The U.S. Securities and Exchange Commission (SEC) has reached a settlement with SolarWinds and its Chief Information Security Officer, Timothy Brown, to resolve charges related to the hacking of the company's systems by Russian-backed attackers.

In a filing last week with a federal judge in New York, the SEC said the parties "have agreed in principle to fully resolve this litigation." That judge is overseeing the SEC's lawsuit against the company.

The judge quickly granted the SEC's request to pause deadlines in the case, including an oral argument originally scheduled for July 22. "The Court congratulates counsel and the parties on this constructive development," the judge said. He gave SolarWinds, Brown, and the SEC until September 12 to file settlement documents or provide an update on the settlement process.

Russian state-sponsored hackers began breaching SolarWinds in late 2019 and injected malicious code into its Orion IT monitoring software, an effort aimed at infiltrating the networks of SolarWinds' customers. The attack was not discovered and disclosed to the public until December 2020.

The supply chain attack triggered one of the most severe cyber espionage campaigns in history, compromising at least nine U.S. federal agencies and more than one hundred private companies.

The SolarWinds incident prompted a broad reassessment of supply chain cyber risks in both government and the private sector, and sparked new attention to the security of software development environments.

In October 2023, the SEC sued SolarWinds and Brown, accusing them of "defrauding investors by overstating SolarWinds' cybersecurity practices and understating or failing to disclose known risks." (Last year, a judge dismissed most of the original charges.) The commission also charged four SolarWinds customers, alleging they misled investors about the extent of the attacks they suffered.

It remains unclear why the SEC chose to settle the SolarWinds case, and an agency spokesperson declined to comment on the reasons. But when the then-Democrat-led commission brought the charges, two Republican-appointed commissioners dissented and later criticized the commission for "playing Monday morning quarterback" by second-guessing SolarWinds' decisions after the fact. After President Donald Trump took office and appointed a new SEC chair, those two commissioners became part of the agency's Republican majority.

SolarWinds declined to disclose the terms of the settlement. "We are pleased with this potential resolution and are happy to move our business forward without distraction," a spokesperson said.

Adam Hickey, a Mayer Brown partner and former federal prosecutor who handled cyber and national security cases, said a review of the final settlement terms will reveal "whether and to what extent the SEC has abandoned certain theories or allegations."

"So far, the SEC has not taken action to rescind the rules requiring disclosure of cybersecurity measures in annual and periodic reports," he said. "The settlement may or may not point in that direction."