CISO Tribune

Guide

CISO Personal Liability: What SEC v. SolarWinds and the Uber Case Actually Decided

The two cases every personal-liability conversation cites, SEC v. SolarWinds and the Uber Joe Sullivan prosecution, did not end the way most retellings suggest. What the SEC alleged, what a federal judge dismissed, what a jury convicted, and where both cases stand now, sourced to the actual court and SEC documents.

By Hadass Liza Bitton · Published October 9, 2026 · Last reviewed October 9, 2026 · 7 min read

TL;DR: Two cases anchor almost every conversation about personal liability for security leaders, and both are usually retold inaccurately. The SEC's case against SolarWinds and its head of information security, Timothy G. Brown, was narrowed sharply by a federal judge in July 2024 and then dismissed entirely, with prejudice, in November 2025: no court ever found Brown liable for anything. The Uber case against former Chief Security Officer Joe Sullivan is the one that produced real personal consequences, but it was a federal criminal prosecution for obstructing an FTC investigation, not an SEC disclosure case, and it ended in probation, not prison. His conviction was affirmed on appeal in November 2025 and remains pending before the Supreme Court. Neither case supports the common shorthand that a CISO can now be sued by the SEC for a breach, or jailed for how one was handled.

These are two different kinds of case, and conflating them misleads

SEC v. SolarWinds was a civil securities-fraud enforcement action: the SEC's own regulatory authority, applied to what a company and an individual said publicly about cybersecurity. United States v. Sullivan was a federal criminal prosecution: a felony charge for concealing a crime from a federal agency during an active investigation. The first case ended with no finding against anyone. The second ended with an actual conviction, carrying real criminal penalties, just not the prison sentence prosecutors asked for. Treating them as one story, "the SEC and DOJ are coming after CISOs," erases the detail that matters most to any security leader assessing their own exposure: what, specifically, was the legal theory, and did it hold up.

SEC v. SolarWinds: what was alleged

The SEC filed its case against SolarWinds Corp. and Brown on October 30, 2023, in the Southern District of New York. Per the SEC's own litigation release, the agency alleged that from the company's October 2018 IPO through its December 2020 disclosure of the SUNBURST attack, SolarWinds and Brown defrauded investors by overstating the company's cybersecurity practices and understating known risks. Judge Paul Engelmayer's later opinion lays out the core of the claim: Brown was "primarily responsible for creating and approving" a public "Security Statement" on the company's website, while internal presentations he gave in 2017 warned that SolarWinds' security left it "in a very vulnerable state for our critical assets," a gap the SEC said the public-facing statement never disclosed. A separate claim alleged SolarWinds' cybersecurity practices amounted to a failure of its "internal accounting controls" under the Securities Exchange Act, the first time the SEC had ever brought that specific theory against a company's cybersecurity.

What survived, and what did not

Engelmayer's July 18, 2024 opinion split the case cleanly. On what the court calls "pre-SUNBURST disclosures," the opinion states plainly: "the Court sustains the SEC's claims of securities fraud based on the company's Security Statement," finding it "viably pled as materially false and misleading in numerous respects." Every other pre-attack claim was dismissed. All claims tied to the company's post-SUNBURST disclosures were dismissed outright, with the court writing they "impermissibly rely on hindsight and speculation."

The internal accounting controls claim did not survive at all, and the court's reasoning is worth citing directly for any CISO who has heard this case described as expanding the SEC's reach into security practice generally. The opinion holds that reading the statute to cover cybersecurity would let the SEC "regulate background checks used in hiring nighttime security guards, the selection of padlocks for storage sheds, safety measures at water parks," and similar matters, since "Congress does not 'hide elephants in mouseholes.'" The court's conclusion was unambiguous: "cybersecurity controls are not, and could not have been expected to be, part of the apparatus necessary to the production of accurate" financial reports. The disclosure-controls claim against SolarWinds was dismissed on similar hindsight grounds, and with it, per the opinion's closing footnote, "the related aiding and abetting claim against Brown."

The ending nobody retells: dismissed with prejudice

Only the Security Statement claim proceeded past July 2024, into discovery. It never reached trial. On November 20, 2025, the SEC and both defendants filed a joint stipulation dismissing the entire remaining case with prejudice, per the SEC's own litigation release, stating the decision was made "in the exercise of its discretion" and that it "does not necessarily reflect the Commission's position on any other case." No liability was ever established against Brown or SolarWinds on any theory the SEC brought. A CISO citing this case as a cautionary tale about personal SEC liability for a breach is, as of this guide's last review, citing a case that ended in a full dismissal.

United States v. Sullivan: a different theory entirely

Joe Sullivan's prosecution did not arise from a data breach disclosure rule at all. Per the Department of Justice's own press release announcing his conviction, a federal jury found him guilty on October 5, 2022, of "obstruction of proceedings of the Federal Trade Commission" and "misprision of felony," arising from his conduct while Uber was under active FTC investigation into an earlier, 2014 breach. Ten days after testifying to the FTC about Uber's security practices, Sullivan learned hackers had stolen records on roughly 57 million Uber users and drivers; prosecutors showed he arranged a payment to the hackers in exchange for signed non-disclosure agreements and withheld the breach from the FTC, Uber's own general counsel, and the company's outside lawyers. Then-U.S. Attorney Stephanie Hinds said at the time: "We will not tolerate concealment of important information from the public by corporate executives more interested in protecting their reputation and that of their employers than in protecting users."

The sentence, and what it was actually for

Sullivan was sentenced on May 4, 2023, to three years of probation and a $50,000 fine, per the DOJ's sentencing announcement. The sentence is real and the conviction is real, but the case was never about how Uber disclosed a breach to investors or regulators under a securities rule; it was about an individual actively concealing a known felony from a federal agency conducting an active investigation into that same company, a materially different act than a judgment call about materiality or disclosure timing. Nothing about this case establishes liability for a CISO who discloses late, discloses imperfectly, or is simply present for a breach; it establishes criminal exposure for deliberately hiding one from investigators who are already asking.

The case is not over

Sullivan appealed, and the Ninth Circuit has already ruled twice. Its original opinion affirmed the conviction on March 13, 2025. Its amended opinion, issued November 12, 2025 by Judge M. Margaret McKeown's panel, again affirmed the conviction and denied Sullivan's petition for rehearing en banc in the same order, rejecting his arguments that the jury instructions on the obstruction charge were flawed and that the evidence of misprision was legally insufficient. Sullivan has since petitioned the U.S. Supreme Court for review. As of this guide's last review date, that petition remains pending, meaning the final word on this case has not yet been written, even though the conviction itself has now survived two rounds of appellate review.

What this actually means for a CISO

Read together, these cases narrow the real personal-liability story considerably compared to how it usually circulates. No court has held a CISO personally liable, civilly or criminally, for how a company disclosed a cyber incident to investors; the one case that tried that theory ended in full dismissal. The one case that produced an actual criminal conviction did so for conduct closer to obstruction of a federal investigation than to security practice itself: actively concealing a known, already-reported matter from the specific agency investigating it, not a disclosure judgment call made in good faith. That distinction, between a defensible call made with incomplete information and a deliberate act to keep investigators from learning what already happened, is the one worth holding onto, not a general rule that security leadership now carries SEC or criminal exposure for a breach.

What this guide does not cover

This page covers only what the cited SEC litigation releases, the SDNY opinion, and the DOJ and Ninth Circuit documents actually say. It is not legal advice and does not cover every cybersecurity-adjacent enforcement action the SEC or DOJ has brought; it covers the two cases that dominate the personal-liability conversation specifically. For the disclosure rules a CISO is actually required to follow today, see CISO Tribune's guide to the SEC's cybersecurity disclosure rules and the Item 1.05 materiality decision guide, both unrelated to either case above since both postdate the conduct at issue in SolarWinds and predate nothing in Sullivan. Any individual facing a real investigation or enforcement inquiry needs their own counsel, not a guide.

Frequently asked questions

Was SolarWinds' CISO found personally liable by the SEC?
No. The SEC sued SolarWinds and its head of information security, Timothy G. Brown, in October 2023. A federal judge dismissed most of the claims in July 2024, and the SEC and both defendants filed a joint stipulation dismissing the entire case with prejudice on November 20, 2025. No court ever found Brown personally liable for anything the SEC alleged.
What did the SEC originally allege against SolarWinds and Brown?
That SolarWinds, including through a public 'Security Statement' Brown was responsible for approving, overstated its cybersecurity practices from its October 2018 IPO through its December 2020 disclosure of the SUNBURST attack, while internal presentations from Brown himself warned of a 'very vulnerable state' for the company's critical assets. The SEC also alleged the company's cybersecurity practices amounted to a failure of its internal accounting controls.
Why did the lawsuit against SolarWinds and Brown fail?
In a July 18, 2024 opinion, Judge Paul Engelmayer of the Southern District of New York let the Security Statement fraud claim proceed to discovery but dismissed the rest, including the entire internal accounting controls theory, ruling that a company's cybersecurity practices are not part of its 'system of internal accounting controls' under a 1977 statute written for financial recordkeeping. The SEC and both defendants then stipulated to dismiss the surviving claim with prejudice in November 2025, ending the case with no finding against either defendant.
What happened to Uber's former Chief Security Officer, Joe Sullivan?
Sullivan is a criminal case, not an SEC enforcement action. A federal jury convicted him in October 2022 of obstruction of a Federal Trade Commission proceeding and misprision of a felony, for concealing a 2016 Uber data breach while the company was under FTC investigation over an earlier breach. He was sentenced in May 2023 to three years of probation and a $50,000 fine, not prison.
Is the Sullivan case over?
No. The Ninth Circuit affirmed his conviction, and its amended opinion, issued November 12, 2025, also denied his petition for rehearing en banc. Sullivan has since petitioned the U.S. Supreme Court for review, a case still pending as of this guide's last review date.

Sources

Hadass Liza Bitton

Writer

Hadass Liza Bitton is a writer at CISO Tribune covering security leadership: the people who take the top security seat, the ones who leave it, and what each move signals. Reach her at hadass@cisotribune.com.

The Briefing

Every verified CISO move of the week, in your inbox Friday.

Every verified CISO move and one piece of analysis, weekly.

Unsubscribe any time. See the privacy policy.