SEC Charges SolarWinds and Chief Information Security Officer with Fraud, Internal Control Failures
Complaint alleges software company misled investors about its cybersecurity practices and known risks
https://www.sec.gov/news/press-release/2023-227
>> CISOs should embrace their audit partners, partner as closely as you can. That's how you get budget, that's how you get a big stick to enforce policy, that's how you can prove that you did what was necessary
>> CISOs should think twice about caving in to finance on their control budget requests without acknowledged written risk acceptance from those with the check book
>> Those that were told NO last budget cycle, may hear a different story this time around
>> those that still hear NO, those without close audit partners, that's what we call an RGE
--> resume generating event <--