Guide
What personal legal liability does a CISO actually face?
SEC v. SolarWinds ended in dismissal; Uber's former security chief was convicted. What the two most-cited cases and the SEC's 2023 rules mean for a CISO's own exposure.
The two cases security leaders cite most often when they talk about personal liability both reached an ending, not an ongoing threat: the SEC's civil case against a named chief information security officer was dismissed with prejudice, and a different CISO's criminal conviction over how a breach was handled still stands. Neither outcome is the same shape as the other, and neither is the "CISOs now go to prison for breaches" story that circulates informally. This guide sets out what each case actually decided, what the SEC's own 2023 disclosure rules change, and where insurance coverage for a CISO personally still has a gap.
What did the SEC actually charge in the SolarWinds case, and how did it end?
On October 30, 2023, the Securities and Exchange Commission filed a civil complaint against SolarWinds Corporation and its chief information security officer, Timothy G. Brown, in the U.S. District Court for the Southern District of New York. The SEC alleged that, from the company's October 2018 initial public offering through its December 2020 disclosure of the SUNBURST cyberattack, SolarWinds and Brown overstated the company's cybersecurity practices and understated or failed to disclose known risks.
The complaint alleged that SolarWinds and Brown violated the antifraud provisions of the Securities Act of 1933 and the Securities Exchange Act of 1934, that SolarWinds separately violated the Exchange Act's reporting and internal-controls provisions, and that Brown aided and abetted the company's violations; the SEC sought a permanent injunction, disgorgement, civil penalties and an officer-and-director bar against Brown.
That case did not go to trial. On November 20, 2025, the SEC filed a joint stipulation with SolarWinds and Brown to dismiss the action with prejudice. The SEC's own litigation release states the decision was made in the exercise of its discretion and does not necessarily reflect the Commission's position on any other case.
A dismissal with prejudice closes the case for good; it is a different outcome from a trial verdict either way, and this one followed more than two years of litigation rather than a ruling on the merits of the original allegations.
What happened in the other case security leaders cite, Uber's former security chief?
A separate case, also widely cited in discussions of CISO liability, is criminal rather than civil and reached a different kind of ending. A federal jury in San Francisco convicted Joseph Sullivan, Uber's former chief security officer, of obstruction of justice and of concealing knowledge that a federal felony had been committed, in a verdict reported in October 2022.
He was sentenced on May 4, 2023, to three years of probation and a $50,000 fine; prosecutors had sought 15 months in federal prison. News coverage of the sentencing describes the underlying conduct as arranging a payment to the hackers who had obtained user data, in exchange for their signing non-disclosure agreements, while the Federal Trade Commission was investigating an earlier, smaller breach.
Unlike the SolarWinds case, this one reached a verdict and a sentence rather than a dismissal. The two cases are often mentioned together as "CISOs can be held personally liable," but they are different proceedings (civil securities-fraud allegations that ended in dismissal, versus a criminal conviction that stands), brought by different authorities, over different conduct.
What do the SEC's 2023 disclosure rules change about a CISO's personal exposure?
Separately from either case, the SEC adopted final cybersecurity disclosure rules on July 26, 2023, that apply to every public company, not to any one individual. Item 1.05 of Form 8-K requires a registrant to disclose a cybersecurity incident it has determined to be material, describing the incident's nature, scope, timing and impact, generally within four business days of that materiality determination, with a possible delay only if the U.S. Attorney General finds that immediate disclosure would pose a substantial risk to national security or public safety.
A separate item, Item 106 of Regulation S-K, requires annual-report disclosure of a company's processes for assessing and managing cybersecurity risk, the board's oversight of that risk, and management's role and expertise in managing it, for fiscal years ending on or after December 15, 2023.
Neither item creates a new personal certification requirement for a CISO; both describe what the company, as registrant, must disclose. The SolarWinds case was brought under existing antifraud and internal-controls law that predates these rules, over conduct from 2018 to 2020, not under Item 1.05 or Item 106 themselves.
Does director-and-officers insurance cover a CISO?
A coverage gap exists independent of either case's outcome. Many CISOs are not legally recognized as corporate officers, which commonly leaves them outside the "insured person" definition in a company's standard directors-and-officers policy and exposed personally to defense costs, fines and judgments a D&O policy would otherwise cover for a named officer.
Insurers have begun selling coverage aimed at that gap. On November 11, 2024, Crum & Forster announced a professional-liability policy for CISOs covering professional consulting services, other information-security and technology-systems consulting work, and claims arising from criminal proceedings, with no deductible for defense costs and limits available up to $5 million.
Whether any individual CISO is covered in a given company still depends on that company's own policy wording, not on this guide.
What does this mean for reading the profiles on this site?
Every profile on cisospotlights.com states a person's sourced career path, not a risk assessment of their current role; nothing in this guide should be read onto any individual profile, since none of it was drawn from, or checked against, any specific person's record beyond the two named cases above, each sourced to the SEC's own releases or contemporaneous news coverage of the court record. A CISO's personal legal exposure, where it exists, turns on the specific facts of a specific matter, not on holding the title itself.