- › The SEC's case against SolarWinds and its CISO was dismissed with prejudice on November 20, 2025, after a judge threw out most claims as non-actionable corporate puffery.
- › The Ninth Circuit upheld Joe Sullivan's conviction in March 2025 for obstructing an FTC investigation and failing to report a felony.
- › The disclosure theory failed and the concealment theory held, so the exposure is in what your people do after they find out, not in what marketing wrote.
- › The practical protections are a written indemnification agreement and confirmed D&O coverage, and most security leaders have neither.
- › Mid-sized companies carry the thinnest protection, because the legal resources that produce these agreements are the ones they do not have.
Ask your head of security a question this week. If a regulator named them personally over an incident, who pays for the lawyer?
Most of them will not know. A smaller number will assume the company covers it, which is a reasonable assumption and frequently wrong. Almost none will be able to show you a document.
That is a governance gap sitting one level below anything your board reviews, and two court decisions in the last eighteen months have made it worth closing. They point in opposite directions, which is what makes them useful.
What the Two Cases Actually Decided
For three years the industry has talked about CISO personal liability as one thing. It is two things, and they went in opposite directions.
In October 2023 the SEC charged SolarWinds and its chief information security officer, Timothy Brown, over public statements and disclosures made before and during the SUNBURST campaign. It was the first time the agency had brought a cybersecurity enforcement action against an individual security officer, and the reaction was appropriate alarm.
The case did not survive. On July 18, 2024, Judge Paul Engelmayer of the Southern District of New York dismissed most of the claims in a 107-page opinion, finding that much of what the SEC pointed to was non-actionable corporate puffery. On November 20, 2025, the SEC dismissed the remaining claims with prejudice. Brown was never prosecuted, and no senior manager was.
The other case went the other way. Joe Sullivan, then chief security officer at Uber, was convicted in October 2022 of obstructing an FTC proceeding and failing to report a felony, after his team paid the people who had taken the data, had them sign non-disclosure agreements, and recorded the payment as a bug bounty while the company was under active FTC investigation. He was sentenced in 2023 to three years of probation, 200 hours of community service, and a $50,000 fine. In March 2025 the Ninth Circuit upheld the conviction.
The Distinction Your Policy Should Turn On
Put those side by side and the line is unusually clear for something this new. The theory that a security leader can be held personally liable for what the company said about its security posture was tested at length and failed. The theory that a security leader can be held personally liable for concealing an incident from a regulator was tested and held, through appeal.
Your exposure sits in the forty-eight hours after somebody discovers something bad, and specifically in whether the people in that room believe their job is to fix the problem or to make the problem go away.
That distinction is worth reading twice, because the second one is a decision made quickly, under pressure, usually by somebody trying to protect the company, and it converts a bad week into a criminal matter.
Why This Is a Board Question and Not a Security One
Here is the part that belongs to leadership and not to the security team. An employee who believes they are personally exposed and unprotected will behave differently during an incident, and not in the direction you want. They will be slower to escalate, more careful about what they put in writing, and more inclined to route a difficult question through a lawyer before it reaches you. None of that is dishonesty. It is an entirely rational response to carrying a risk nobody has agreed to share with them.
The organizations that handle incidents well are the ones where the people closest to the problem can say something uncomfortable quickly. If your security leader is quietly wondering whether the company would fund their defense, you have introduced a delay into the exact process that has to move fastest.
Our C-suite guide to executive liability covers the corporate exposure, and the board’s fiduciary duty in cybersecurity covers the directors’ side. This piece is about the person between them, who usually has the least protection and the most operational knowledge.
Four Things to Put in Writing
None of these requires a new budget line, and all four are ordinary corporate hygiene that simply never got applied to this role. Work them in order, because the first one is what the other three depend on.
A written indemnification agreement, naming the role
Indemnification is what commits the company to funding a defense and paying a settlement. Officers and directors usually have it. Security leaders frequently do not, because the role sits below the officer tier in a lot of structures and nobody revisited the list when the exposure changed.
Ask whether one exists for the role. If the answer is that the general corporate policy probably covers it, that is not an answer, and it is the answer you will get most often.
Confirmed D&O coverage, with the security leader inside it
Directors and officers insurance is the funding mechanism behind the indemnity when the company cannot pay or will not. The question is not whether you carry D&O, because you do. The question is whether your head of security is a covered person under the policy as written.
Get the broker to confirm it in writing. This is a fifteen-minute request that most organizations have never made.
Coverage that survives the person leaving
The exposure outlives the employment. Sullivan was charged over conduct at a company he had left, and regulatory matters routinely surface years after the fact.
Check whether your indemnity and your policy cover former employees for acts during their tenure, because a security leader who resigns during an incident is exactly the person most likely to need it.
A named escalation path that bypasses the incident owner
This is the control that keeps the concealment case from happening to you. Whoever is running an incident should not be the only route by which bad news reaches the executive team, because that is the arrangement that turned a breach into a conviction.
Write down who else can be told, confirm they can be reached at three in the morning, and say out loud that using that path is never held against anybody.
The Uncomfortable Part for Mid-Sized Companies
The protection gap is not evenly distributed, and it runs the wrong way. Large organizations have general counsel, a risk committee, and a broker relationship that produces these documents as a matter of routine. Mid-sized companies have the same regulatory exposure, a security leader carrying the same personal risk, and none of the legal infrastructure that generates the paperwork. The security leader at a 400-person company is frequently the least protected person doing that job anywhere.
If that describes you, the entire fix is a conversation with your broker and an hour of counsel’s time. It is one of the few genuine bargains in this field.
The Question for Your Next Leadership Meeting
Ask who would fund the defense if a regulator named your head of security personally, and ask to see the document that says so. The answer is either a document or it is not. If somebody says they will look into it, put a date on it, because the only version of this problem that matters is the one discovered during an incident rather than before one.
Want to know where your governance gaps sit before a regulator finds them? Contact Grab The Axe for an executive risk assessment, or start with our free Human Attack Surface Score.
A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.
View Author Page →