SEC notifies SolarWinds CISO and CFO of possible action in cyber investigation
cybersecuritydive.com
cybersecuritydive.com
I.e. they are being prosecuted not because they were "incompetent and got hacked", but that they then "tried to cover it up", which is where the SEC comes in (illegal stock manipulation via false or incomplete release of public information).
Capone was taken down for tax evasion. Any tool we have, is a good one.
And the more shareholders and board members feel lax security could lead to a bad path (eg hiding the result), the better for all.
I can hardly wait for the first civil lawsuits, for any such incident, by shareholders over negligence and loss of value.
I can hardly wait until everyone had to provide a license validation for all code they use, so we can finally put node crap to rest.
I don't see a reason Node dies faster than say, Java, or Rust or ...
You mean like UPS just did?
And report up to the CEO.
But it also depends on the nature of the action that's about to come down. My guess is something to do with misrepresentation of Solarwinds' security posture.
@dvt: you can nudge with legislation (or in this case, executive branch rule making), we’re just at the initial phase of getting there: https://www.axios.com/2023/04/07/company-boards-sec-cybersec... | https://www.sec.gov/news/press-release/2022-39 | https://www.forbes.com/sites/bobzukis/2022/04/18/the-sec-is-...
Statute and rule making, like corporate bylaws, are mutable, and must adapt to the risk landscape.
(thoughts and opinions my own, interim deputy CISO in finance)
I mean, this is all company bylaws, you can't seriously legislate this. But in any case, C-execs do have skin in the game (particularly if investigated by the SEC). They're usually insulated, but if non-compliant (or grossly negligent), directors can be personally liable.
Edit: wish folks downvoting this would comment too. We're supposed to be curious here.
There should definitely be a government inspector general empowered to poke around.
SolarWinds was a sophisticated operation, but there are a ton of security orgs for very important companies that are just inept, underfunded, or both. And absent mandated ability to inspect, they're not going to get the harsh spotlight of "unfuck this now" they deserve.
When refusal to take cybersecurity seriously results in 1/3 of Americans losing their identity or when refusal to take cybersecurity seriously results in what happened to solarwinds they should be subjected to a regulatory scheme that will enforce seriousness.
Part of the problem is that the term "identity theft" itself is spin to avoid addressing security problems.
As brilliantly pointed out by Mitchell & Webb: https://www.youtube.com/watch?v=CS9ptA3Ya9E
Identity theft is not a joke Jim.
The BBC period costume drama image of posh characters referencing the classics makes that look more respectable, but I'm not sure how different was that in practice to the modern day, say, barrage of obvious reaction "meme" images to a Tweet.
As the poet said, "Hasta la vista, baby."
Just because enough identifying information about me had been leaked where people could potentially use it to impersonate me, does not mean that I stop knowing who I am.
Edit: Notably, where did you get that quote? I'm not seeing it in this story.
The quotes are not from the article, it's a writing style.
As with most answers, this one comes with questions of its own. If it was that well known and obvious, why did it take so long to move on it? I'm now interested in this topic. :D
Windows-centric orgs barely know software from their ass.
If your org is dumb enough to run closed source software for core IT functions, or you run Windows on bare metal, or don't have TPM chips and secure boot enabled, you kinda deserve what you get.
Palo Alto detected the SolarWinds problem early, but failed to notify the Cyber Threat Alliance which it spearheaded, significantly exacerbating the impact: https://www.cfr.org/blog/most-tools-failed-detect-solarwinds...
The PE firm that basically ran SolarWinds into the ground (Thoma Bravo) bought Proofpoint in 2021, not too long after the debacle became public.
>“Sunburst was a highly sophisticated and unforeseeable attack that the United States government has said was carried out by a global superpower using novel techniques in a new type of threat that cybersecurity experts had never seen before,” a company spokesperson told Cybersecurity Dive in an emailed statement
If there was a criminal referral they wouldn’t announce it and any charges would usually sigbificantly trail civil enforcement action, judging from every other SEC civil + DOJ criminal action I’ve seen.
Not just any prod system... the one that distributed their trusted updates to their entire customer base I believe.
From what I can tell, all we know is that the attackers definitely got into their build system (since the trojan was signed), and we know they moved laterally through exploits in various Microsoft products: https://en.wikipedia.org/wiki/2020_United_States_federal_gov...