When the Securities and Exchange Commission filed suit in October 2023 against SolarWinds Corporation and its Chief Information Security Officer, Timothy Brown, it marked the first time a federal regulator had targeted an individual CISO by name for cybersecurity disclosure failures. The theory was pointed: that Brown and the company had knowingly overstated the maturity of SolarWinds' security posture in public filings while concealing known vulnerabilities in the run-up to, and aftermath of, the SUNBURST supply-chain attack. The case immediately reordered how security executives and their counsel thought about personal exposure.
In November 2025, the SEC dismissed the case against both defendants with prejudice (Hunton). Under new Chair Paul Atkins, the Commission signaled publicly that future cybersecurity enforcement would concentrate on affirmative misrepresentation and deliberate concealment rather than on contested disclosure judgment calls (A&O Shearman). For many CISOs, the headline read as a reprieve. The fuller picture is considerably more complicated. This article examines what the dismissal actually changed in the enforcement landscape, identifies the liability vectors that remain fully operative, and provides practical guidance for in-house counsel and security executives working to calibrate their programs accordingly.
What the Dismissal Did — and Did Not — Change
The with-prejudice dismissal forecloses the SEC from refiling this particular action, and the Commission's public statements under the Atkins leadership represent a genuine policy reorientation (A&O Shearman). The practical effect is a narrowed enforcement target: regulators appear willing to proceed where a registrant or its officers affirmatively lied about a known breach or deliberately minimized a material incident in public disclosures; they appear unwilling to second-guess the reasonableness of a good-faith materiality determination made under genuine uncertainty.
What the dismissal did not change is equally significant. The SEC's 2023 cybersecurity disclosure rules — requiring public companies to disclose material cybersecurity incidents within four business days of a materiality determination — remain fully in force (ComplianceHub). Private securities plaintiffs are entirely unaffected by prosecutorial restraint; a class of shareholders asserting that a company's pre-breach disclosures were materially false may proceed on theories the SEC has chosen not to pursue. And the statute of limitations on most securities fraud claims runs five years, meaning that today's enforcement posture does not foreclose a future administration from revisiting conduct occurring now (A&O Shearman).
The Second Track: Caremark and the Board's Duty of Oversight
While SEC enforcement risk has narrowed along one axis, a second liability vector is expanding. Courts applying Delaware's Caremark doctrine — which holds that directors may face personal liability for a sustained or systematic failure to implement oversight mechanisms — are increasingly willing to entertain claims that board-level cybersecurity governance failures constitute a breach of the duty of oversight (Aprio). The logic is straightforward: where a company operates in an environment of known, significant cyber risk and the board has failed to establish adequate reporting lines or review processes, Caremark's standard becomes applicable.
This matters because Caremark exposure is structurally different from SEC enforcement. It is not subject to prosecutorial discretion. It is triggered by governance process failures rather than by the content of any particular public filing. And it runs directly against individual directors. The result is a two-track risk map for security executives and their counsel: SEC enforcement risk narrows to deliberate concealment in public filings, while board fiduciary exposure simultaneously intensifies around the quality and documentation of cybersecurity governance (StackCyber).
Practical Guidance for In-House Counsel and Security Executives
The appropriate response to this realigned risk environment is not complacency; it is structured preparation. In-house counsel advising public companies should consider the following steps.
1. Audit the materiality determination process. Map precisely how your organization identifies, escalates, and evaluates a potential cyber incident for securities-law materiality. The four-business-day clock begins upon a materiality determination, not upon discovery of the incident; the process by which that determination is made must be defensible and documented.
2. Pressure-test escalation playbooks. Review internal incident-response protocols to confirm that the path from technical discovery to legal and executive escalation is clearly defined, routinely tested, and produces a contemporaneous written record. Gaps in that record are the raw material of both SEC inquiries and private plaintiff claims.
3. Strengthen board-level documentation. Given Caremark's focus on governance process, ensure that board and audit committee minutes reflect substantive, recurring engagement with cybersecurity risk — not merely acknowledgment that a presentation was received. The absence of documented board oversight is itself a liability under the duty-of-oversight framework.
4. Brief the CISO on the residual risk perimeter. Security executives should understand clearly that the dismissal of the SolarWinds action does not immunize affirmative misrepresentation. If a CISO signs or reviews a public filing containing statements about the company's security posture, personal exposure under Section 10(b) and Rule 10b-5 remains live where those statements are knowingly false or misleading.
5. Plan for administration change. The five-year limitations period means that conduct occurring today is reviewable by a future SEC leadership. Programs and documentation built to current standards should be built to endure, not calibrated to the current enforcement posture alone.
Conclusion
In conclusion, the SolarWinds dismissal is a meaningful data point about where the current Commission will direct its prosecutorial resources; it is not a grant of immunity. The four-business-day disclosure obligation, the private litigation bar, and the expanding Caremark framework all operate independently of the SEC's enforcement choices. For in-house counsel and security executives, the practical imperative is to treat this moment as an opportunity to shore up materiality determination processes, escalation documentation, and board governance records — not to relax them. Enforcement postures are a function of administration; the underlying legal obligations are not. Organizations that build durable, well-documented cybersecurity governance programs now will be better positioned regardless of which direction the regulatory environment moves next.

