ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Fraud charges for CISOs

Linked InXFacebook
bookmark_borderSave to Library

CIOs and CISOs have always had their career on the line in the case of a data breach. But now, as Jamie Moles at ExtraHop explains, their personal freedom could be under threat

 

On 30 October 2023, the Securities and Exchange Commission charged SolarWinds, and its former CISO Timothy Brown, with fraud and internal control failures. The charges allege that an overstated cyber-security posture and a failure to disclose known vulnerabilities amounted to investor fraud.

 

Personal litigation has been a favoured approach by the SEC for cases involving cryptocurrency, but this is exceptional in the cyber-security industry, and most likely as intended, has firms rethinking their security practices.

 

The short term scramble 

In the short term, a scramble is to be expected as businesses look at internal practices and study the specifics of the SolarWinds case to cover any potential exposure. Boards are likely to examine which existing structures enable the CISO to protect the organisation, whilst CISOs will likely be deciding whether their current employer best supports their long-term career prospects.

 

There will be a jump in plug-and-play security solutions that require minimal set up, as firms try to ensure that any glaring issues are triaged and covered while a longer term strategy is developed. As with most security risks, businesses that have neglected cyber-security will have the greatest struggles.

 

An internal focus could damage the long term

Taking a longer-term view, liability makes individuals responsible, and that responsibility encourages more direct engagement from executives that previously may not have given cyber-security the concern due. If it isn’t someone’s job, a task probably won’t get done.

 

A lack of culpability always leads to neglect; the lack of meaningful repercussions for executives that cause damage to customers and the businesses they lead are a common complaint in popular discourse. CISOs will be increasingly important when the full responsibility they will be expected to shoulder becomes clearer. 

 

Considering CISOs already have some of the shortest tenures in the C suite, in part due to burnout, changes in management structure may be needed to manage the workload and liability. Either the role may be given more executive authority, or subdivided between two spheres of expertise and liability to manage the risks and workload intelligently.

 

Already digital and information roles are separating, a trend which these charges could accelerate. It’s also likely that cyber-security firms capable of offering bespoke solutions for customers will expand operations, as more firms realise it’s almost impossible to develop a security solution internally without involving the wider ecosystem of providers.

 

Currently, most vendors cannot even provide a complete solution. Instead, the channel is increasingly made up of firms that each offer a piece of the puzzle.

 

Structural change without knocking the house down

A lot of the coverage has focused on the sentiment of boards and executives to these changes, but a deciding role will be played by investors. Previously, firms with lax approaches to cyber-security but strong balance sheets out-performed competitors. But charges like this reintroduce risk where the market fails to accurately signal the potential damages.

 

In the same way carbon credits for polluting companies provide an economic signal for the damage emissions caused to the environment (costs which were previously externalised to the public). Now a data breach does not only impact customers; it could have very personal consequences for the executives that oversee it.  

 

Looking inwards for security 

The question remains, how can businesses protect staff and customers from the consequences of a data breach? The main lesson from these charges is to follow the rules. Firms with integrity have nothing to worry about regarding any legal ruling. Firms that have made a habit of flaunting the rules and conventions of cyber-security have the most to lose, because It isn’t just bad actors but also whistleblowers that can expose a firm’s failure to secure their data and disclose any breaches.

 

Similarly, these charges underline the importance in proactive cyber-security posture, namely encouraging internal reviews that are reported. Valid concerns being dismissed is at the crux of the prosecution’s case, having a robust feedback loop where concerns are actioned will be essential. 

 

Something missing from much of the analysis so far is that many firms lack a post breach action plan. Bad actors only need one opportunity out of thousands of attempts, relying on a perfect defence is a terrible plan. Businesses should not be playing catch up to a breach, there should already be contingencies in place.

 

End of an era, not the world 

These rules are not an indication of sweeping oversight by regulators, but part of a wider system of incentives and enforcement designed to shape the market. It’s not the end of the world, it’s the end of an era. 

 

There is currently an epidemic of data breaches and ransomware attacks that is only becoming more pervasive. Clearly, the threat of cyber-extortion is insufficient to create change in the marketplace, so governments are having to use charges like this to shape behaviour.

 

While governments are also working to track down and break up gangs of cyber-criminals, most nations have neither the funding nor expertise to act as cyber-insurance for all businesses, so incentives have to be implemented to create a sustainable, robust marketplace.

 

Hopefully, this sends the right message and Mr Brown is the last CISO looking at jail time after a data breach.  

 


 

Jamie Moles is Senior Technical Manager at ExtraHop

 

Main image courtesy of iStockPhoto.com

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543