
CISO Tradecraft® #246 - Tim Brown on SolarWinds: What Every CISO Should Know
5 snips
Aug 18, 2025 Tim Brown, the Chief Information Security Officer of SolarWinds, shares his firsthand experience navigating the infamous supply-chain breach. He discusses the attacker’s sophisticated tactics and the challenges of incident response, including real-time communications and customer notifications. Tim emphasizes the importance of supply-chain security, highlighting tools like SBOMs for risk assessment. He also covers the legal complexities and accountability that CISOs face in today’s regulatory landscape, offering crucial insights for cybersecurity leaders.
AI Snips
Chapters
Transcript
Episode notes
Downloaded Doesn't Mean Fully Compromised
- Although ~18,000 customers downloaded the compromised update, fewer than 100 progressed to the active second-stage payload.
- Firewalls and not exposing Orion to the internet limited the attacker’s reach.
Patient, Mission-Focused Adversary
- The adversary executed a patient, deliberate campaign with reconnaissance and error-free code changes.
- They tested in October, returned with polished code in February, and behaved like a mission-focused state actor.
Enforce Triple Builds And Compare Outputs
- Do implement redundant, tamper-resistant builds such as triple builds and ephemeral build systems to detect injected code.
- Compare build outputs across isolated environments and block shipping if results diverge.
