Compliance Briefing — SEC charges SolarWinds and CISO over cyber risk disclosures
The SEC filed enforcement actions on 30 October 2023 against SolarWinds and its CISO, alleging misleading cyber risk disclosures and internal controls failures tied to the 2020 Orion compromise.
On 30 October 2023 the U.S. Securities and Exchange Commission charged SolarWinds Corporation and its CISO with fraud and internal control violations related to statements about the company’s cybersecurity posture before and after the 2020 Orion supply-chain compromise. The complaint cites gaps between public filings and internal assessments, emphasizing disclosure obligations for material cyber risks and incidents.
Public companies should align cyber risk factors and incident timelines with board and audit committee oversight, strengthen documentation of control evaluations, and ensure Form 8-K and 10-K narratives reflect internal security realities.
Continue in the Compliance pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Third-Party Risk Oversight Playbook — Zeph Tech
Operationalize OCC, Federal Reserve, EBA, and MAS outsourcing expectations with lifecycle controls, continuous monitoring, and board reporting.
-
Compliance Operations Control Room — Zeph Tech
Implement cross-border compliance operations that satisfy Sarbanes-Oxley, DOJ guidance, EU DORA, and MAS TRM requirements with verifiable evidence flows.
-
SOX Modernization Control Playbook — Zeph Tech
Modernize Sarbanes-Oxley (SOX) compliance by aligning PCAOB AS 2201, SEC management guidance, and COSO 2013 controls with data-driven testing, automation, and board reporting.




