Friday, September 20, 2024
HomeTechnologyJudge in SolarWinds case rejects SEC oversight of cybersecurity controls

Judge in SolarWinds case rejects SEC oversight of cybersecurity controls

Published on

spot_img


A federal judge in a case stemming from one of the worst known cyberattacks has rejected the Securities and Exchange Commission’s bid to oversee corporate cybersecurity controls, relieving companies worried they would be penalized by regulators after breaches by well-resourced hackers.

In a closely watched case brought by the agency against 2020 hacking victim SolarWinds, U.S. District Judge Paul A. Engelmayer on Thursday granted most of the company’s motion to dismiss, holding that current laws give the SEC authority only over financial controls, not all internal controls.

“The SEC’s rationale, under which the statute must be construed to broadly cover all systems public companies use to safeguard their valuable assets, would have sweeping ramifications,” Engelmayer wrote in a 107-page decision.

“It could empower the agency to regulate background checks used in hiring nighttime security guards, the selection of padlocks for storage sheds, safety measures at water parks on whose reliability the asset of customer goodwill depended, and the lengths and configurations of passwords required to access company computers,” he wrote.

The federal judge in Manhattan also dismissed SEC claims that SolarWinds’ disclosures after it learned its customers had been affected improperly covered up the gravity of the breach, in which Russian intelligence agents were accused of burrowing through SolarWinds software for more than a year to get inside multiple federal agencies and big tech companies. U.S. authorities described the operation, disclosed in December 2020, as one of the most serious in recent years, and its ramifications are still playing out for the government and industry.

See also  Elon Musk seizes on chaotic election as Biden tweets to make history

In an era when deeply damaging hacking campaigns have become commonplace, the suit alarmed business leaders, some security executives and even former government officials, as expressed in friend-of-the-court briefs asking that it be thrown out. They argued that adding liability for misstatements would discourage hacking victims from sharing what they know with customers, investors and safety authorities.

Austin-based Solar Winds said it was pleased that the judge “largely granted our motion to dismiss the SEC’s claims,” adding in a statement that it was “grateful for the support we have received thus far across the industry, from our customers, from cybersecurity professionals, and from veteran government officials who echoed our concerns.”

The SEC did not immediately respond to a request for comment.

Engelmayer did not dismiss the case entirely, allowing the SEC to try to show that SolarWinds and top security executive Timothy Brown committed securities fraud by not warning in a public “security statement” before the hack that it knew it was highly vulnerable to attacks.

The SEC “plausibly alleges that SolarWinds and Brown made sustained public misrepresentations, indeed many amounting to flat falsehoods, in the Security Statement about the adequacy of its access controls,” Engelmayer wrote. “Given the centrality of cybersecurity to SolarWinds’ business model as a company pitching sophisticated software products to customers for whom computer security was paramount, these misrepresentations were undeniably material.”



Source link

Latest articles

Padres continue playoff push against historically bad White Sox – San Diego Union-Tribune

On their way to the postseason, a destination that is practically inevitable now,...

Los Angeles Sparks beat Lynx at Target Center

Los Angeles Sparks beat Lynx at Target Center Source link

Man charged with murder in shooting death of Long Beach student

article Troy Lamar Fox, 34, was charged with the murder...

Sublime Biopic Casts KJ Apa as Bradley Nowell

The band's original members, Bud Gaugh and Eric Wilson, are producing the film,...

More like this

Padres continue playoff push against historically bad White Sox – San Diego Union-Tribune

On their way to the postseason, a destination that is practically inevitable now,...

Los Angeles Sparks beat Lynx at Target Center

Los Angeles Sparks beat Lynx at Target Center Source link

Man charged with murder in shooting death of Long Beach student

article Troy Lamar Fox, 34, was charged with the murder...