CISO Personal Liability After SolarWinds: What the Community Actually Said

Quick answer: The SEC's case against SolarWinds CISO Tim Brown was dismissed with prejudice in November 2025, but that does not make personal liability disappear - it makes documentation your best defense. Keep timestamped, tamper-evident records of every risk you escalated, and use the readiness checklist and evidence criteria below to know whether you are actually protected.

When the SEC brought an enforcement action against Tim Brown, the CISO of SolarWinds, it did something unusual: it went after an individual, not just the company. CISOPlatform hosted a panel with Jim Routh, Michael W. Reese, and Matthew Rosenquist to unpack it. It's one of the most substantive sessions in the community's archive - and, until now, it lived across three disconnected posts with barely 400 combined views. Why this case rattled the profession Jim Routh's framing: this is a precedent-setting event. Regulatory enforcement usually evolves through years of collaboration between regulators and industry to work out the practical mechanics of a new rule. An enforcement action against an individual CISO short-circuits that process - and the community's reaction, in Routh's words, was essentially: "wait a minute, this appears to be a bit draconian." The stat that should worry every board Routh shared a live example from his own advisory work: in a CISO search he was running with a dozen candidates, two withdrew specifically because of personal liability concerns raised by the SolarWinds/Tim Brown case. In a market where security talent is already scarce, a precedent that makes senior candidates opt out of the CISO role entirely is a direct business risk, not just an industry talking point. Jim Routh's three levels of change CISOs need to make 1. Fix identity access management inside DevOps. Routh called IAM embedded in the software pipeline "really weak" industry-wide - a legacy of on-prem thinking that hasn't caught up to cloud-first development. 2. Get a real seat at the table, with the authority to match. Reese's point: this is a genuine game-changer for what a CISO is responsible for, and organizations have to be intentional about giving that seat real weight, not just a title. 3. Treat software supply chain poisoning as the number one enterprise cyber risk. Routh: the right level of resourcing and practice has to follow that designation - it can't just be a slide in a board deck. The shareholder question nobody likes to answer The panel posed a sharper version of the disclosure debate: if you were a SolarWinds shareholder, would you have wanted to know management was aware of active attacks on its primary product for six months? Routh's answer reframes disclosure away from legal minimum and toward what a reasonable investor would expect to be told. The one defense that actually holds up A recurring thread across all three original posts: documentation of good-faith action is the single best protection against a fraud claim. If a CISO can show they were acting in good faith with the information available, prosecutors have a much harder case - which makes contemporaneous documentation a personal-liability control, not just a compliance checkbox. Put your own documentation to the test: Verified CISOPlatform members can request a free AI-powered pentest of their attack surface from FireCompass - a concrete artifact showing you proactively tested and documented your security posture, exactly the kind of good-faith evidence this panel says matters most. Forum seed question: If your organization had a SolarWinds-style incident tomorrow, could you personally produce six months of documentation showing good-faith action? What's missing?

Update: what actually happened to the SolarWinds case

Since this panel was recorded, the case moved fast. In July 2024, Judge Paul Engelmayer dismissed most of the SEC's claims against SolarWinds and Tim Brown - including everything tied to the pre-SUNBURST risk-factor disclosures and the internal accounting-controls theory - while allowing narrower fraud claims tied to specific pre-breach statements to proceed. Then, on November 20, 2025, the SEC agreed to dismiss its remaining claims against SolarWinds and Brown with prejudice, closing out the first-ever individual CISO enforcement action of its kind with no finding against him.

What that does and doesn't mean for you: it does not mean personal liability risk for CISOs has gone away. The SEC's most aggressive theory - that a CISO's internal risk assessments and disclosure judgment calls amount to securities fraud - did not survive contact with a federal court, and that's a meaningful data point for CISOs and their counsel. But Joe Sullivan's criminal conviction as Uber's CISO stands untouched, built on a different legal theory entirely (obstruction and failure to report a breach to the FTC, not disclosure fraud) - so the underlying exposure a CISO carries hasn't disappeared, it's just better defined. The panel's core advice - document your good-faith actions contemporaneously - is, if anything, more clearly the right answer now that we've seen which legal theories hold up and which don't.

Are you personally exposed right now? A readiness self-assessment

  • Do you have a documented, timestamped decision trail for the major security calls you've made in the last twelve months - not a reconstruction after the fact?
  • Does your company's D&O policy explicitly name "CISO" or "Chief Information Security Officer," or does it only reference "officers" in a way that could be argued either way in a dispute?
  • Is there a self-insured retention on that policy large enough to functionally bankrupt you personally before coverage kicks in?
  • Do you have personal indemnification commitments in writing - board-approved, not a verbal assurance from your CEO?
  • Have you confirmed whether the D&O policy covers SEC or regulatory enforcement actions specifically? Some policies exclude regulatory investigations or cap them separately from shareholder litigation.
  • Do you know the tail coverage period if you leave the company - and whether indemnification survives an acquisition or change of control?
  • Have you retained your own counsel's contact information before you need it, rather than relying solely on company counsel whose duty is to the company, not to you personally?
  • Do board minutes and risk register entries reflect the risks you raised, even in cases where leadership chose not to act on them?

Two or more "no" answers here is the actual definition of personal exposure - not whether you've been named in a lawsuit yet.

Questions to ask your legal counsel, D&O insurer, and GRC vendor

  • To legal counsel: If we had a SolarWinds-style incident tomorrow, whose interests do you represent - mine or the company's - and at what point would that conflict require me to get my own lawyer?
  • To your D&O insurer: Does this policy cover defense costs for SEC enforcement, criminal referral, and shareholder derivative suits, or only one of the three?
  • To your D&O insurer: Are defense costs advanced as incurred, or reimbursed only after the case concludes - because mounting a defense is expensive well before any judgment.
  • To your D&O insurer: What exactly triggers exclusions - willful misconduct clauses are common, and prosecutors and plaintiffs' counsel will always argue your conduct meets that bar.
  • To your GRC vendor: Can this system produce a timestamped, tamper-evident record of a security decision from eighteen months ago, in a format legal can use in a filing?
  • To your GRC vendor: Does it support legal hold and e-discovery workflows, or is documentation just a compliance checkbox with no evidentiary value?

RFP / evaluation criteria for GRC and documentation tooling

Criterion Why it matters for personal liability
Immutable audit trail A record that can be altered after the fact has no evidentiary value in your defense
Timestamped decision logging Contemporaneous documentation is the single defense the panel agreed actually holds up
Board reporting templates Shows risks were escalated, not buried, even when the board chose a different path
Legal hold / e-discovery support Your documentation needs to survive being subpoenaed, not just audited
Incident timeline integration Ties SIEM/ticketing timestamps to governance decisions for a defensible narrative
Retention configurability Long enough to cover statute-of-limitations windows relevant to securities and state claims
Access controls on records Prevents "the record was edited after the incident" from becoming the plaintiff's argument

The protections most CISOs still haven't put in place

  • A retainer with a personal attorney, agreed before an incident, not sourced from a panic search during one.
  • A written, board-minuted acknowledgment every time you flag a risk that leadership decides not to fund or fix.
  • Confirmation, in writing, of whether your indemnification and D&O coverage survive if you're terminated, if the company is acquired, or if you resign.
  • A standing tabletop exercise cadence with minutes kept as a formal record - not just a checkbox but genuine evidence of proactive testing.

Sources

Related reading on CISO Platform

Votes: 0
E-mail me when people leave their comments –

Priyanka Aash is Co-Founder of CISO Platform, the world's first online community for information security executives, and Co-Founder of FireCompass. She has been nominated for the Cybersecurity Excellence Award for leadership and AI innovation in cybersecurity, honored with the NetApp Excellerate HER award, and featured in SC Media's Women in IT Security series. She is the author of The AI Divide. Security technologist Bruce Schneier advises FireCompass.

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion