Case · contested2017 – 20266 sources

Timothy G. (Tim) Brown

Case — personal legal exposure and disclosure behaviour (SolarWinds)

This is a contested case, and the contest is the point. A regulator alleged that a company and its CISO personally misled investors about security; a court dismissed most of it; the regulator dropped the rest. Nothing here is a finding about the program or a verdict on the person. Teach it as a question about what personal legal exposure does to disclosure behaviour.

Roles and dates

Compiled from the sources listed at the foot of this page. Where a date is unconfirmed in the public record, the entry says so.

  • Vice President, Security; later Chief Information Security Officer through and after the SUNBURST compromiseSolarWinds2017–2026
  • General partner and CISO in residenceTeam8announced March 2026

Situation and mandate

FACT Brown joined SolarWinds in 2017 as VP of Security and was CISO during and after the SUNBURST supply-chain compromise disclosed in December 2020 [5]. He remained through response, remediation and a federal enforcement action naming him personally, and is now general partner and CISO in residence at Team8 [5][6].

Documented decisions

  1. Stay rather than depart, leading response and remediation and remaining through the enforcement action [5].
  2. Rebuild the build pipeline, not just the estate. Secure by Design introduced a parallel-build model — dual build from January 2021, a full "triple build" at SLSA Level 4 by Phase III — because "multiple builds require collusion from multiple people to affect the build environment," and subverting three "would require three highly trusted architects" [3].
  3. Buy redundant visibility. Three separate SOCs fed by CrowdStrike, SecureWorks and internal monitoring, "to increase visibility across the entire environment" [3].
  4. Keep speaking publicly while personally charged — though silence, in his own later description, would have been "the safest move — at least in terms of his own liability" [6].
  5. Convert the experience into communication discipline — written conduct policies consistently enforced, employees educated about discovery "including email tracing and scraping," internal channels monitored [6].

Reported results

FACT On 30 October 2023 the SEC charged SolarWinds and Brown with fraud and internal-control failures — alleging that from October 2018 to December 2020 they overstated the company's cybersecurity practices and understated known risks — and sought an officer-and-director bar against Brown [1].

FACT On 18 July 2024 Judge Paul Engelmayer (S.D.N.Y.) dismissed nearly all of it: Brown's podcast, blog and press-release statements were "non-actionable corporate puffery"; the internal-accounting-controls theory was rejected — "cybersecurity controls are outside the scope of Section 13(b)(2)(B)"; and the post-SUNBURST Form 8-K claims "impermissibly rel[ied] on hindsight and speculation." What survived was narrow: alleged misstatements about access controls and password policy in the Security Statement on the company's website, treated as information furnished to the investing public [2].

FACT— verified. On 20 November 2025 the case was dismissed with prejudice by joint stipulation (SEC Litigation Release No. 26423; SEC v. SolarWinds Corp. and Timothy G. Brown, No. 1:23-cv-09518-PAE, S.D.N.Y.). The SEC said the decision was "in the exercise of its discretion" and "does not necessarily reflect the Commission's position on any other case" [4].

Company-reported. About $21 million spent on secure-development measures by Q2 2021 [3].

What is contested or thinly documented

  • A dismissal is not an endorsement. The SEC dropped the case in its discretion and disclaimed any read-across; nothing was adjudicated about the program's adequacy.
  • The 2024 holdings are one district court's — influential, not settled national law.
  • Brown's account is a party's account [6], and the triple-build design and $21 million are unaudited company claims [3].
  • Awards. A 2023 Globee "CISO of the Year" is pay-to-enter and is not evidence [5].
  • Whether staying was right is a judgment, not a finding.

What it teaches

INTERPRETATION The durable lesson is not the ending but which claim survived. The customer-facing security page was treated as an investor disclosure; the podcasts and press releases were not. Marketing copy describing controls is the exposure.

Name the chilling mechanism precisely. The evidence included a 2018 internal presentation calling remote access "not very secure" [1] — candid risk assessment. Brown: "Normal operating procedures became proof, from [the SEC's] perspective, of negligence" [6]. The rational individual response is to write less down, and that destroys the information environment the program depends on. Do not let "stop documenting" be the lesson.

What to do instead. (1) Separate the risk register from the marketing claim; no public security statement ships without tracing to a control that exists and is tested. (2) Date, scope and assign every internal finding so it reads as a snapshot with an owner and a plan, not a standing confession. (3) Review public security claims like financial disclosure. (4) Course guidance, not a Brown decision: settle indemnification, D&O cover and independent counsel before taking the chair.

Trait Dial (INTERPRETATION — from the decisions). Aggression↔caution +1; urgency↔patience +2, staying for a multi-year rebuild; innovation↔operational discipline +3; centralization↔decentralization −1.

Maturity and Fit. The live question is Fit: should a leader whose company suffered a nation-state supply-chain compromise stay to rebuild, or step aside so the rebuild is not read through their record? Both are defensible. Risk Corollary. "Yes — and here is the risk we are accepting, priced" now extends to your own sentences: the legal risk of a claim is part of its cost.

Discussion questions

  1. Pull your public security page today. Which sentences assert a control? For each, name the control, its owner and the last test.
  2. If candid internal risk writing can become evidence, how do you keep engineers reporting honestly? Draft the paragraph atop your risk register that makes it accurate and defensible.
  3. You are offered a CISO chair at a company that has just suffered a supply-chain compromise. Argue staying versus stepping aside — for the company, then for the person.

Sources

  1. SEC press release 2023-227, 30 Oct 2023 (primary) — https://www.sec.gov/newsroom/press-releases/2023-227
  2. Holland & Knight on the 18 July 2024 Engelmayer opinion — https://www.hklaw.com/en/insights/publications/2024/07/court-in-solarwinds-case-blows-down-secs-cyber-enforcement-authority
  3. SecurityWeek, "SolarWinds Outlines 'Triple Build' Software Development Model" — https://www.securityweek.com/solarwinds-outlines-triple-build-software-development-model-secure-supply-chain/
  4. SEC Litigation Release No. 26423, 20 Nov 2025 (dismissal with prejudice; primary) — https://www.sec.gov/enforcement-litigation/litigation-releases/lr-26423
  5. research/leaders-shortlist.md, §2.6 (Tim Brown) — internal research file.
  6. TechTarget, "Watch your words: Tim Brown's advice for CISOs," 27 Mar 2026 — https://www.techtarget.com/searchsecurity/feature/Watch-your-words-Tim-Browns-advice-for-CISOs

Numbered references match the bracketed markers in the text above. Links open the primary source where one exists; internal research files are named as such.

Related

Dials illustrated
aggression↔cautionurgency↔patienceinnovation↔operational disciplinecentralization↔decentralization
Sectors
technology / software supply chain