It’s interesting to see SEC go after a CISO, yes he was at the helm but can’t the one to patch systems… yes they had an ongoing attack but disclosing that to shareholders is a sensitive affair… they were also a technology provider to the US government. I honestly think that is what got them the teeth of the SEC.