SEC Considering Action Against Solarwinds over Cyber Disclosures
The U.S. Securities and Exchange Commission has recommended an enforcement action against SolarWinds Corp. over its public statements on cybersecurity and procedures governing such disclosures, the software firm said on Thursday.
SolarWinds did not admit wrongdoing in the settlement, which requires approval by a judge.
The company was at the center of a cybersecurity crisis in December 2020, after hackers compromised SolarWinds software updates and used them to access the data of thousands of companies and government offices that used its products. The U.S. government has attributed the hack to Russia.
SolarWinds said Thursday it had received a Wells notice from the SEC alleging the company violated U.S. securities law “with respect to its cybersecurity disclosures and public statements, as well as its internal controls and disclosure controls and procedures.”
While a Wells notice does not necessarily mean the recipients have violated any law, the SEC issues the letter to firms when it is planning to bring an enforcement action against them.
SolarWinds said it will respond to the notice, and “maintains that its disclosures, public statements, controls and procedures were appropriate.”
A spokesperson for the SEC did not immediately reply to a request for comment.
Investors sued SolarWinds in 2021, alleging the company and two executives touted cybersecurity measures publicly while prioritizing cost cutting and profit for SolarWinds’ two largest investors.
The case is Bremer v. SolarWinds Corp et al., No. 21-cv-00002, U.S. District Court, Western District of Texas.
- Verisk: A Shift to More EVs on The Road Could Have Far-Reaching Impacts
- Swiss Re: Mitigating Flood Risk 10x More Cost Effective Than Rebuilding
- PE Firm Cornell Sued Over $345 Million Instant Brands Dividend
- T-Mobile’s Network Breached as Part of Chinese Hacking Operation