Skip to main content
A polished wooden gavel with gold trim rests on a sound block against a crimson background.
Q&A

SolarWinds CISO Tim Brown Speaks Out Ahead of Final SEC Settlement

In a rare interview, Brown recounts the legal fallout from one of the biggest cybersecurity breaches in history, the personal impact (“The doctors confirmed a heart attack”), and his remarkable takeaway: Being a CISO is still a great job.

As a successful corporate CISO at SolarWinds, Tim Brown seemed to have it all.

A photo of a clean-shaven middle-aged White man with brown hair and brown eyes.

The chief information security officer (at right) was charged with safeguarding the software development company’s entire portfolio of infrastructure management tools, which included an IT monitoring platform called Orion that they provided to about 33,000 private and public sector customers.

Then everything changed.

In late 2020, hackers allegedly linked to a Russian intelligence service injected malicious code called Sunburst into an Orion software patch. The compromised update was downloaded and installed by roughly 18,000 organizations, including U.S. government agencies and Fortune 500 companies. It was one of the most sophisticated and novel cyberattacks in history and served as a wake-up call about the state of supply chain security.

A 30-year IT security veteran, Brown believed there could be legal repercussions, given the number of government agencies affected by the breach. But even he was surprised when, in October 2023, while he was at a conference in Zurich, word came down that the U.S. Securities and Exchange Commission had charged Texas-based SolarWinds—and Brown personally—for fraud and internal control failures relating to allegedly known cybersecurity risks and vulnerabilities.

The forthcoming complaint alleged that, from 2018 through December 2020, SolarWinds and Brown defrauded investors by overstating the software company’s security practices and understating or failing to disclose known risks.

After an intense year, Brown was relieved when a U.S. district court judge dismissed most of the SEC’s claims in July 2024. SolarWinds and the SEC recently reached a preliminary settlement on the remaining charges. Terms of the arrangement, expected to be finalized this fall, were not disclosed.

Now, Brown, 61, is publicly reflecting on the SEC’s unprecedented charges against a CISO and what they mean for the profession. Focal Point met with him recently to discuss how the experience affected him and what he learned from it.

(The following interview has been edited for clarity and length.)

What did you go through in those early days after the SEC filed its complaint?

The legal challenges were expected. Our lawyers were all over it, expecting a class-action suit or something from a government entity, like the SEC. A day or two after we found out about the attack, one of our external counsel spoke with me and, as ethically required, said, “We just want to remind you that we represent the company. We don’t represent you.”

We just want to remind you that we represent the company. We don’t represent you.
An attorney for SolarWinds to CISO Tim Brown in 2020, a day or two after the cyberattack was discovered

I understood they had to say this, but it was an uncomfortable way to start. They tell you they want to make sure they have all the facts and know what happened from your perspective. But again, they emphasize they represent the company. Not you. I ended up hiring an attorney for myself and also had an attorney who was shared with the company. Fortunately, the company paid the bills for my individual attorney. The entire process for my individual representation ultimately cost SolarWinds more than $1 million.

Keeping my experience in mind, I always recommend CISOs have a simple conversation with their employers. Go to them and say, “Tim had to go through this. He was sued. He had to get a personal attorney. Those attorney fees are expensive. Luckily for him, SolarWinds was willing to pay for him to have his own attorney. How would we deal with that if something like this occurs?”

[Read also: 5 myths—and realities—about cyber insurance]

D&O [directors and officers insurance] may cover things depending on how policies are written. But they may not. So, having that conversation and determining what will happen if you get in trouble like this is important. In my case, the company was incredible. We were extremely aligned through the whole process, so I didn’t have to worry about covering my personal attorney. But you want to check.

Still, being personally charged by the SEC had to take a toll. How did you handle the stress?

Yeah, I thought I was doing fine for the first few years. But I ended up having a heart attack the week that I was informed I was being charged. So, I guess I was not doing as well as I thought.

I ended up having a heart attack the week that I was informed I was being charged. So, I guess I was not doing as well as I thought.

Most of us have our ways of dealing with stress: Some people are talkers. Some people are publishers. Others internalize or compartmentalize things. I tend to be a compartmentalizer. I keep my work and home lives separate. That helps me to de-stress. I live on a Texas ranch with horses, mini donkeys, and all of those things. That has always been my outlet for stress. That always worked well for me, or at least I thought it did.

I was at a conference in Zurich in September 2023 when I found out I was going to be charged. I flew home on a Saturday and knew something was wrong when I was walking from the airport to my car and had to stop to rest. When I got home, I told my wife about it, and she insisted I go to the hospital right away. The doctors confirmed a heart attack.

What did that experience teach you?

It put things into perspective for me. You realize the job isn’t as important as your health. There’s a lot of stress in the CISO role. Most of us thrive on it. We just don't know what that breaking point is. For me, I hit it that day. I reached my limit of stress at that point.

When things got back to somewhat normal, it helped to put it into perspective. It helped to ask myself, “What is the worst-case scenario?” In my case, I realized the charges weren’t criminal. So, I wasn’t going to jail. The worst-case scenario was a fine and a five-year ban from serving as an officer or board member of a public company. And you can survive that, right?

[Listen also: In our companion podcast, a former CISO discusses how security pros can extend their careers (and preserve their mental health)]

I had great people surrounding me. My lawyers were very good. They were working through everything. I trusted them and knew we’d get through the process. When you come to those realizations, your stress levels drop.

The cybersecurity community was shocked that the SEC charged you. Some felt you were unfairly targeted. Others worried they could be next and thought about quitting. What’s your take?

The community support was incredible. People sympathized with my situation and understood that CISOs like me are just trying to protect everything. We do the best we can. Sometimes it’s not good enough to combat a nation-state.

People sympathized with my situation and understood that CISOs like me are just trying to protect everything. We do the best we can.

The first few days, weeks, or months in an incident, you get very little good said to you. You also get friends coming out of the woodwork and saying, “You’ll get through this. Just fix it and move on. Just do the job.” And that type of encouragement helps a great deal.

But it goes the other way, too. Telling the story of what you experienced and being transparent about what you saw helps the community be more resilient to these types of attacks. In many ways, we took something that was theoretical and made it truly real for everyone. Yes, the Russians are out there. Yes, the Russians are attacking U.S. firms. Yes, the Russians know how to run a good mission, and other nation-states do as well. Here's what it might look like, and this is what you have to watch out for.

[Read also: Supply chain security is tough—so what should good look like?]

When SolarWinds communicated that in a clear model, I think it helped a lot of folks around the world. So the more you can get good to come out of an incident, the more value you can have, and then it makes it all worthwhile.

After everything, you’re still the CISO at SolarWinds and seem to love the role. Why is it worth staying in the job despite all you’ve been through?

This job is one of the most impactful jobs you can have. Just think about being responsible for a company and it's on your watch when something happens.

After everything I’ve gone through, I still believe the CISO role is extremely important. We must provide sufficient safeguards so that our next generation is willing to take on the job, accept the responsibility.

When you secure a company to the appropriate level, when you're working in the background, fighting off adversaries and doing everything you can to stay ahead, it has its excitement. It has its flow. It is never dull. You're not coming in and doing the same thing every day.

It remains one of the most challenging and rewarding positions available. Yes, you’ll hear other people say it’s frustrating. And, yeah, it's hard. But you get to build great teams. And you get the satisfaction of seeing your team succeed. Being a CISO provides a lot of great opportunities, and it's always changing.

[Read also: CISO success story—how Stratascale’s Joseph Karpenko stepped beyond his tech domain to bridge risk and business strategy]

After everything I've gone through, I still believe the CISO role is extremely important. We must provide sufficient safeguards so that our next generation is willing to take on the job, accept the responsibility, and fulfill their duties. We're not saying that we're immune to responsibilities. And that's also important for people to understand that when we take on this role, we assume responsibility. And with responsibility sometimes comes liability.

What we need to work on is ensuring that liability is appropriately managed.