In December of 2020, SolarWinds Corp. publicly acknowledged a major cyberattack that resulted in supply chain compromise and headline discussions about national security and data security. On Oct. 20, 2023 the U.S. Securities and Exchange Commission (SEC or Commission) charged SolarWinds and its chief information security officer (CISO) with fraud for allegedly failing to disclose known material cybersecurity risks and vulnerabilities.

While the complaint references the cyberattack, the lawsuit notably focuses more on SolarWinds’ allegedly “poor cybersecurity practices” and lack of internal controls, and, for the first time, implicates a CISO personally.