rules and separate proceedings: Keep pre-effective-date allegations in the SolarWinds case distinct from later SEC rule requirements and from enforcement actions against other companies.

Because the SolarWinds action ended without a final merits decision, it does not resolve how courts or regulators will treat different facts, disclosures, or executives in another case.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.