SolarWinds CISO Charged: A Wake-Up Call for Security Leaders
- Misleading Investors and Cybersecurity Failures: SolarWinds and its CISO, Tim Brown, are charged with fraud by the SEC. They are accused of overstating cybersecurity measures and not disclosing known risks. This happened from their 2018 IPO through the 2020 Sunburst cyberattack. Internal documents revealed they knew their remote access was vulnerable.
- Internal Contradictions and Profit from Deception: Despite public reassurances, internal SolarWinds presentations in 2018 and 2019 highlighted severe security vulnerabilities. Meanwhile, Brown sold 9,000 shares for a $170,000 profit before the stock plummeted by 35% after the attack's disclosure.
- Legal and Ethical Repercussions: The charges have caused concern among CISOs about increased accountability. The SEC's actions may deter potential CISO candidates, exacerbating the shortage of cybersecurity professionals. This case raises questions about the balance between holding leaders accountable and creating a fear-based environment.
- Factual Outcomes of the Case: The SEC's complaint alleges that Brown was aware of but did not address or sufficiently escalate the company's cybersecurity issues. As a result, SolarWinds could not assure the protection of its assets, including its Orion product. The company's stock dropped about 25% two days after disclosing the Sunburst attack and 35% by the end of that month.
Okta Breached Again: This Time via Third-Party Vendor
- Third-Party Breach Leads to Employee Data Exposure: Okta, the identity management giant, faced a breach through its third-party vendor, Rightway Healthcare. The breach, which occurred on September 23, 2023, led to the exposure of personal and healthcare data of nearly 5,000 Okta employees. The compromised data included names, social security numbers, and medical insurance plans.
- Delayed Discovery and Response: The breach was discovered on October 12, nearly three weeks after the initial incident. Okta's response included a thorough investigation, notification of affected individuals, and the provision of free identity and credit monitoring services. This incident adds to a series of security challenges Okta has faced in recent weeks.
- Impact on Okta's Reputation: While Okta's services remained secure, the breach raises concerns about the company's overall security posture, especially considering recent events involving threat actors and supply chain vulnerabilities. The trust of cybersecurity professionals in Okta may be impacted, despite the company's proactive steps to mitigate the situation.
- Recent Security Woes: The breach is part of a series of security incidents involving Okta. Previously, threat actors exploited Okta's software platform to breach MGM Resorts, and Okta's own systems were compromised, leading to the theft of customer data including session tokens and cookies. This was followed by a supply chain attack on its customer 1Password, marking a challenging period for the IAM provider.