CISO Trainings
,
Events
,
RSAC Conference
SolarWinds CISO Tim Brown’s Case Shows Personal, Legal and Health Risks for CISOs
CISOs face tremendous stress in dealing with regulatory scrutiny and legal exposure in the wake of a data breach. SolarWinds CISO Tim Brown shared the personal and professional impact of U.S. Securities and Exchange Commission charges against him after the infamous 2020 SolarWinds supply chain attack.
See Also: How Generative AI Enables Solo Cybercriminals
Brown said the long legal ordeal began years before the SEC officially charged him and SolarWinds in September 2023, alleging he misled investors about cybersecurity risks. He describes the emotional toll of learning that the SEC had named only him, personally, along with the company. Brown suffered a heart attack that same week, dealing with the health and psychological fallout from the investigation.
“The month after the incident, I lost about 25 or 30 pounds. I don’t recommend that as a diet program,” Brown said. A federal judge in 2024 dismissed most of the SEC claims against the company and Brown.
In this video interview with Information Security Media Group at RSAC Conference 2025, Brown also discussed:
- Cyber Sarbanes-Oxley – a legal framework that establishes clear processes and accountabilities in cybersecurity;
- The importance of organizational support during crisis;
- The role of company culture and formal agreements in supporting CISOs.
Brown has over 25 years of experience in the IT and security domain, and a deep expertise in identity, privileged access and threat modeling. He holds 15 issued patents and has played a key role in developing and enhancing enterprise patent programs. Brown has held advisory and board roles with organizations including the Open Identity Exchange and the Transglobal Secure Collaboration Program, and has served as global CTO for the Dell/Deloitte joint venture.