Home » Tim Brown Reflects on SolarWinds, SEC Case, Lessons
By Michael Hiskey
At the June 2026 CxO Security Forums in Boston, New York and alongside the Security Summit in National Harbor, former SolarWinds CISO Tim Brown spent nearly two hours answering questions about one of the most consequential cybersecurity events in modern history. Rather than revisiting the technical details of the SUNBURST attack alone, Brown walked through the timeline from the first notification on December 12, 2020, through five years of investigations, legal proceedings, recovery, and reflection. What follows is a factual summary of the discussion, organized largely in the order Brown presented it.
Tim Brown began with the moment that changed everything.
On Saturday, December 12, 2020, SolarWinds received notification from Mandiant that malicious code had been identified inside Orion software and that the information would become public the following day. According to Brown, the initial questions were straightforward but urgent:
Within hours, SolarWinds had assembled technical, legal, executive and communications teams while beginning work with external partners including DLA Piper, CrowdStrike, Microsoft, the FBI and CISA. Brown explained that very early analysis determined the malicious code had not originated within SolarWinds’ source code repository itself but had been introduced somewhere within the software build process.
By Monday morning, before U.S. markets opened, the company had filed an 8-K and publicly disclosed what it knew. At that point, approximately 18,000 customers had downloaded affected software versions. Brown noted that this represented the upper bound of potentially affected organizations; subsequent investigation would determine that fewer than 100 organizations progressed to the second stage of the attack.
I welcome your input on this article… please do that via the summary LinkedIn post on this same topic!
Brown repeatedly described the first several days as “controlled chaos.”
He explained that communication channels themselves immediately became suspect. Until SolarWinds could determine which systems remained trustworthy, teams shifted sensitive coordination to alternative communication platforms. Simultaneously, technical investigation, customer notification, legal coordination, regulatory reporting and executive decision-making all proceeded in parallel.
One of the recurring themes was speed. Every hour mattered. Every public statement mattered. “We learned as much as we could as fast as we could,” he explained.
Rather than allowing a single department to manage the response, SolarWinds organized independent leadership teams responsible for engineering, IT, customer outreach, communications and law enforcement coordination. Those teams met nightly, while executive leadership and the board received daily briefings. Brown credited DLA Piper’s cyber response team with serving as an important coordinator during this period.
Although the technical aspects of SUNBURST have been widely documented, Brown spent considerable time discussing organizational culture. He emphasized that the CEO established the tone from the beginning.
Rather than focusing on reputation management or blame, executive leadership concentrated on helping customers understand whether they had been affected and how they could recover safely.
Internally, Brown recalled feeling both responsibility and uncertainty. “This happened on my watch.”
He also admitted assuming there was roughly a fifty-percent chance he would lose his job during the early days of the incident. At the same time, Brown said there was simply too much work to spend time worrying about that possibility. His focus became straightforward:
“Help the customers. Help us move forward. Be part of the solution.”
Tim also stressed that nobody managed the incident alone. External expertise was brought in immediately, while employees throughout the company assumed responsibilities well outside their normal roles.
One of Brown’s observations concerned the pace of public information.
According to him, organizations involved in a high-profile cyber incident quickly become “out-numbered, out-marketed, and out-communicated.” Accurate reporting exists alongside inaccurate reporting. Researchers publish new findings.
Commentators speculate. Social media amplifies incomplete narratives.
Brown advised that organizations should resist becoming distracted by every inaccurate statement. Instead, he argued for focusing on verified facts while communicating consistently with customers and employees.
“It’s OK not to have all the answers,” he said. “Focus on sharing facts you know to be true.”
He also noted that written communications alone were insufficient. Customers, governments and industry leaders wanted direct conversations with executives responsible for managing the response.
As weeks became months, the emphasis shifted. Investigations continued with CrowdStrike and KPMG, while SolarWinds rebuilt significant portions of its software development and build infrastructure.
The company revoked product signing certificates, developed new build verification approaches and eventually published a comprehensive root cause analysis. Brown described this period as one in which the company adopted a broader “Secure by Design” philosophy.
Development of new product features paused while engineering concentrated on strengthening security architecture and software development practices. He summarized the objective simply: “Don’t just be good. Be exemplary.”
That philosophy extended beyond engineering. Tim described extensive customer meetings, government briefings, congressional testimony and ongoing industry engagement designed to explain both the attack itself and the company’s response.
Brown characterized the legal proceedings as “Phase Two.”
The technical crisis gradually evolved into a multi-year legal process that extended well beyond recovery efforts. According to the timeline he presented, the progression included:
Brown explained that the legal process involved years of document collection, interviews, depositions and formal discovery.
The rumors are that Tim’s personal legal expenses exceeded $3 million, and SolarWinds’ were upwards of $70 million.
One of the most discussed portions of the session involved executive accountability.
Brown described how the SEC investigation prompted cybersecurity leaders across both public and private companies to begin asking questions about indemnification, directors’ and officers’ insurance, legal representation and executive responsibilities.
He observed that conversations many organizations had never previously held became common throughout the CISO community.
According to Brown, one practical recommendation emerged above all others:
“One of the most important things to do is have an accurate job description of what you do—and what you don’t do.”
He argued that responsibilities, reporting relationships, disclosure obligations and decision authority should all be clearly documented before a crisis occurs.
Looking back, Brown identified several areas where additional preparation would have helped Among them were:
He also credited the support of SolarWinds’ leadership, employees and the broader cybersecurity community with helping him navigate the experience. Tim contrasted that support with the other well-known CISO legal case – Joe Sullivan from Uber, emphasizing that organizational backing significantly affected his ability to defend himself throughout the process.
Brown concluded not by focusing on the attack itself, but on its longer-term impact.
He pointed to increased attention on software supply chain security, Secure by Design initiatives, stronger cybersecurity communities and greater executive awareness of cyber risk. He also noted that SolarWinds ultimately recovered, with renewal rates returning above 95 percent as customer confidence gradually returned.
Perhaps his most memorable observation came near the end of the discussion. Reflecting on the broader cybersecurity community, Tim remarked:
“If you didn’t use what happened to me to increase your cybersecurity budget, that’s on YOU.”
It was delivered with humor, but it reflected a recurring theme throughout the discussion: major cyber incidents reshape not only technology, but governance, executive leadership, legal preparedness, and the role of the modern CISO.
Five years after SUNBURST, Brown’s presentation was less about revisiting history than documenting it—from the perspective of the executive who lived through every stage of it.
I welcome your input on this article… please do that via the summary LinkedIn post on this same topic!