惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
The Blog of Author Tim Ferriss
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
博客园 - Franky
博客园 - 三生石上(FineUI控件)
爱范儿
爱范儿
腾讯CDC
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
Tailwind CSS Blog
P
Privacy International News Feed
The Cloudflare Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
T
Threat Research - Cisco Blogs
Hugging Face - Blog
Hugging Face - Blog
Project Zero
Project Zero
S
SegmentFault 最新的问题
美团技术团队
WordPress大学
WordPress大学
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
云风的 BLOG
云风的 BLOG
Spread Privacy
Spread Privacy
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
B
Blog
Cisco Talos Blog
Cisco Talos Blog
The GitHub Blog
The GitHub Blog
G
Google Developers Blog
T
The Exploit Database - CXSecurity.com
Simon Willison's Weblog
Simon Willison's Weblog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
C
Cisco Blogs
NISL@THU
NISL@THU
J
Java Code Geeks
C
CERT Recently Published Vulnerability Notes
T
Tor Project blog
K
Kaspersky official blog
宝玉的分享
宝玉的分享
Martin Fowler
Martin Fowler
I
Intezer
U
Unit 42
博客园 - 聂微东
C
Check Point Blog
Recent Announcements
Recent Announcements
Microsoft Azure Blog
Microsoft Azure Blog
Latest news
Latest news
博客园 - 司徒正美
G
GRAHAM CLULEY
S
Schneier on Security
V
Visual Studio Blog

Search Security Resources and Information from TechTarget

How to operationalize threat modeling with AI | TechTarget CISO First fully agentic ransomware attack sparks readiness concerns | TechTarget Evaluating secure enterprise browsers vs. security plugins | TechTarget The AI vulnerability storm is here: Is your security program ready? | TechTarget Perimeter to posture: A roadmap to zero trust maturity | TechTarget TLS certificate lifetime changes: What CISOs must do now | TechTarget The agentic AI 8 key aspects of a mobile device security audit program | TechTarget Why mobile security audits are important in the enterprise | TechTarget Beyond the perimeter: The shift to data-centric protection | TechTarget How agentic AI threat intelligence aids NGO cyber defense: Case study | TechTarget How to conduct a mobile app security audit | TechTarget NO FAKES Act advances: What CISOs need to know | TechTarget What CISOs should know about AI runtime security | TechTarget As Q-Day looms, 90% of systems are unprepared for PQC | TechTarget A CISO Most security pros say their culture is Zscaler lays out its vision to secure the AI era at Zenith Live | TechTarget The OpenClaw security risks every CISO needs to know | TechTarget Cloud security metrics and KPIs: A CISO Florida public sector training on SimSpace cyber range: Case study | TechTarget Reporters' Notebook — Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security It's time to update incident response for the AI era How to build AI security guardrails without blocking innovation The prosecution gap: Why cybercrimes go unpunished AI in cyberdefense: Learning from threat actors' playbooks Top identity and access management risks CISO role changes as cyber-risk appetites in the C-suite grow CISO's guide to data minimization Researchers build autonomous AI worm that can reason and adapt How to secure data at rest, in use and in motion How to find cyber-risk data sources for a FAIR analysis Lost in translation: Cybersecurity board reporting for CISOs How to prepare security controls for future AI regulations EO 14390 raises stakes for enterprise cybersecurity First month of Mythos Preview testing exposes 10K flaws OT attacks shift from recon to physical control, raising stakes For CISOs, dawn of OpenAI Daybreak brings good and bad news Gartner Security & Risk Management Summit 2026: Adapting for AI | TechTarget Inside business email compromise attacks: Real-world examples Verizon 2026 DBIR: 6 key takeaways for CISOs Identity security for AI agents: The proliferation challenge How to build a business impact analysis checklist Taking care of business: The CISO's role in a cyber crisis What CISOs need to know about AI audit logs SOC vs. MDR: What CISOs need to consider Instructure cyberattack reignites ransom payment debate Transform SIEM rules with behavior-based threat detection CISO's guide: How to test an incident response plan How to implement zero trust for AI Data after the breach: Economics of the dark web The breakup: Why CISOs are decoupling data from their SIEMs | TechTarget News brief: Security worries and warnings as AI use expands How to construct an effective security controls evaluation 5 leading enterprise password managers to consider Claude Mythos changes the AI security threat matrix Buyer 6 things to check in your cyber insurance policy fine print How cyber insurance helped with breach recovery -- or not News brief: Critical infrastructure, OT cybersecurity attacks Tape's strategic role in modern data protection Top zero-trust use cases in the enterprise What every CISO should consider before a SIEM migration CISO's guide to centralized vs. federated security models Shadow code: The hidden threat for enterprise IT How to fix cybersecurity's agentic AI identity crisis 5 top SIEM use cases in the enterprise Top 8 e-signature software providers for 2026 How do digital signatures work? News brief: AI woes continue for security leaders Deepfake era demands proof-based security, not just awareness Is SOAR dead or alive? Sort of The push for digital sovereignty: What CISOs need to know Beyond awareness: Human risk management metrics for CISOs Cybersecurity in the age of AI means bigger, faster threats At RSAC 2026, AI optimism and anxiety -- and an MIA U.S. government Inside the SOC that secured RSAC 2026 Conference How to roll out an enterprise passkey deployment How to improve the SOC analyst experience -- and why it matters How contact centers detect and prevent fraud News brief: Iranian cyberattacks target U.S. water, energy CISO checklist: Cybersecurity platform or marketing ploy? RSAC 2026 Conference: Key news and industry analysis | TechTarget Next-generation firewall buyer's guide for CISOs Contact center monitoring best practices for CX leaders RSAC 2026: Cyber insurance and the rise of ransomware Agentic AI's role in amplifying and creating insider risks RSAC 2026 recap: AI security and network security trends Identity security at RSAC 2026: The new enterprise dynamics Meaningful metrics demonstrate the value of cyber-resiliency What to know about red team testing and the law News brief: Iran cyberattacks escalate, U.S. targets named 5 top SOC-as-a-service providers and how to evaluate them Cloud security architecture: Enterprise cloud blueprint for CISOs Contact center compliance checklist for modern workforces How AI caught a malicious North Korean insider at Exabeam News brief: U.S. absence at RSAC sparks leadership concerns Network security management challenges and best practices 10 enterprise secure remote access best practices
Watch your words: Tim Brown's advice for CISOs
2026-03-27 · via Search Security Resources and Information from TechTarget

Sharon Shea

By

Published: 27 Mar 2026

"Anything you say can and will be used against you."

As the first CISO personally indicted in a civil lawsuit, Tim Brown knows all about how what he and his colleagues said -- be it industry language or benign jokes -- could be used against him and his company, SolarWinds.

Brown was the CISO at SolarWinds when the infamous 2020 supply chain attack occurred. Nation-state hackers had injected malicious code into SolarWinds Orion updates, enabling them to infiltrate thousands of organizations worldwide, including government agencies and private companies, and conduct cyberespionage.

What ensued was not only what is widely considered the first large-scale, highly sophisticated supply chain attack executed through a trusted vendor, but also a data discovery and interrogation by the SEC unlike any Brown had ever imagined, given he knew he had nothing to hide.

In October 2023, SolarWinds and Brown were charged with fraud for misleading investors regarding cybersecurity risks and internal control failures. After a five-year process, the charges against the company and Brown were ultimately dropped, but not before Brown learned some eye-opening lessons about communications, interpretations and what truly can and will be used against you.

Don't share too much

In the days and months following the 2020 breach, Brown shared more details with the public than many companies might. During an RSAC 2026 Conference presentation, Brown, currently general partner and CISO in residence at venture group Team8, admitted that the safest move -- at least in terms of his own liability -- would have been to stay silent. But, given public scrutiny of the incident, that would probably have put the company out of business.

"We got into a rhythm of sharing and sharing and sharing, and it really helped our process," Brown said. He explained that it enabled the company to educate the industry about nation-state attacks and their tactics, as well as to share the steps it was taking to build cyber resilience.

But sharing too much isn't always a good thing. According to Brown, his openness was a driving factor in the SEC's investigation -- in which it seized SolarWinds' internal records, devices and communications -- and led to his and the company's ultimate indictment.

Watch what you say

The first year of the investigation, the SEC collected data to build a case. It gathered company communications and emails, and asked Brown for information from his phone, including WhatsApp and Signal messages.

"One of my naïve beliefs at the beginning was somebody was looking for the truth," Brown said. But, he added, he soon found out that no one was looking for the truth, they were searching for enough information to bring a compelling case to the enforcement division.

During the investigation-gathering and investigation phases, Brown was struck by which types of communications were called into question.

For one, industry knowledge was misunderstood. Emails among him and the CTO and CIO often used "continuous improvement," for example -- a well-known phrase in the IT industry. The SEC questioned how they could possibly be "continuously improving."

The SEC also asked why the company had an identity program that lasted multiple years. As any CISO knows, identity programs are ongoing initiatives that only grow and evolve -- they never "end." Brown said he was asked if he was incompetent.

"Normal operating procedures became proof, from [the SEC's] perspective, of negligence," Brown said. He cited an internal audit report that found five incidents of misconfigured access controls. According to the SEC complaints, this was a "systemic issue" -- despite the audit also reporting that the company had 30,000 properly configured access control records, and that it caught these five misconfigurations.

At the time, Brown tried to explain himself to the SEC -- which he said only led to further problems.

"One of the mistakes I made during our first initial interviews and information-collecting by SEC policy folks was that I tried to teach them what software engineering was, what a security team does, what the process was -- they accused us of collusion," he said.

Another thing that alarmed Brown during the investigation was how some communications were taken out of context -- a problem most organizations don't address in communications or security policies. Plenty of internal communications warrant investigation and discipline -- harassment, for example. But what about an email between two security analysts that says, "Our security sucks!"? Everyone has one of those days, and most employees occasionally vent to trusted colleagues. But any message sent over corporate channels is subject to subpoena, and when it comes to the SEC, those are serious words to utter.

"There were jokes in the deficit, there were casual conversations over Teams with our workers," Brown said -- communications he would never have thought twice about -- until now, because the SEC also considered these jokes to be collusion.

Learning from the past

Brown said he believes the SEC was using the SolarWinds breach as a lesson for other organizations.

"Where I give the SEC a little bit of grace -- one day we'll figure out whether it's true -- is I believe that they were looking for a case that would be public enough, that would be able to put CISOs on notice, put security teams on notice, and put executive teams and boards on notice that security is important and you should be talking about security more within the exec team, within the board -- or else you're being negligent," Brown said. "They can't create laws, but they can create precedents by enforcement."

A lesson Brown wants people to take from his experience is that while no CISO or organization wants to limit what its employees say, within reason, under many regulations they have the right to, especially when those communications occur using company property.

"I never saw it said, 'Be aware that the language you're using inside a message could be looked at in a critical way,'" Brown said. "We didn't stress the idea of discovery and email being used against you or Teams being used against you."

Brown and his RSAC co-presenter Ira Winkler, CISO and vice president at exposure management platform vendor CYE, shared the following advice to help CISOs and their organizations put controls in place to address this lesson:

  • Put it in a policy. Create documents outlining appropriate conduct and communication. Get approval from the CEO down. Define penalties for noncompliance.
  • Have an enforcement policy and enforce it. Enforce the policy justly across all employees.
  • Educate users about the policies. Ensure employees understand the policy. Include what the policy entails and how it is enforced. For example, explain the discovery process, including email tracing and scraping.
  • Adhere to regulations. Follow the appropriate and required industry, national and international regulations, as well as privacy laws, data security laws and data retention laws.
  • Encourage self-reporting. Create anonymous reporting capabilities for internal and external communications channels.
  • Implement monitoring for internal channels. Implement just-in-time training and monitor all possible channels, including email and collaboration platforms.

Organizations should prioritize conversations about communications, interpretations and context, Brown said, and ensure all employees are informed and understand the situation clearly.

"If you're not thinking about it, you don't want to be the next Tim Brown -- no offense," Winkler said.

Sharon Shea is executive editor of TechTarget Security.

Next Steps

RSAC 2026 recap: AI security and network security trends

Inside the SOC that secured RSAC Conference 2026

Dig Deeper on Security operations and management