Recently, a ruling in a lawsuit filed by the U.S. Securities and Exchange Commission (SEC) against SolarWinds, a software provider headquartered in Austin, Texas, was viewed by legal analysts as a significant blow to the agency's aggressive cybersecurity enforcement stance.

Judge Paul Engelmayer of the U.S. District Court for the Southern District of New York dismissed most of the case last week, including the SEC's claim that cybersecurity failures could be penalized as violations of "internal accounting controls" under Section 13(b)(2)(B) of the Securities Exchange Act.

"The ruling effectively limits the SEC's ability to challenge companies' cybersecurity programs," said Mark Schonfeld, a litigation partner at Gibson, Dunn & Crutcher, in an email. However, he added that the ruling still allows the agency to continue pursuing claims that companies' statements about their cybersecurity programs were materially misleading.

This lawsuit highlights a trend of aggressive cybersecurity enforcement actions by the SEC and other federal agencies since President Joe Biden took office. However, given recent court rulings, the outlook remains uncertain.

In the SolarWinds case, "the court dismissed all of the SEC's most aggressive claims," said Walker Newell, vice president of management liability at insurance brokerage Woodruff Sawyer, in an email. "The judge easily and convincingly ruled that cybersecurity controls do not fall under internal accounting controls."

It is unclear whether the SEC plans to appeal the ruling. A spokesperson for the agency declined to comment.

Meanwhile, the U.S. Supreme Court last month overturned the so-called "Chevron" doctrine, which had required courts to defer to government agencies' interpretations of ambiguous statutes. According to a previous CFO Dive report, this ruling is expected to have far-reaching effects on the federal government, including agencies like the SEC that assert broad jurisdiction over cybersecurity-related matters without explicit congressional authorization.

The SEC's current cybersecurity enforcement agenda could also change due to the upcoming presidential election in November, which may lead to a change in the agency's leadership.

"We won't really know the future direction of the SEC's cyber enforcement program until next year," Newell said.

SolarWinds sued over response to breach

The SEC sued SolarWinds and its chief information security officer, Timothy Brown, in October of last year, accusing them of defrauding investors by misrepresenting the company's actual cybersecurity practices before a significant breach discovered in December 2020. SolarWinds was also accused of cybersecurity deficiencies that constituted a violation of Section 13(b)(2)(B) for "failing to design and maintain internal accounting controls."

The U.S. Chamber of Commerce and the Business Roundtable jointly supported a subsequent motion by SolarWinds and Brown to dismiss the SEC's lawsuit.

"The ruling is clearly favorable to the defendants in many important respects, and CFOs in particular will note that the court found, based on statutory interpretation, that the SEC's claims about internal controls over financial reporting do not apply to cybersecurity controls," said Danette Edwards, a partner at Katten Muchin Rosenman and co-chair of the securities enforcement defense practice, in an email.

Section 13(b)(2)(B) requires public companies to "devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances that... access to assets is permitted only in accordance with management's general or specific authorization," according to the statutory text.

Expanded use of legal tool

In recent years, the SEC has expanded its interpretation and use of this provision, raising concerns.

The SolarWinds lawsuit is one of two cases where the SEC used Section 13(b)(2)(B) to address cybersecurity violations. In the second case, the agency announced last month that R.R. Donnelley & Sons Co., a global business communications and marketing services provider, agreed to pay approximately $2.1 million to settle SEC charges that it violated Section 13(b)(2)(B) in its response to a ransomware attack in 2021.

In the court ruling, Engelmayer sided with SolarWinds on the Section 13(b)(2)(B) issue, finding that cybersecurity controls are not within the scope of that provision.

"The ruling has significant implications beyond cybersecurity because in recent years the SEC has increasingly relied on this statute to charge companies based on deficiencies in legal, compliance, or risk management controls unrelated to a company's accounting," said Nicole Friedlander, a partner in the criminal defense and investigations group and co-head of the cybersecurity practice at Sullivan & Cromwell, in an email.

According to Friedlander, based on the SEC's interpretation of the statute, the agency would be able to penalize any company that is a victim of a cybercrime. Her firm filed an amicus brief in this case on behalf of the U.S. Chamber of Commerce and the Business Roundtable.

More broadly, the SEC argued that the statute could be interpreted to cover all systems that public companies use to protect their valuable assets, a rationale that "would have far-reaching implications," the judge said in the ruling. "It could give the agency authority to regulate background checks for hiring night guards, the choice of padlocks for storage sheds, safety measures at water parks on which customer goodwill depends, and the length and configuration of passwords required to access company computers."

The opinion "should help curb the SEC's aggressive application of liability to victim companies (and their agents) in cybersecurity cases," said Scott Kimpel, a partner at Hunton Andrews Kurth, in an email. "In particular, the judge's rejection of the SEC's novel internal accounting controls theory may make it harder for the agency to bring similar charges in the future."

The judge also dismissed the SEC's theories that certain "risk factors" stated by SolarWinds in its securities filings, as well as its post-breach disclosures, were misleading.

"This should bring comfort to legal and finance departments at public companies," Newell said. "Government and private plaintiffs will find it difficult to allege securities fraud based solely on good-faith cybersecurity-related statements in SEC filings."

Limited SEC victory

However, the ruling is not a complete loss for the SEC. The judge allowed the agency to continue pursuing securities fraud claims related to cybersecurity statements published on SolarWinds' website.

"Although the company argued that these statements were directed at customers rather than investors, the court still found that alleged misstatements on a public website could serve as the basis for securities claims," said Cara Peterman, a partner in the securities litigation group at Alston & Bird, in an email. "The key takeaway from the ruling is that public companies and their officers and directors should be aware that any public statement about a company's cyber controls could be subject to scrutiny in future SEC enforcement actions or shareholder litigation."

The ruling highlights that public companies need to be cautious about all public statements regarding cybersecurity—including those in blogs, interviews, and conferences—Newell noted.

"Finance, legal, and communications teams should work closely with cybersecurity leaders to handle any meaningful public statements in this area," he said.

In another SEC victory, SolarWinds' CISO remains a defendant in the remaining claims. Analysts noted that although the charges against him and the company were significantly reduced, the ruling overall leaves room for CISOs, CFOs, and other public company executives to face personal liability in SEC cybersecurity enforcement actions.

"Not only do the defendants still face the most serious fraud claims, but the court's ruling on disclosure controls (as opposed to internal controls) is highly fact-dependent," Edwards said. "This does not preclude the use of disclosure control charges in future cybersecurity cases."

Analysts said the case does not affect the SEC's ability to enforce its new cybersecurity rules adopted last year. These rules, based on federal securities laws, require public companies to report to the SEC via Item 1.05 of Form 8-K within four days of determining that a cybersecurity incident is "material," among other requirements.

"The new rules do not involve accounting controls; they only involve disclosure," Peterman said. "And the SolarWinds case was not brought under the new rules."

Nevertheless, the court ruling has indirect implications for any future enforcement of the rules, Newell said. "It signals to the SEC that it needs to proceed cautiously when handling aggressive cybersecurity cases," he said.