https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Security


Shutterstock

Transparency

SolarWinds Talks ‘Transparent Communication’ with U.S. Government – But It’s Still Getting Sued by SEC

  • Written by Christine Horton
  • December 19, 2022
In the aftermath of the Sunburst attack, SolarWinds says penalizing companies will stop them reporting attacks.

SolarWinds says becoming the face of the Sunburst attack has led to more transparent communication with government agencies and enterprise customers.

SolarWinds' Chip Daniels

SolarWinds’ Chip Daniels

“We’re willing to share lessons learned to make everybody better together,” said Chip Daniels, head of government affairs at SolarWinds.

“This is a threat that’s not one party against another party. This is a threat to our entire society. And to begin to counter this threat, it requires the cooperation of public and private. But it also requires the cooperation of private and private. So we’re having to collaborate with competitors in this space. Because, if you’ve to defend one, you’ve got to defend everybody.”

The Sunburst supply chain cyberattack made headlines around the world in 2020. Hackers inserted malicious code, Sunburst, into SolarWinds’ Orion software updates sent to nearly 18,000 customers. This led to security breaches at numerous U.S. government agencies. Those include the Treasury Department, the National Telecommunications and Information Administration (NTIA) and the Department of Homeland Security (DHS). The attacker also breached SolarWinds’ corporate clients.

Daniels said one of the biggest challenges to emerge from the attack was a lack of transparency into the federal government’s supply chain.

“There were many U.S. federal agencies, customers of ours, that had no idea how much SolarWinds they had deployed in their networks. And on the flip side, we didn’t know how many of our products were ultimately deployed, let’s say with the U.S. Army. Because it went through different channel members in between. So we really had to both sit back and say, ‘OK, how exposed are we?’ And that’s the major lesson learned for the entire industry. That’s the real vulnerability in the supply chain – when you don’t know the extent of the supply chain. So that’s the first major lesson; we need to understand what’s on our networks. From both sides.”

‘Forthright and Transparent’

Daniels spent 28 years in the U.S. Army before Joining SolarWinds. He was working Congressional Affairs for the Army on Jan. 6, 2021. He decided that day to quit.

“It was not a good day. It was a very surreal day,” he said.

He contacted a friend, who was general counsel at SolarWinds at the time. Daniels admitted he hadn’t heard of the Sunburst attack, but was surprised the firm didn’t have a government affairs team to deal with the aftermath.

“So, I started offering him some advice as a friend — and next thing you know, here I am,” said Daniels.

“I wouldn’t have joined the company if we weren’t so forthright and transparent,” he said. “I did an interview with Sudhakar [Ramakrishna, SolarWinds CEO] very early on and I watched his Congressional testimony. He approached this crisis the exact same way that I would advise senior leaders in the army. Don’t be deceptive, don’t be dismissive, and don’t be defensive. Because you’re just going to invite criticism.”

Penalties Preventing Firms From Coming Forward?

Daniels said SolarWinds receives praise for how it continues to handle the situation, post-attack, on Capitol Hill.

“I meet with somebody for the first time, they’ll say, ‘I just want to tell you, you guys are the gold standard on how you should respond to a cyber incident,'” noted Daniels.

However, SolarWinds has called for better information sharing from the government and reduced penalties for companies that voluntarily report incidents.

“We’re seen as the gold standard [for] how transparent we are. We’re also still being sued by the Securities and Exchange Commission (SEC) in the United States,” said Daniels.

“Government is not monolithic. The U.S. federal government is so expansive that what happens in one agency has little effect on another one. So, Jenny Easterly, [director of the Cybersecurity and Infrastructure Security Agency (CISA)], or Chris Inglis, the national cyber director, talk about the need for public private partnership. But when the enforcement agencies are still leveraging penalties against you, are we creating the environment that would facilitate for future victims to come forward? Or are we creating an environment where they say, ‘I’m only going to tell the government what we’re legally required to tell them.’

“So companies like us are saying that there has to be an incentive to report,” said Daniels.

Where Does The Data Go?

Another question that Daniels raised is where the attack information goes once its reported.

“We would like to better understand when we report to CISA, where does that information go within the government? With whom is it shared? Because different agencies have different interests, and they’re not always aligned. An enforcement agency does not have the same incentive as a national defender, or the intel agency doesn’t have the same interest as a national defender. An intel agency might want to watch the threat actor in your environment for a period of time to see what they’re doing, to learn about techniques and practices. Our company wants to get them out of our environment immediately. So we want to know what information is going to what federal agency for what purpose.”

Moving forward, Daniels stressed that SolarWinds is meeting government guidelines.

“In 2023 we want to communicate clearly that we’re moving that direction. And we’re the safest thing out there for you to buy because we’re already in compliance.”

Want to contact the author directly about this story? Have ideas for a follow-up article? Email Christine Horton or connect with her on LinkedIn.

 

Tags: MSPs VARs/SIs Best Practices Regulation & Compliance Security Technologies

Most Recent


  • CFTV CPaaS Freeze
    CPaaS Sales Tips: Benefits, Ideal Customer, Partner Talking Points
    Watch our video with sales tips and then see who made our list of top CPaaS companies in the channel.
  • Dark Web, hacker
    Kaspersky Study: Dark Web Ads Offer Jobs, Careers in Cyber Crime
    Some dark web job ads included bonuses and commissions for successful projects.
  • Cloud marketplace
    Ingram Micro Cloud Marketplace Expands with Key Microsoft Enhancements
    The news revolves around the New Commerce Experience subscription model.
  • Customer Experience CX
    NICE, Cognizant Team Up to Transform Digital Customer Experience
    The collaboration offers opportunities in CX, WFM and digital transformation.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • skill
    Infoblox Rolls Out New Skilled to Secure Partner Program
  • Microsoft 365
    Key Practices to Close the Microsoft 365 Security Gap
  • Update
    Cynet Partners Get Updated Global Partner Program
  • TD Synnex Cyber Range to Showcase Infoblox Networking, Cybersecurity Solutions

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Kaspersky Study: Dark Web Ads Offer Jobs, Careers in Cyber Crime

January 30, 2023

7 Channel People Making Waves This Week at 8×8, Intel, Google Cloud, RingCentral, More

January 27, 2023

Intelisys AMP’d Images: Partners Explore B2B Purchasing Trends, CX, Security Solutions

January 27, 2023

Industry Perspectives

View all

The Benefits of Hiring an Investment Bank

January 30, 2023

Make the Most of the Gift of Time in 2023

January 25, 2023

Strong Partnerships Ease Challenging UPS Upgrade

January 24, 2023

Webinars

View all

Next-Generation MSP Platform: The Building Blocks for Your Business

February 15, 2023

Security Secrets of the MSP 501: How to Be a Cyber Leader in 2023

December 15, 2022
  • 1

Cybersecurity Certifications: Their Evolving Role in the Fight Against Increasing Attacks

December 13, 2022

White Papers

View all

Overcoming Your Endpoint Security Limitations with a Skeleton Crew

October 25, 2022

Embracing the Zero Trust Mindset For Endpoints

October 24, 2022

Endpoints are the Destination

October 24, 2022

Channel Futures TV

View all

Coffee with Craig and James Episode 117: Cato Networks, Video Killed the Podcast Stars

Retired Astronaut Capt. Scott Kelly Previews His CP Expo Keynote

December 21, 2022

Fusion Connect Eyes Future with Intrado UC, Managed Network Customers

September 23, 2022

RingCentral Focused on Hybrid Work, Microsoft Teams, Other Integrations

September 23, 2022

Twitter

ChannelFutures

.@Avant_CCC offers tips on #CPaaS sales, ideal customers and tech benefits on #ChannelFuturesTV.… twitter.com/i/web/status/1…

January 30, 2023
ChannelFutures

.@kaspersky study examines thousands of employment ads on the #DarkWeb. dlvr.it/ShhH2m https://t.co/zli195hsBz

January 30, 2023
ChannelFutures

.@IngramCloud makes important @Microsoft-related changes to its #cloudmarketplace. dlvr.it/ShhCpR https://t.co/0zwCkUOH5z

January 30, 2023
ChannelFutures

A @NICELtd - @Cognizant partnership promises to accelerate customer adoption of advance #CX solutions.… twitter.com/i/web/status/1…

January 30, 2023
ChannelFutures

Cybersecurity advisory warns of hackers' malicious use of #RMM. @CISACyber dlvr.it/ShYRwg https://t.co/zsBvQWqOYY

January 27, 2023
ChannelFutures

Reaction to #Intel earnings coming in fast and furious. Find out what investors are saying, and how CEO Pat Gelsing… twitter.com/i/web/status/1…

January 27, 2023
ChannelFutures

Our latest #GatelyReport looks at #cybersecurity M&A, investment with @progresspartner, @cyber_advisory, @FBI Hive… twitter.com/i/web/status/1…

January 27, 2023
ChannelFutures

.@channelsmart says plan and boost client #retention efforts to reduce #churn. dlvr.it/ShXvhj https://t.co/4jyHPCjTBn

January 27, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X