Of everything the SEC threw at SolarWinds, one page survived the motion to dismiss: the detailed one. The doctrine rewards vagueness, and the vague page fails every questionnaire it exists to answer.
Read these two paragraphs the way you would skim any vendor's website:
"Access Controls: Role based access controls are implemented for access to information systems. Processes and procedures are in place to address employees who are voluntarily or involuntarily terminated. Access controls to sensitive data in our databases, systems, and environments are set on a need-to-know / least privilege necessary basis."
"We require that authorized users be provisioned with unique account IDs. Our password policy covers all applicable information systems, applications, and databases. Our password best practices enforce the use of complex passwords that include both alpha and numeric characters, which are deployed to protect against unauthorized use of passwords. Passwords are individually salted and hashed."
Unremarkable, right? You have read fifty pages like this. You may have written one. It is the standard register of the corporate trust center: concrete enough to sound real, generic enough to publish.
Those paragraphs are quoted from a 107-page opinion by Judge Paul Engelmayer of the Southern District of New York, filed July 18, 2024, in SEC v. SolarWinds Corp. and Timothy G. Brown. They come from the "Security Statement" SolarWinds posted on its website in late 2017, three years before the SUNBURST supply-chain compromise made the company a household name. And of everything the SEC threw at SolarWinds, the press releases, the blog posts, the podcasts, the SEC filings, the post-breach disclosures, the internal-controls theories, those two paragraphs and the page they lived on were what a federal court refused to dismiss.
The court's own summary of the allegations is one sentence, and it is the sentence every engineering leader should have pinned somewhere: "In essence, the Statement held out SolarWinds as having sophisticated cybersecurity controls in place and as heeding industry best practices. In reality, based on the pleadings, the company fell way short of even basic requirements of corporate cyber health."
Note the qualifier, because it matters enormously and we will come back to it: "based on the pleadings." Nothing in this case was ever proved. Hold that thought through everything that follows.
What makes this opinion worth an engineer's time is not that a security vendor got sued. It is the shape of what survived versus what died.
The SEC's claims about SolarWinds' post-incident disclosures, the statements made in the chaotic days after the company learned its build system had been compromised, were dismissed entirely. The court held they "impermissibly rely on hindsight and speculation." The disclosure written under pressure, at speed, with incomplete information, got judicial grace.
The SEC's ambitious theory that cybersecurity failures violated the internal accounting controls statute was dismissed too, with a line worth framing: reading the law that broadly "could empower the agency to regulate background checks used in hiring nighttime security guards, the selection of padlocks for storage sheds, safety measures at water parks." Congress, the court wrote, quoting precedent, does not "hide elephants in mouseholes."
The vague marketing survived nothing either, and here is where it gets interesting. Claims built on press releases, blog posts and podcasts, the ones promising "high security standards" and a community "built on a bedrock of trust," were thrown out as puffery: statements "too general to cause a reasonable investor to rely upon them," in the court's quoted standard, "too generic to express any objective fact." Calling your compliance program "robust" or "best-of-class" is, in this doctrine, legally weightless. Nobody is entitled to believe it, so nobody can be defrauded by it.
What survived, alone, was the Security Statement. The page with the two paragraphs you just read.
Sit with the perversity of that for a moment. The document that survived a motion to dismiss was the good one. Detailed, concrete, organized by control family, the kind of security page practitioners praise and customers actually want. "Role based access controls are implemented" is a factual assertion about a system. Somebody can pull the ticket. "We take security seriously" asserts nothing, so it can never be false.
The doctrine, in other words, rewards vagueness. The safest security page under securities law is the one that says nothing checkable, which is also the page that fails every customer security questionnaire it exists to answer. And in SolarWinds' case that connection was not hypothetical: the opinion records that the company used the Security Statement as its official response to customer questionnaires about its cybersecurity practices. The marketing page and the compliance artifact were the same document. That is exactly what made it material, and exactly what put it in front of a judge.
What did the government say the reality was? Remember, these are allegations, accepted as true only for the purpose of the motion, never tested, never proved. As pled: while the page advertised complex-password enforcement, the company's actual policy required a minimum of eight characters with 90-day rotation. As pled: a NIST 800-53 self-assessment of the "Identification and Authentication" control family scored twenty of twenty-seven controls "no program/practice in place," and zero fully in place. As pled: of one hundred controls tested for Sarbanes-Oxley purposes, twenty-seven IT controls were deficient, many of them access and password controls, the precise subjects of the page's most confident sentences.
Here is the detail that should reorganize how you think about your own company's documents. The most damaging characterization of the Security Statement did not come from the SEC's lawyers. As quoted in the opinion, an employee described the Security Statement as "aspirational," capturing what SolarWinds hoped to achieve in the future.
And the internal record the SEC assembled, as reproduced in the opinion, is a chain of exactly the artifacts a functioning security program is supposed to produce. Days after the Statement went up in December 2017, Brown, the security executive who would later be personally named as a defendant, emailed the CIO a presentation flagging shortfalls in penetration testing, security training and data classification, repeating an earlier warning that the current state of security left the company "in a very vulnerable state for our critical assets." In January 2018, managers complained, in the government's telling, that "we don't do some of the things that are indicated in" the Security Statement. An assessment of continuous monitoring read: "GAP. Currently there is no program for this across [SolarWinds]." A September 2018 presentation to the CTO flagged, in red font, that active monitoring and true SOC services were "limited or non existent."
The instinct this triggers in some executives is the worst possible lesson: write fewer honest internal assessments. That is exactly backwards, and it misses what actually happened here. The internal assessments were the security program working. Candid gap analyses, escalations in red font, engineers saying plainly what does not exist: that is what you want your team producing, and no defensible version of this story involves producing less of it. The gap that became a federal case was not created by the honest documents. It was created by a public page that did not match them, written calmly, years before any incident, by people who had every opportunity to check. The court forgave the statement made in a panic. It declined to forgive the one made at leisure, because the one made at leisure was specific enough to be false.
Now finish the story, because the ending changes the lesson.
The sustained claims never went to trial. In July 2025 the parties told the court they had a settlement in principle. The settlement never materialized. On November 20, 2025, the SEC and the defendants filed a joint stipulation dismissing the remaining claims with prejudice, with no settlement conditions beyond a waiver of claims against the government. The SEC's own litigation release frames the dismissal as an exercise of its discretion that "does not necessarily reflect the Commission's position on any other case." SolarWinds and Brown, to be perfectly clear, ended this case with nothing proved against them, ever. The allegations above remain allegations, permanently.
So the company won. And winning cost two years of litigation. It cost a security executive being personally named in a federal fraud action for statements on a marketing page. And it cost something subtler and permanent: the company's internal security assessments, its gap analyses, its managers' bluntest complaints, its red-font slides, are now reproduced verbatim in a published federal opinion that anyone can read, that this essay is quoting, that every customer and competitor and plaintiff's lawyer has already read.
That is the real exposure model, and it is why the eventual dismissal makes this case more instructive rather than less. The exposure is not the judgment. The exposure is the discovery. A regulator can walk away, and this one did. What cannot be walked back is that the gap between the public page and the internal record, once litigated, becomes public infrastructure. And the doctrine that survived, the reasoning that a specific security page is an actionable representation while puffery is not, remains on the books for the next plaintiff. The SEC was never the only reader of that page. Private class actions, state attorneys general, contract counterparties and every prospect running a vendor review read the same document, and none of them dismissed anything in November 2025.
The payload, then, for the people who will actually be asked to make the page true:
Write only what you can produce a ticket for. Every present-tense factual sentence on the trust page ("is implemented," "are enforced," "is monitored") should map to evidence you could retrieve this week: a config export, an audit finding, a screenshot with a date. If the evidence hunt would embarrass you, the sentence is not ready.
Separate "we do" from "we are building." The SolarWinds record, as pled, turned on present tense describing hoped-for future state. An honest roadmap section costs nothing and converts the aspirational into the accurate. The one thing you cannot safely do is let hope wear the grammar of fact.
Date the page and version it. A security statement is a claim about a moment. An undated one is a claim about every moment, including the bad quarter two years from now.
Assume it will be read against your own assessments. Your gap analyses and pen-test reports are discoverable, and they should exist in abundance, because they are the work. The page is safe exactly when it would survive being read in the same sitting as your most honest internal document, by someone hostile.
And know which of your documents is really the questionnaire answer. If sales sends the trust page to close deals, it is not marketing. It is a representation someone relied on, which is the entire legal theory that survived here.
The court's rule, compressed: vague is safe and useless; specific is useful and binding. There is no third option where the page is impressive and free. So make it specific, and then make it true, in that order of difficulty.
The SEC has left the building. Everyone else who reads your security page is still in it.
Sources: SEC v. SolarWinds Corp. and Timothy G. Brown, No. 23 Civ. 9518 (PAE) (S.D.N.Y.), Opinion and Order of July 18, 2024 (Dkt. 125, 107 pages), from which all quotations of the Security Statement, the court's holdings, and the internal communications are drawn; all descriptions of SolarWinds' internal security state are the SEC's allegations as pled in its Amended Complaint, accepted as true by the court only for the motion to dismiss, never adjudicated, and dismissed with prejudice by joint stipulation on November 20, 2025 (SEC Litigation Release LR-26423; the dismissal and its terms corroborated by client alerts from Perkins Coie, Alston & Bird, Morrison Foerster, Covington, Jones Day, and A&O Shearman, and the Harvard Law School Forum on Corporate Governance, December 2025). The SEC's July 2023 cybersecurity disclosure rules were not at issue; the court noted the conduct predated their effective date.
Write only what you can produce a ticket for
The rule the court left behind is that a specific claim about a system is a representation somebody can check, and the safe version of that is not a vaguer sentence. It is a claim with its evidence attached. Chain of Consciousness is a tamper-evident record of what a system actually did, on what inputs, in what order, written as the work happens rather than assembled once somebody asks. It does not make a claim true. It makes the claim and its evidence the same artifact, which is the only version of a trust page that survives being read next to your own internal assessments.
Hosted Chain of Consciousness · Verify a record
pip install chain-of-consciousness · npm install chain-of-consciousness